statewide cybersecurity encryption system; requirements
HB 2809 requires Arizona state agencies to implement a statewide cybersecurity system using post-quantum encryption - which protects against future quantum computing threats - for all agencies handling sensitive data like personal information, election systems, public safety records, and infrastructure data. The bill mandates that the system must meet or exceed U.S. Department of Defense’s CMMC 2.0 standards, with all vendors required to be U.S.-based, have no foreign dependencies, and avoid foreign-owned technology. The Auditor General will independently manage encryption keys, conduct regular audits, and report noncompliance to the Governor and Legislature, with agencies facing corrective plans or IT budget restrictions for failing to adhere to requirements.
Bill status
passed
3 of 5 stages cleared
Introduction
Jan 2026
Committee Review
Mar 2026
House Passage
Feb 2026
Senate Passage
Governor
Introduced Jan 21, 2026
Last action Mar 17, 2026
Maddy AI version diff · 1 comparison
What changed between versions
Introduced Version
→
House Engrossed Version (02/26/2026)
·
4 edits
·
Feb 26, 2026
MODERATE
The bill was reorganized from a standard legislative format into a structured statutory text with explicit article and section numbering. The core policy requirements remain largely the same, mandating a statewide post-quantum encryption system managed by the Auditor General and procured exclusively from US-based vendors. A new section was added to outline specific duties for vendors and state agencies, including training requirements and consequences for non-compliance such as budget restrictions.
Scope change
The bill's scope expanded by adding a new section (18-564) that details specific operational requirements for vendors and state agencies, including training, audit cooperation, and enforcement mechanisms like budget restrictions for non-compliance.
REQUIREMENT
Added a new section (18-564) requiring vendors to provide technical training and support, and state agencies to install and validate the encryption system on all their systems.
ENFORCEMENT
Added specific consequences for non-compliance, including mandatory corrective action plans, legislative oversight hearings, and restrictions on IT-related state budgets.
TECHNICAL
Changed the document structure from a narrative bill introduction to a formal statutory layout with defined Articles and Sections, and added a 'Legislative findings' section to justify the policy.
DEFINITION
Clarified definitions within the statutory text, ensuring terms like 'Post-quantum encryption' and 'Vendor' are explicitly defined for legal consistency.
Floor votes · House Feb 26, 2026
How they voted
39–14
Passed · 7 other
Total votes 60
Feb 26, 2026
D
Democratic27
51% Nay
R
Republican33
93% Yea
Vote distribution
All Yea
All Nay
Mixed
No data
Full legislative history
Actions timeline
Total actions
9
Key actions
4
Committee
1
Amendments
2
Mar 17, 2026
Upper · Passed
DP
upper
Feb 26, 2026
Lower · Passed
PASSED
lower
Feb 23, 2026
Lower · Passed
DPA
lower
Feb 11, 2026
Lower · Passed
DPA
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
John Gillette
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about HB 2809
Scope: AZ
Hi! I can help you understand HB 2809. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline