State Requirements
Requirements by State
Browse cybersecurity and data-protection requirements one state at a time. Each card summarizes what government contractors need to know, with a link to the full state profile.
52 jurisdictions published.
- AlabamaAlabama has no cybersecurity requirement written specifically for government contractors, though its IT procurement references NIST and FIPS standards. Contractors that handle personal data otherwise fall under Alabama's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- AlaskaAlaska sets no cybersecurity statute aimed at contractors, but state procurement carries cybersecurity regulations that vendors must meet on government work. More broadly, any business—contractors included—must comply with Alaska's personal-information breach-notification law.View state profile →
- ArizonaArizona has no contractor-specific cybersecurity statute, but cloud vendors selling to the state face a dated GovRAMP/AZRAMP mandate: new cloud contracts required a GovRAMP- or NIST SP 800-53-aligned risk assessment starting July 1, 2025, and renewal contracts require GovRAMP- or FedRAMP-aligned requirements starting July 1, 2026. Contractors handling personal data otherwise follow Arizona's general data-breach-notification law that applies to all businesses.View state profile →
- ArkansasArkansas has no contractor-specific cybersecurity statute, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data otherwise follow Arkansas's general data-breach-notification law, which also requires reasonable security for personal information.View state profile →
- CaliforniaCalifornia imposes no cybersecurity rule written only for government contractors, though state IT references NIST/FIPS standards and cloud vendors use GovRAMP. All businesses—contractors included—must provide reasonable security for personal information and notify residents of a breach under California law.View state profile →
- ColoradoColorado has no contractor-specific cybersecurity statute, though cloud vendors selling to the state go through GovRAMP authorization. Contractors that hold personal data must also maintain reasonable security and notify residents of a breach under Colorado's data-protection law.View state profile →
- ConnecticutConnecticut has its own cybersecurity statute and references NIST/FIPS standards; notably, its law gives liability protection to businesses that adopt a recognized cybersecurity framework. Contractors handling personal data must also meet Connecticut's data-breach-notification requirements.View state profile →
- DelawareDelaware has no contractor-specific cybersecurity mandate. Businesses—including contractors—that hold residents' personal information must maintain reasonable safeguards and notify them of a breach under Delaware's data-security and breach-notification law.View state profile →
- District of ColumbiaThe District of Columbia sets no contractor-specific cybersecurity requirement. Contractors handling personal data follow DC's consumer data-breach law, which requires reasonable safeguards and notice to affected residents after a breach.View state profile →
- FloridaFlorida has its own cybersecurity statute, references NIST/FIPS standards, and runs cloud vendors through GovRAMP. Contractors handling personal data must also comply with the Florida Information Protection Act, which requires reasonable security measures and breach notification.View state profile →
- GeorgiaGeorgia has no cybersecurity statute written specifically for government contractors, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data otherwise follow Georgia's general data-breach-notification law.View state profile →
- HawaiiHawaii has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under Hawaii's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- IdahoIdaho has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under Idaho's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- IllinoisIllinois has its own cybersecurity statute for the public sector. Contractors that handle personal information must also follow Illinois's Personal Information Protection Act, which requires reasonable security and breach notification for all businesses.View state profile →
- IndianaIndiana has no cybersecurity requirement written specifically for government contractors. Contractors handling personal data instead fall under Indiana's general data-breach-notification law, which also requires reasonable security procedures for personal information.View state profile →
- IowaIowa has no contractor-specific cybersecurity statute, but state procurement carries cybersecurity regulations and references NIST/FIPS standards. Contractors handling personal data also fall under Iowa's general data-breach-notification law.View state profile →
- KansasKansas has no cybersecurity requirement written specifically for government contractors. Contractors handling personal data instead fall under Kansas's data-protection law, which requires reasonable security procedures and breach notification for all businesses.View state profile →
- KentuckyKentucky has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under Kentucky's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- LouisianaLouisiana has no cybersecurity requirement written specifically for government contractors. Contractors handling personal data instead fall under Louisiana's Database Security Breach Notification Law, which requires reasonable security and notice to affected residents.View state profile →
- MaineMaine has no cybersecurity statute written specifically for government contractors, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data otherwise follow Maine's general data-breach-notification law.View state profile →
- MarylandMaryland has both a cybersecurity statute and regulations and references NIST/FIPS standards, including duties that reach vendors handling state data. For in-scope telecommunications and connected-system contracts, Md. Code Ann., State Fin. & Proc. § 13-115(b) accepts NIST SP 800-171, ISO 27001, or CMMC as an alternative recognized security standard. Contractors must also comply with the Maryland Personal Information Protection Act's reasonable-security and breach-notification requirements.View state profile →
- MassachusettsMassachusetts has no standalone contractor cyber statute, but procurement carries cybersecurity regulations and cloud vendors use GovRAMP. Any business—contractors included—holding Massachusetts residents' personal information must maintain a written information security program under 201 CMR 17.00 and report breaches.View state profile →
- MichiganMichigan has no cybersecurity statute written specifically for government contractors, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data otherwise follow Michigan's general data-breach-notification law.View state profile →
- MinnesotaMinnesota has no contractor-specific cyber statute, but state procurement includes cybersecurity regulations and cloud vendors use GovRAMP. Contractors handling personal data also follow Minnesota's general data-breach-notification law.View state profile →
- MississippiMississippi has its own cybersecurity statute and references NIST/FIPS standards for public-sector systems. Contractors handling personal data must also meet Mississippi's data-breach-notification requirements.View state profile →
- MissouriMissouri has no cybersecurity statute written specifically for government contractors, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data otherwise follow Missouri's general data-breach-notification law.View state profile →
