HB 2809 Arizona House · 57th Legislature - Second Regular Session

statewide cybersecurity encryption system; requirements

HB 2809 requires Arizona state agencies to implement a statewide cybersecurity system using post-quantum encryption - which protects against future quantum computing threats - for all agencies handling sensitive data like personal information, election systems, public safety records, and infrastructure data. The bill mandates that the system must meet or exceed U.S. Department of Defense’s CMMC 2.0 standards, with all vendors required to be U.S.-based, have no foreign dependencies, and avoid foreign-owned technology. The Auditor General will independently manage encryption keys, conduct regular audits, and report noncompliance to the Governor and Legislature, with agencies facing corrective plans or IT budget restrictions for failing to adhere to requirements.
Bill status passed 3 of 5 stages cleared
Introduction
Jan 2026
Committee Review
Mar 2026
House Passage
Feb 2026
Senate Passage
Governor
Introduced Jan 21, 2026 Last action Mar 17, 2026
Maddy AI version diff · 1 comparison

What changed between versions

Introduced Version House Engrossed Version (02/26/2026) · 4 edits · Feb 26, 2026
MODERATE
The bill was reorganized from a standard legislative format into a structured statutory text with explicit article and section numbering. The core policy requirements remain largely the same, mandating a statewide post-quantum encryption system managed by the Auditor General and procured exclusively from US-based vendors. A new section was added to outline specific duties for vendors and state agencies, including training requirements and consequences for non-compliance such as budget restrictions.
Scope change
The bill's scope expanded by adding a new section (18-564) that details specific operational requirements for vendors and state agencies, including training, audit cooperation, and enforcement mechanisms like budget restrictions for non-compliance.
REQUIREMENT

Added a new section (18-564) requiring vendors to provide technical training and support, and state agencies to install and validate the encryption system on all their systems.

ENFORCEMENT

Added specific consequences for non-compliance, including mandatory corrective action plans, legislative oversight hearings, and restrictions on IT-related state budgets.

TECHNICAL

Changed the document structure from a narrative bill introduction to a formal statutory layout with defined Articles and Sections, and added a 'Legislative findings' section to justify the policy.

DEFINITION

Clarified definitions within the statutory text, ensuring terms like 'Post-quantum encryption' and 'Vendor' are explicitly defined for legal consistency.

Floor votes · House Feb 26, 2026

How they voted

3914
Passed · 7 other
Total votes 60
Feb 26, 2026
D Democratic27
8 Yea 14 Nay 5
51% Nay
R Republican33
31 Yea 2
93% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
9
Key actions
4
Committee
1
Amendments
2
Mar 17, 2026
Upper · Passed
DP
upper
Feb 26, 2026
Lower · Passed
PASSED
lower
Feb 23, 2026
Lower · Passed
DPA
lower
Feb 11, 2026
Lower · Passed
DPA
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of John Gillette
John Gillette
RRepublican
AZ
30