HB 957 Maryland House of Delegates · 2026 Regular Session

Cybersecurity - Standards and Compliance - Alterations

HB 957 requires all Maryland local school systems to designate a cybersecurity point of contact, comply with state minimum cybersecurity standards set by the Department of Information Technology (DOIT), and conduct a cybersecurity maturity assessment every two years starting in 2027. It repeals a prior requirement that county boards prioritize purchasing digital devices with certain funds, shifting focus toward cybersecurity compliance. Schools must annually certify compliance with DOIT’s standards by June 30 and report cybersecurity spending details by August 15 each year. The bill also mandates DOIT to annually review and update the state cybersecurity standards. This directly affects all local school systems and their technology budgeting and reporting practices.
Bill status signed all 5 stages cleared
Introduction
Feb 2026
Committee Review
Apr 2026
House of Delegates Passage
Apr 2026
Senate Passage
Apr 2026
Signed into Law
Apr 2026
Introduced Feb 5, 2026 Signed Apr 14, 2026
Maddy AI version diff · 1 comparison

What changed between versions

First - Cybersecurity - Standards and Compliance - Alterations Third - Cybersecurity - Standards and Compliance - Alterations · 5 edits
MODERATE
This bill update clarifies that the Department of Information Technology must update cybersecurity standards only if necessary and requires the Department to advise local school systems rather than just support them. It also adds a new requirement for county boards to designate a local point of contact for cybersecurity communications. Additionally, the bill expands the list of State Finance and Procurement sections being repealed and reenacted to include 3.5-101, 3.5-2A-04(b), and 3.5-406.
Scope change
The bill's scope regarding cybersecurity oversight was modified to include advisory responsibilities for the Department and a mandatory contact designation for local school boards.
REQUIREMENT

Changed the Department of Information Technology's duty from reviewing and updating standards to reviewing and, if necessary, updating them.

Changed the Department's role regarding local schools from providing support to providing advice.

Added a new mandate for each county board to designate a local point of contact for all cybersecurity-related communications.

SCOPE

Expanded the list of repealed and reenacted State Finance and Procurement sections to include 3.5-101, 3.5-2A-04(b), and 3.5-406.

TECHNICAL

Added a note explaining that underlining indicates amendments to the bill.

Floor votes · House of Delegates Mar 9, 2026

How they voted

This bill passed the Senate by voice vote (no roll call recorded).
Full legislative history

Actions timeline

Total actions
13
Key actions
9
Committee
6
Apr 14, 2026
Signed into law
Approved by the Governor - Chapter 34
executive
Apr 8, 2026
Lower · Passed
Returned Passed
lower
Apr 8, 2026
Upper · Passed
Third Reading Passed
upper
Apr 3, 2026
Upper · Passed
Favorable Adopted Second Reading Passed
upper
Apr 2, 2026
Upper · Passed
Favorable Report by Education, Energy, and the Environment
upper
Mar 23, 2026
Committee
Referred Education, Energy, and the Environment
upper
Mar 21, 2026
Lower · Passed
Third Reading Passed
lower
Mar 20, 2026
Lower · Passed
Favorable with Amendments {
lower
Mar 20, 2026
Lower · Passed
Favorable with Amendments Report by Government, Labor, and Elections
lower
Mar 9, 2026
House Of Delegates · Passed
House of Delegates Vote: pass (130-0-12)
house of delegates
Feb 5, 2026
Committee
First Reading Government, Labor, and Elections
lower
5 primary · 0 co-sponsors

Sponsors