Plain-English Summary
North Dakota cybersecurity requirements usually reach contractors through the contract, solicitation, statement of work, data-use terms, technology approval process, or statewide IT policy—not always through a standalone cybersecurity statute. For a contractor, the practical question is whether the work touches state data, state systems, cloud or software services, confidential records, personal information, or agency-managed technology.
This page separates binding sources from background guidance. A source matters to your company when it applies directly to vendors or when an agency incorporates it into a solicitation, purchase order, master agreement, statement of work, data-use agreement, security exhibit, or other contract document.
What Contractors Should Check First
Before bidding on or performing a North Dakota contract, confirm:
- whether the work involves state data, personal information, confidential records, cloud services, software-as-a-service, network-connected products, or access to a state system;
- which state Chief Information Officer (CIO), Chief Information Security Officer (CISO), technology-office, or procurement-office policies apply to the purchase;
- whether standard terms add cybersecurity, privacy, incident-reporting, audit, insurance, subcontractor, or flowdown duties; and
- what evidence the agency expects, such as a security plan, data inventory, access-control records, incident contact, vendor questionnaire, security assessment, approval record, or subcontractor flowdown.
How To Read This Page
Direct contractor duty means the source applies to vendors, service providers, contractors, or handlers of state data. Agency duty that affects vendors means the source binds the state agency but changes what the agency must require from contractors. Contract clause / flowdown means the duty usually becomes binding when it appears in the solicitation, contract, master agreement, data-use agreement, or statement of work. Background only means the source helps explain the state's cybersecurity or procurement environment but does not, by itself, impose a contractor duty.
At-a-Glance Contractor Map
| Area | What to verify | Evidence to keep |
|---|---|---|
| State data | Whether the work uses state data, personal information, confidential records, or agency records. | Data inventory, data-flow map, access list, return/destruction record. |
| State systems | Whether employees, subcontractors, tools, or cloud services connect to state systems. | Access approvals, account list, logging evidence, offboarding records. |
| Technology procurement | Whether the purchase requires IT approval, security review, architecture review, or procurement-office approval. | Solicitation questions, approvals, exceptions, security questionnaire, evaluation submissions. |
| Contract terms | Whether cybersecurity, privacy, incident reporting, audit, insurance, and subcontractor duties are incorporated. | Clause matrix, flowdown terms, subcontractor certifications, incident contact list. |
Cybersecurity statutes (background)
These entries cover statutes or statutory-code sources from the uploaded source archive that may affect contractor cybersecurity, privacy, breach response, procurement, records, or technology work. Each citation should be checked against the current official state code before publication.
Guidelines, Rules and Laws Office of Management and Budget North Dakota
Category. `GOV` Authority type. Source document to verify against current official state authority before publication. Contractor nexus. Agency duty that affects vendors; may become a contractor duty through contract incorporation, system access, or technology approval.
In plain terms. This source identifies who in North Dakota government has authority over information technology, security policy, technology approval, or statewide digital operations. For contractors, that matters because the responsible office often controls the standards an agency must include in technology contracts.
Who it applies to. It primarily applies to state agencies and state technology officials. Contractors are affected when an agency uses that authority to set solicitation requirements, contract terms, security reviews, approval gates, or data-handling conditions.
What it requires. Contractors should use this source to identify the office that can require security documentation, technology approval, architecture alignment, data-protection terms, or compliance with statewide IT policies. Before bidding, map the solicitation to the responsible CIO, CISO, procurement, or technology office and preserve the approval record.
Why it matters. State IT governance sources often explain why a solicitation contains cybersecurity terms even when the statute does not mention contractors directly. Missing the governing office or approval path can create bid, performance, payment, or acceptance risk.
Citation. Guidelines, Rules and Laws Office of Management and Budget North Dakota
North Dakota Century Code t54c59 Information Technology Department
Category. `GOV` Authority type. Source document to verify against current official state authority before publication. Contractor nexus. Agency duty that affects vendors; may become a contractor duty through contract incorporation, system access, or technology approval.
In plain terms. This source identifies who in North Dakota government has authority over information technology, security policy, technology approval, or statewide digital operations. For contractors, that matters because the responsible office often controls the standards an agency must include in technology contracts.
Who it applies to. It primarily applies to state agencies and state technology officials. Contractors are affected when an agency uses that authority to set solicitation requirements, contract terms, security reviews, approval gates, or data-handling conditions.
What it requires. Contractors should use this source to identify the office that can require security documentation, technology approval, architecture alignment, data-protection terms, or compliance with statewide IT policies. Before bidding, map the solicitation to the responsible CIO, CISO, procurement, or technology office and preserve the approval record.
Why it matters. State IT governance sources often explain why a solicitation contains cybersecurity terms even when the statute does not mention contractors directly. Missing the governing office or approval path can create bid, performance, payment, or acceptance risk.
Citation. North Dakota Century Code t54c59 Information Technology Department
Regulations, Policies & Standards
These entries cover regulations, procurement manuals, IT policies, security standards, contract templates, terms and conditions, and agency guidance that may become binding when incorporated into a solicitation, purchase order, master agreement, statement of work, data-use agreement, or other contract document.
Cyber Security, Governance, Risk and Compliance Services North Dakota Information Technology
Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.
Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.
What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.
Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.
Citation. Cyber Security, Governance, Risk and Compliance Services North Dakota Information Technology
Data Classification Policy
Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source explains how North Dakota buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.
Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.
What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.
Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.
