Skip to main content
State profile

Georgia

Procurement agency: Georgia Department of Administrative Services (DOAS), State Purchasing Division

Last reviewedJune 28, 2026Version v1

Plain-English Summary

Georgia cybersecurity requirements usually reach contractors through the contract, solicitation, statement of work, data-use terms, technology approval process, or statewide IT policy—not always through a standalone cybersecurity statute. For a contractor, the practical question is whether the work touches state data, state systems, cloud or software services, confidential records, personal information, or agency-managed technology.

This page separates binding sources from background guidance. A source matters to your company when it applies directly to vendors or when an agency incorporates it into a solicitation, purchase order, master agreement, statement of work, data-use agreement, security exhibit, or other contract document.

What Contractors Should Check First

Before bidding on or performing a Georgia contract, confirm:

  • whether the work involves state data, personal information, confidential records, cloud services, software-as-a-service, network-connected products, or access to a state system;
  • which state Chief Information Officer (CIO), Chief Information Security Officer (CISO), technology-office, or procurement-office policies apply to the purchase;
  • whether standard terms add cybersecurity, privacy, incident-reporting, audit, insurance, subcontractor, or flowdown duties; and
  • what evidence the agency expects, such as a security plan, data inventory, access-control records, incident contact, vendor questionnaire, security assessment, approval record, or subcontractor flowdown.

How To Read This Page

Direct contractor duty means the source applies to vendors, service providers, contractors, or handlers of state data. Agency duty that affects vendors means the source binds the state agency but changes what the agency must require from contractors. Contract clause / flowdown means the duty usually becomes binding when it appears in the solicitation, contract, master agreement, data-use agreement, or statement of work. Background only means the source helps explain the state’s cybersecurity or procurement environment but does not, by itself, impose a contractor duty.

At-a-Glance Contractor Map

AreaWhat to verifyEvidence to keep
State dataWhether the work uses state data, personal information, confidential records, or agency records.Data inventory, data-flow map, access list, return/destruction record.
State systemsWhether employees, subcontractors, tools, or cloud services connect to state systems.Access approvals, account list, logging evidence, offboarding records.
Technology procurementWhether the purchase requires IT approval, security review, architecture review, or procurement-office approval.Solicitation questions, approvals, exceptions, security questionnaire, evaluation submissions.
Contract termsWhether cybersecurity, privacy, incident reporting, audit, insurance, and subcontractor duties are incorporated.Clause matrix, flowdown terms, subcontractor certifications, incident contact list.

Cybersecurity statutes (background)

Georgia source materials in the uploaded archive did not clearly identify a standalone contractor-facing cybersecurity statute for this page. Security requirements appear to flow primarily through procurement documents, IT policies, privacy/breach laws, or contract terms.

Regulations, Policies & Standards

These entries cover regulations, procurement manuals, IT policies, security standards, contract templates, terms and conditions, and agency guidance that may become binding when incorporated into a solicitation, purchase order, master agreement, statement of work, data-use agreement, or other contract document.

Appropriate use of Information Technology Resources (PS-08-003.2) 0

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Appropriate use of Information Technology Resources (PS-08-003.2) 0

Appropriate use of Information Technology Resources (PS-08-003.2) 0 (1)

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Appropriate use of Information Technology Resources (PS-08-003.2) 0 (1)

Authorization and Access Managment SS-08-010.02

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Authorization and Access Managment SS-08-010.02

Authorization and Access Managment SS-08-010.02 (1)

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Authorization and Access Managment SS-08-010.02 (1)

Cybersecurity Georgia Technology Authority

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Cybersecurity Georgia Technology Authority

Enterprise Information Security Policy (PS-08-005) Enterprise Policies, Standards, and Guidelines

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Enterprise Information Security Policy (PS-08-005) Enterprise Policies, Standards, and Guidelines

Enterprise Information Security Policy PS-08-005

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Enterprise Information Security Policy PS-08-005

Enterprise Policies, Standards, and Guidelines

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Enterprise Policies, Standards, and Guidelines

Georgia Procurement Manual

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Georgia Procurement Manual

GTA Endorsement of Procurement SM-14-008 0

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. GTA Endorsement of Procurement SM-14-008 0

Independent Security Assessments SS-08-042

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Independent Security Assessments SS-08-042

Information Security Controls Policy (PS-17-001) Enterprise Policies, Standards, and Guidelines

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Information Security Controls Policy (PS-17-001) Enterprise Policies, Standards, and Guidelines

Network Security Information Flow PS-08-030

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Network Security Information Flow PS-08-030

OCGA Title 50, ch. 5

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. OCGA Title 50, ch. 5

Outsourced IT Services and Third-Party Interconnections SS-08-044

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Outsourced IT Services and Third-Party Interconnections SS-08-044

PSGs Sorted by Name

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. PSGs Sorted by Name

SS-20-001 Cybersecurity Capability Maturity Model Standard (002)

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. SS-20-001 Cybersecurity Capability Maturity Model Standard (002)

Terms and Conditions for Cloud SM-14-010

Category. `PROC-CYBER` · `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Terms and Conditions for Cloud SM-14-010

Third Pary Security Requirements SS-08-013

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Third Pary Security Requirements SS-08-013

Third-Party Access PS-08-011

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Georgia buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Third-Party Access PS-08-011

Cross-State Procurement Context

NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding Georgia law unless a Georgia statute, regulation, policy, solicitation, or contract adopts them.

For GovConCyber implementation, use this callout to help readers understand why a state may ask for cybersecurity documentation even when the state code is not written like a federal cybersecurity clause. Do not cite NASPO, NASCIO, CIS, or StateRAMP materials as the source of a binding state requirement unless the specific state has adopted or incorporated them.

Cross-state procurement context

NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding Georgia law unless a Georgia statute, regulation, policy, solicitation, or contract adopts them.