HB2591 creates a state-level restriction on certain information and communications technology and services connected to foreign adversaries. It directs the Chief Information Officer (CIO) of the Virginia Information Technologies Agency to establish and maintain a public list of prohibited ICT products and services that are designed, developed, manufactured, or supplied by entities owned, controlled by, or subject to the jurisdiction or direction of a foreign adversary, where those products or services are determined to pose an unacceptable risk to U.S. national security or safety. The list is to be published online and updated at least annually.
The bill then prohibits public bodies and, separately, any person conducting business in the Commonwealth from acquiring, importing, transferring, installing, dealing in, or using listed prohibited technologies. It also authorizes the CIO to create a waiver process for otherwise prohibited transactions if the waiver would not create an unacceptable national security risk and is not otherwise barred by law. A limited exception is also provided for law-enforcement-related matters with approval from the Superintendent of State Police in consultation with the CIO. The bill includes a July 1, 2025 timing provision that appears to exempt certain transactions initiated, pending, or completed after that date from the prohibition language as written.
In practical terms, the bill would add a new layer of procurement and business compliance requirements in Virginia for state agencies, public bodies, and private entities operating in the Commonwealth. It would amend existing definitions in the information technology code and add a new chapter in Title 59.1, expanding state authority over ICT supply-chain security and foreign-adversary-related transactions. The measure is aimed at reducing exposure to technologies deemed risky to U.S. national security.
The available voting history suggests mixed to skeptical sentiment: a House subcommittee voted 6-4 to lay the bill on the table, which indicates the proposal did not advance at that stage. No committee transcript is available, so the record does not show detailed debate, but the vote implies concern or lack of consensus around the scope, enforceability, or necessity of the restrictions.
The main points of contention likely center on the breadth of the prohibition, the practical burden on public bodies and businesses, and the ambiguity of the July 1, 2025 exception language. Another likely issue is the extent of executive-branch discretion given to the CIO to define and update the prohibited list and to grant waivers. Supporters would likely emphasize supply-chain security and national security protection, while opponents may worry about compliance costs, procurement disruption, and overbroad restrictions on commerce.
HB2591 would amend Virginia’s information technology and public procurement-related statutes by adding a new CIO-managed prohibited-technology list and by prohibiting certain transactions involving listed ICT and services tied to foreign adversaries. It would affect state agencies, public bodies, and private persons conducting business in Virginia by restricting acquisition and use of covered technologies unless a waiver or exception applies. The bill also adds a new chapter to Title 59.1, extending the restrictions beyond government entities to private business activity in the Commonwealth.
The only recorded vote shows the bill was laid on the table by a 6-4 subcommittee vote, which suggests the measure faced resistance and did not have clear support at that stage. Without transcript remarks, the available record points to cautious or negative sentiment overall, likely reflecting concerns about the bill’s scope and implementation rather than broad agreement.
The likely areas of contention are the breadth of the ban on ICT and services linked to foreign adversaries, the compliance burden on both public bodies and private businesses, and the amount of discretion given to the CIO to maintain the prohibited list and issue waivers. The July 1, 2025 language also appears potentially confusing or limiting, and may have raised questions about how the prohibition would apply to transactions already underway. Supporters would focus on national security and supply-chain risk, while critics would likely emphasize operational uncertainty, procurement disruption, and possible overreach.