SB 185 Colorado Senate · 2026 Regular Session

Enhance Security of Office of Information Technology

Summary
The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding.     If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit.     The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies.     The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data.     The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually.     The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer.     The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor.     The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information.     The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
Bill status signed all 5 stages cleared
Introduction
May 2026
Committee Review
May 2026
Senate Passage
May 2026
House Passage
May 2026
Signed into Law
Jun 2026
Introduced May 1, 2026 Signed Jun 2, 2026
Maddy AI version diff · 5 comparisons

What changed between versions

Rerevised Final Act · 8 edits · May 21, 2026
MODERATE
This bill strengthens Colorado's cybersecurity oversight by empowering the Joint Technology Committee to order special security audits if audit recommendations remain unresolved for two years or if major discrepancies are found. It mandates the State Auditor to conduct these audits, requiring the Office of Information Technology to reimburse costs from a specific security fund. Additionally, the bill requires the office to maintain an updated public list of all active IT vendor contracts and clarifies rules for implementing emergency security standards.
Scope change
The bill expands the scope of oversight to include mandatory special audits triggered by unresolved past findings and requires the creation and maintenance of a comprehensive inventory of IT vendor contracts.
REQUIREMENT

Added authority for the Joint Technology Committee to formally request special IT security audits if audit recommendations are over two years old or if significant discrepancies exist between reports and previous audits.

Mandated that the State Auditor must conduct special IT security audits when requested and approved, with input from the Office of Information Technology regarding the audit scope.

Required the Office of Information Technology to establish, maintain, and quarterly update a list of all active IT vendor contracts for state agencies, including vendor names, contract values, expiration dates, and data criticality tiers.

Added a process for the Office to submit a one-time budget request to the Joint Technology Committee to fund the creation and maintenance of the new vendor contract list.

Required the State Auditor to submit the final audit report to the Legislative Audit Committee, Joint Technology Committee, Joint Budget Committee, and the Governor.

Added new rules for emergency security standards, requiring them to be posted online within 72 hours and automatically expiring after 90 days unless formalized under standard procedures.

FISCAL

Established that the Office of Information Technology must reimburse the State Auditor for audit costs using the Technology Risk Prevention and Response Fund.

TIMELINE

Specified that the State Auditor must produce the special audit report within twelve months of the Legislative Audit Committee's affirmative vote.

Floor votes · House May 13, 2026

How they voted

This bill passed the Senate by voice vote (no roll call recorded).
Full legislative history

Actions timeline

Total actions
14
Key actions
7
Committee
4
Jun 2, 2026
Signed into law
Governor Signed
executive
May 22, 2026
Lower · Passed
Signed by the Speaker of the House
lower
May 22, 2026
Upper · Passed
Signed by the President of the Senate
upper
May 13, 2026
Lower · Passed
House Third Reading Passed - No Amendments
lower
May 12, 2026
Lower · Passed
House Committee on Appropriations Refer Unamended to House Committee of the Whole
lower
May 9, 2026
Committee
House Committee on State, Civic, Military, & Veterans Affairs Refer Unamended to Appropriations
lower
May 8, 2026
Introduced
Introduced In House - Assigned to State, Civic, Military, & Veterans Affairs
lower
May 8, 2026
Upper · Passed
Senate Third Reading Passed - No Amendments
upper
May 7, 2026
Upper · Passed
Senate Committee on Appropriations Refer Unamended - Consent Calendar to Senate Committee of the Whole
upper
May 5, 2026
Committee
Senate Committee on Business, Labor, & Technology Refer Amended to Appropriations
upper
May 1, 2026
Introduced
Introduced In Senate - Assigned to Business, Labor, & Technology
upper
5 primary · 7 co-sponsors

Sponsors