Skip to main content
State profile

Alaska

Procurement agency: Alaska Department of Administration, Division of General Services

Last reviewedJune 28, 2026Version v1

Plain-English Summary

Alaska cybersecurity requirements usually reach contractors through the contract, solicitation, statement of work, data-use terms, technology approval process, or statewide IT policy—not always through a standalone cybersecurity statute. For a contractor, the practical question is whether the work touches state data, state systems, cloud or software services, confidential records, personal information, or agency-managed technology.

If it does, Alaska expects contractors to follow security terms written into the agreement, comply with applicable state and federal privacy and breach laws, and meet any standards the agency adopts by reference. Most of the hard requirements are found in the solicitation documents, not on a single public-facing statute page.

Cybersecurity statutes (background)

These entries describe state statutes that may affect government contractors who handle state data, provide technology or cybersecurity services, or participate in Alaska public procurements. The Alaska Constitution, Alaska Statutes, and session laws are the primary sources of binding state law. Agencies also issue regulations and policies, but the contract documents usually determine the contractor's immediate obligations.

Alaska Statutes 2024

Category. `GOV` · `PRIV` · `BREACH` · `PROC-IT` Authority type. Codified statute (verify current official Alaska Statutes and any amendments before publication). Contractor nexus. General governance and baseline compliance; may become contract-relevant when incorporated into the solicitation or contract.

In plain terms. The Alaska Statutes are the codified laws of the state. They set up agencies, delegate authority, create privacy and breach obligations, regulate public procurement, and authorize the IT security programs that agencies run. For contractors, statutes matter because they are the source of the powers an agency uses to write contract requirements.

Who it applies to. The statutes apply to state agencies and to anyone doing business with the state when the statute or a contract clause expressly covers them. Privacy and breach statutes generally apply to any person or entity that handles personal information of Alaska residents in the ways described by the statute.

What it requires. Contractors should identify the statutes that authorize the agency, the procurement, the data protection rules, and any breach-notification duties. Then read the solicitation and contract to see which of those statutory duties are passed through to the contractor.

Why it matters. A contractor that understands the statutory basis can spot risks: Is the agency asking for something beyond its authority? Is the contract silent on a statutory duty that the contractor must still satisfy? Are the data-protection terms consistent with Alaska law?

Citation. Alaska Statutes 2024 (verify current official Alaska Statutes and any amendments before publication)

AS 36.30.010 – 36.30.900 (State Procurement Code)

Category. `PROC-IT` Authority type. Codified statute (verify current official Alaska Statutes and any amendments before publication). Contractor nexus. Direct vendor relevance; governs how the state buys goods and services.

In plain terms. This is the State Procurement Code. It tells agencies how to solicit, evaluate, award, and administer contracts. It also creates the standard contract clauses and dispute rules that appear in Alaska solicitations and awards.

Who it applies to. It applies to state agencies and to vendors that submit offers, receive awards, or perform state contracts.

What it requires. Contractors must follow the procurement rules that apply to the specific contract type, understand protest and appeal rights, and comply with any contract clauses that are required by law to be included in state awards.

Why it matters. The Procurement Code is the framework for every state contract. It controls competition, evaluation factors, contract terms, and remedies. Contractors that ignore it may miss protest deadlines, misunderstand award criteria, or fail to comply with mandatory clauses.

Citation. Alaska Statutes 2024, AS 36.30.010 – 36.30.900 (State Procurement Code) (verify current official Alaska Statutes and any amendments before publication)

AS 44.21.010 – 44.21.025 (Department of Administration, including Office of Information Technology)

Category. `GOV` · `CYBER` · `PROC-IT` Authority type. Codified statute (verify current official Alaska Statutes and any amendments before publication). Contractor nexus. General governance and baseline compliance; may become contract-relevant when incorporated into the solicitation or contract.

In plain terms. These statutes establish the Department of Administration and the Office of Information Technology. They give the state IT office authority to set statewide technology policies, standards, and services, including cybersecurity.

Who it applies to. It applies to state agencies and to contractors that provide IT, software, cloud, security, or data services to the state, especially when the contract requires compliance with statewide IT policies or standards.

What it requires. Contractors should confirm whether the contract adopts OIT policies, standards, or security controls by reference. If so, the contractor must understand and meet those requirements, document compliance, and maintain it through performance.

Why it matters. A statewide IT policy can become a contract term through a simple reference. Contractors that know the policy can prepare a compliant proposal and avoid post-award surprises.

Citation. Alaska Statutes 2024, AS 44.21.010 – 44.21.025 (Department of Administration, including Office of Information Technology) (verify current official Alaska Statutes and any amendments before publication)

AS 45.48.010 – 45.48.090 (Security Breach of Personal Information)

Category. `BREACH` · `PRIV` Authority type. Codified statute (verify current official Alaska Statutes and any amendments before publication). Contractor nexus. Direct vendor relevance when handling personal information or incident response under a state contract.

In plain terms. This statute requires notification to Alaska residents when their personal information is subject to unauthorized access or acquisition. It applies to any person or entity that owns or licenses personal information about Alaska residents.

Who it applies to. It applies to state agencies and to any person or business that owns, licenses, or maintains personal information of Alaska residents. Contractors that handle state personal information are covered through the contract and through this statute.

What it requires. Maintain reasonable security safeguards for personal information. Have a breach response plan. Notify affected individuals and, if applicable, the state, without unreasonable delay when a breach is discovered. Contracts often specify how the contractor must report incidents to the state.

Why it matters. A breach involving a state contractor can trigger both the statutory notice duties and the contractual remedies. Knowing the statute helps contractors negotiate clear incident-response terms and avoid surprise liability.

Citation. Alaska Statutes 2024, AS 45.48.010 – 45.48.090 (Security Breach of Personal Information) (verify current official Alaska Statutes and any amendments before publication)

Regulations, Policies & Standards

These entries cover regulations, procurement manuals, IT policies, security standards, contract templates, terms and conditions, and agency guidance that may become binding when incorporated into a solicitation, purchase order, master agreement, statement of work, data-use agreement, or other contract document.

Alaska Statutes 2023a Title 44, ch. 21 Article 2. Automatic Data Processing

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Alaska buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Alaska Statutes 2023a Title 44, ch. 21 Article 2. Automatic Data Processing

PIM 79 - Nondisclosure and Confidentialtiy of Information Technolgy Contracts

Category. `PROC-CYBER` · `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. PIM 79 - Nondisclosure and Confidentialtiy of Information Technolgy Contracts

saf-professional-services

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Alaska buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. saf-professional-services

scf-goods-and-non-professional-services

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Alaska buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. scf-goods-and-non-professional-services

Cross-State Procurement Context

NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding Alaska law unless a Alaska statute, regulation, policy, solicitation, or contract adopts them.

For GovConCyber implementation, use this callout to help readers understand why a state may ask for cybersecurity documentation even when the state code is not written like a federal cybersecurity clause. Do not cite NASPO, NASCIO, CIS, or StateRAMP materials as the source of a binding state requirement unless the specific state has adopted or incorporated them.