Citation. Data Classification Policy
Electronic Records Management Guidelines North Dakota Information Technology
Category. `RECMGT` Authority type. State government source. Contractor nexus. Conditional contractor relevance; include only where the contract or data workflow makes the source applicable.
In plain terms. This source concerns records, information management, retention, or data handling. For contractors, it matters when the contract requires the company to create, store, preserve, return, or destroy state records.
Who it applies to. It primarily applies to state agencies and records officials, but contractors are affected when the contract makes them custodians, processors, hosts, or maintainers of state records.
What it requires. Contractors should identify record types, retention periods, access restrictions, backup duties, return or destruction obligations, and audit evidence before performance begins.
Why it matters. Records obligations can survive contract closeout. They also affect incident response, litigation holds, audit readiness, and agency acceptance of deliverables.
Citation. Electronic Records Management Guidelines North Dakota Information Technology
Electronic Signature Guidelines North Dakota Information Technology
Category. `ETXN` Authority type. State government source. Contractor nexus. Conditional contractor relevance; include only where the contract or data workflow makes the source applicable.
In plain terms. This source supports electronic records, electronic signatures, or digital transactions with the state. For contractors, it matters when bids, certifications, invoices, notices, approvals, or contract records are created or signed electronically.
Who it applies to. It may apply to state agencies, public bodies, contractors, and other parties that use electronic records or signatures in state business.
What it requires. Contractors should preserve signed records, system confirmations, timestamps, approval trails, and identity or authorization evidence. If the contract specifies an electronic procurement platform or signature method, follow that method exactly.
Why it matters. Electronic transaction rules help prove who agreed to what and when. That evidence can matter in bid disputes, contract administration, payment disputes, and audit reviews.
Citation. Electronic Signature Guidelines North Dakota Information Technology
Information Technology Procurement Standard North Dakota Information Technology
Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source explains how North Dakota buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.
Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.
What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.
Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.
Citation. Information Technology Procurement Standard North Dakota Information Technology
IT Review North Dakota Information Technology
Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source explains how North Dakota buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.
Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.
What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.
Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.
Citation. IT Review North Dakota Information Technology
IT Standards North Dakota Information Technology
Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source explains how North Dakota buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.
Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.
What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.
Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.
Citation. IT Standards North Dakota Information Technology
NDIT Business Plan 2023-2025 North Dakota Information Technology
Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source explains how North Dakota buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.
Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.
What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.
Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.
Citation. NDIT Business Plan 2023-2025 North Dakota Information Technology
procurement-it-guidelines-jul-2024
Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source explains how North Dakota buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.
Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.
What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.
Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.
Citation. procurement-it-guidelines-jul-2024
State of North Dakota Procurement Manual
Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.
In plain terms. This source explains how North Dakota buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.
Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.
What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.
Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.
Citation. State of North Dakota Procurement Manual
Statewide IT Plan 2023-2025 North Dakota Information Technology
Category. `GOV` Authority type. State government source. Contractor nexus. Agency duty that affects vendors; may become a contractor duty through contract incorporation, system access, or technology approval.
In plain terms. This source identifies who in North Dakota government has authority over information technology, security policy, technology approval, or statewide digital operations. For contractors, that matters because the responsible office often controls the standards an agency must include in technology contracts.
Who it applies to. It primarily applies to state agencies and state technology officials. Contractors are affected when an agency uses that authority to set solicitation requirements, contract terms, security reviews, approval gates, or data-handling conditions.
What it requires. Contractors should use this source to identify the office that can require security documentation, technology approval, architecture alignment, data-protection terms, or compliance with statewide IT policies. Before bidding, map the solicitation to the responsible CIO, CISO, procurement, or technology office and preserve the approval record.
Why it matters. State IT governance sources often explain why a solicitation contains cybersecurity terms even when the statute does not mention contractors directly. Missing the governing office or approval path can create bid, performance, payment, or acceptance risk.
Citation. Statewide IT Plan 2023-2025 North Dakota Information Technology
Third-Party Risk Management North Dakota Information Technology
Category. `CYBER` Authority type. State government source. Contractor nexus. Agency duty that affects vendors; may become a contractor duty through contract incorporation, system access, or technology approval.
In plain terms. This source describes North Dakota's cybersecurity or information-security baseline for state systems, state data, or agency technology. A contractor should read it as the state's security expectation unless the contract narrows, expands, or replaces it.
Who it applies to. It primarily applies to state agencies, technology offices, system owners, and security officials. Contractors are affected when they host, process, transmit, store, or access state data or connect products and services to a state environment.
What it requires. Before performance, confirm whether the contract incorporates this policy or standard. Maintain evidence that can show how the company protects accounts, access, devices, data, logging, incident response, subcontractors, and any cloud or managed service used for the state work.
Why it matters. Cybersecurity policy can become a contract-performance requirement. If a contractor treats it as background only after the contract incorporates it, the contractor may face corrective action, rejection of deliverables, audit findings, termination risk, or future responsibility concerns.
Citation. Third-Party Risk Management North Dakota Information Technology
Cross-State Procurement Context
NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding North Dakota law unless a North Dakota statute, regulation, policy, solicitation, or contract adopts them.
For GovConCyber implementation, use this callout to help readers understand why a state may ask for cybersecurity documentation even when the state code is not written like a federal cybersecurity clause. Do not cite NASPO, NASCIO, CIS, or StateRAMP materials as the source of a binding state requirement unless the specific state has adopted or incorporated them.
Cross-state procurement context
NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding North Dakota law unless a North Dakota statute, regulation, policy, solicitation, or contract adopts them.