- MontanaMontana has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under Montana's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- NebraskaNebraska has no contractor-specific cybersecurity statute, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data must also maintain reasonable security and notify residents of a breach under Nebraska's data-security law.View state profile →
- NevadaNevada has no contractor-specific cybersecurity statute, but the Governor's Technology Office has mandated GovRAMP as the statewide/executive-branch cloud-security verification standard, effective July 1, 2026. Contractors handling personal data otherwise follow Nevada's general data-breach-notification and data-security law.View state profile →
- New HampshireNew Hampshire has its own cybersecurity statute and regulations and runs cloud vendors through GovRAMP. Contractors handling personal data must also comply with New Hampshire's data-breach-notification law.View state profile →
- New JerseyNew Jersey sets no contractor-specific cybersecurity statute, though state IT references NIST/FIPS standards. Contractors handling personal data follow New Jersey's general data-breach-notification law that applies to all businesses.View state profile →
- New MexicoNew Mexico has its own cybersecurity statute for the public sector. Contractors handling personal data must also comply with New Mexico's Data Breach Notification Act, which requires reasonable security and notice to affected residents.View state profile →
- New YorkNew York has no cybersecurity rule written specifically for general government contractors. Businesses—contractors included—that hold New Yorkers' private information must maintain reasonable safeguards and notify residents of a breach under the SHIELD Act.View state profile →
- North CarolinaNorth Carolina has no cybersecurity statute written specifically for government contractors, but NCDIT has mandated GovRAMP for cloud vendors serving executive-branch agencies: vendors must hold GovRAMP Authorized status (or a committed path to it) starting April 1, 2026, with full compliance required by April 1, 2027. Contractors handling personal data otherwise follow North Carolina's general data-breach-notification law.View state profile →
- North DakotaNorth Dakota has no cybersecurity statute written specifically for government contractors, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data otherwise follow North Dakota's general data-breach-notification law.View state profile →
- OhioOhio has its own cybersecurity statute and references NIST/FIPS standards; its Data Protection Act offers a legal safe harbor to businesses that adopt a recognized cybersecurity framework. Under Ohio Rev. Code § 9.64, political subdivisions must report a cybersecurity incident to the Ohio Cyber Integration Center within 7 days and to the Auditor of State within 30 days, and a ransom payment requires a formal legislative-authority resolution. Contractors handling personal data must also meet Ohio's data-breach-notification requirements.View state profile →
- OklahomaOklahoma sets no contractor-specific cyber statute, though state IT references NIST/FIPS standards and cloud vendors use GovRAMP. Contractors handling personal data follow Oklahoma's general data-breach-notification law.View state profile →
- OregonOregon has no standalone contractor cyber statute, but state procurement carries cybersecurity regulations. Any business—contractors included—must provide reasonable safeguards for personal information and notify residents of a breach under the Oregon Consumer Information Protection Act.View state profile →
- PennsylvaniaPennsylvania has no contractor-specific cyber statute, but state procurement includes cybersecurity regulations. Contractors handling personal data also follow Pennsylvania's Breach of Personal Information Notification Act.View state profile →
- Puerto RicoPuerto Rico sets no contractor-specific cybersecurity requirement. Businesses—contractors included—that hold residents' personal data must secure it and report breaches under Puerto Rico's data-security and breach-notification law.View state profile →
- Rhode IslandRhode Island has no contractor-specific cyber mandate. Businesses—including contractors—must maintain reasonable security for personal information and notify residents of a breach under the Rhode Island Identity Theft Protection Act.View state profile →
- South CarolinaSouth Carolina has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under South Carolina's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- South DakotaSouth Dakota has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under South Dakota's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- TennesseeTennessee has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under Tennessee's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- TexasTexas has its own cybersecurity statute and regulations, references NIST/FIPS standards, and runs cloud vendors through its TX-RAMP program; state contractors handling sensitive data face defined security controls. Tex. Gov't Code § 2054.0593 makes TX-RAMP certification mandatory for cloud services sold to Texas state agencies and higher-education institutions, assessed under the TX-RAMP Program Manual version 4.0 (Feb. 11, 2026). Contractors must also comply with the Texas Identity Theft Enforcement and Protection Act's breach-notification duties.View state profile →
- UtahUtah has its own cybersecurity statute and references NIST/FIPS standards; its Cybersecurity Affirmative Defense Act rewards businesses that maintain a recognized security program. Contractors handling personal data must also meet Utah's data-breach-notification requirements.View state profile →
- VermontVermont has no cybersecurity statute written specifically for government contractors, though cloud vendors selling to the state go through GovRAMP authorization. Contractors handling personal data otherwise follow Vermont's general data-breach-notification and data-security law.View state profile →
- VirginiaVirginia has no cybersecurity statute written specifically for government contractors generally, but COV Ramp applies when a vendor will act as data custodian and/or system administrator of Commonwealth data as a SaaS provider. Contractors handling personal data follow Virginia's breach-notification law, and those processing consumer data may also have duties under the Virginia Consumer Data Protection Act.View state profile →
- WashingtonWashington sets no contractor-specific cyber statute, though state IT references NIST/FIPS standards. Contractors handling personal data must comply with Washington's data-breach-notification law that applies to all businesses.View state profile →
- West VirginiaWest Virginia has its own cybersecurity statute and runs cloud vendors through GovRAMP. Contractors handling personal data must also follow West Virginia's data-breach-notification law.View state profile →
- WisconsinWisconsin has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under Wisconsin's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →
- WyomingWyoming has no cybersecurity requirement written specifically for government contractors. Contractors that handle personal information instead fall under Wyoming's general data-breach-notification law, which requires businesses to notify affected residents after a breach.View state profile →