What contractors should check first
For California contracts, start with the contract documents, solicitation instructions, and any state IT or data-security attachments. A requirement matters to your company when it is incorporated into the solicitation or contract, when your work touches state systems or state data, or when the state requires approval for technology, cloud, software, or network-connected services.
Before bidding or performance, confirm:
- whether the work involves state data, personal information, confidential records, cloud services, or access to a state system;
- whether California Department of Technology (CDT), Office of Information Security policies or security review requirements apply;
- whether California Department of General Services (DGS), Procurement Division standard terms add cybersecurity, privacy, incident-reporting, audit, or flowdown duties; and
- what evidence the agency expects, such as a security plan, access-control documentation, incident contact, insurance, or vendor security questionnaire.
Cybersecurity statutes (background)
In plain terms. California centralizes state cybersecurity in the Office of Information Security and runs detailed IT procurement rules through the State Administrative Manual.
Who it applies to. State agencies and their IT vendors. California references NIST/FIPS and participates in GovRAMP.
What it requires. State law establishes the Office of Information Security to set statewide security policy, and computer-crime law backs it. Agencies follow the State Administrative Manual for IT procurement and system-and-services acquisition.
Why it matters. Vendors selling IT to California must work within the Office of Information Security's policies and the State Administrative Manual's procurement and security rules.
Citation. Cal. Gov't Code (Office of Information Security); Cal. Penal Code (computer crime). References NIST/FIPS; participates in GovRAMP.
Regulations, Policies & Standards
In plain terms. California's vendor-facing IT rules live in DGS contract provisions and the State Administrative Manual.
Who it applies to. State agencies and their IT vendors.
What it requires. DGS general provisions for IT contracts and State Administrative Manual sections on IT procurement and system-and-services acquisition set the terms and security expectations for vendors.
Why it matters. Expect California's standard IT contract provisions and SAM acquisition rules to govern your engagement.
Citation. DGS PD-401 (General Provisions — Information Technology Contracts); State Administrative Manual (SAM) §§ 4800, 5210, 5230.4, 5305.8, and 5315.1 (System and Services Acquisition).
Cross-state procurement context
NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding California law unless a California statute, regulation, policy, solicitation, or contract adopts them.