Skip to main content
State profile

Oregon

Procurement agency: Oregon Department of Administrative Services (DAS), State Procurement Services

Last reviewedJune 28, 2026Version v1

Plain-English Summary

Oregon ties contractor cybersecurity obligations to procurement rules, IT standards, privacy/breach law, and contract terms rather than a single contractor-facing cybersecurity statute. Vendors that sell IT, cloud, software, data, or professional services to state agencies should read solicitations and contracts carefully and confirm which security, privacy, audit, insurance, and incident-reporting duties are incorporated.

Contractor Quick-Reference Matrix

TopicWhere it usually shows up for vendorsWhat to capture in your file
ProcurementDAS Procurement Services rules, statewide price agreements, agency solicitations.Solicitation, evaluation criteria, standard terms, IT addenda, security questionnaires.
IT standardsDAS Enterprise Information Services policies and standards.Configuration, access, logging, encryption, identity, and cloud usage expectations.
Privacy and breachOregon Consumer Information Protection Act and related statutes.Breach notification triggers, definitions of personal information, contact protocols.
Contract termsWhether cybersecurity, privacy, incident reporting, audit, insurance, and subcontractor duties are incorporated.Clause matrix, flowdown terms, subcontractor certifications, incident contact list.

Cybersecurity statutes (background)

Oregon source materials in the uploaded archive did not clearly identify a standalone contractor-facing cybersecurity statute for this page. Security requirements appear to flow primarily through procurement documents, IT policies, privacy/breach laws, or contract terms.

Regulations, Policies & Standards

These entries cover regulations, procurement manuals, IT policies, security standards, contract templates, terms and conditions, and agency guidance that may become binding when incorporated into a solicitation, purchase order, master agreement, statement of work, data-use agreement, or other contract document.

107-004-052 Cyber and Information Security

Category. `PROC-CYBER` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. 107-004-052 Cyber and Information Security

107-004-160 Enterprise Information Services

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Oregon buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. 107-004-160 Enterprise Information Services

Contract for Goods

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Oregon buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. Contract for Goods

Data Governance Maturity Model

Category. `RECMGT` Authority type. State government source. Contractor nexus. Conditional contractor relevance; include only where the contract or data workflow makes the source applicable.

In plain terms. This source concerns records, information management, retention, or data handling. For contractors, it matters when the contract requires the company to create, store, preserve, return, or destroy state records.

Who it applies to. It primarily applies to state agencies and records officials, but contractors are affected when the contract makes them custodians, processors, hosts, or maintainers of state records.

What it requires. Contractors should identify record types, retention periods, access restrictions, backup duties, return or destruction obligations, and audit evidence before performance begins.

Why it matters. Records obligations can survive contract closeout. They also affect incident response, litigation holds, audit readiness, and agency acceptance of deliverables.

Citation. Data Governance Maturity Model

Department of Administrative Services Oregon Law Procurement Services State of Oregon Laws and Policies

Category. `PROC-CYBER` · `PROC-IT` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Department of Administrative Services Oregon Law Procurement Services State of Oregon Laws and Policies

Department of Administrative Services Site Map Oregon Procurement Manual State of Oregon

Category. `PROC-CYBER` · `PROC-IT` · `CYBER` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source connects cybersecurity to procurement or contract performance. It is especially important when a contractor provides IT, cloud, software, managed services, security services, data processing, or access to state systems.

Who it applies to. It may apply directly to vendors or indirectly through state agencies that must include security terms in solicitations and contracts. Subcontractors can be affected when the prime contract requires flowdown.

What it requires. Before bidding or performance, identify the security controls, questionnaires, certifications, incident-reporting contacts, access restrictions, confidentiality duties, cloud requirements, audit rights, and subcontractor obligations that the state expects. Keep written evidence showing how each requirement is satisfied.

Why it matters. These sources are often the closest state-law analogue to federal contract cybersecurity clauses. They translate general security policy into contract terms that can affect award, performance, remedies, and future responsibility.

Citation. Department of Administrative Services Site Map Oregon Procurement Manual State of Oregon

eis-css-statewide-information-technology(IT)-control-standards

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Oregon buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. eis-css-statewide-information-technology(IT)-control-standards

IT Statutes

Category. `PROC-IT` Authority type. State government source. Contractor nexus. Contract clause / flowdown; direct vendor relevance when incorporated into the solicitation or contract.

In plain terms. This source explains how Oregon buys technology, services, software, hardware, cloud offerings, or related support. For contractors, it tells you where security requirements may enter the deal: the solicitation, evaluation criteria, standard terms, approval process, or contract documents.

Who it applies to. It applies to state purchasing officials and agencies, and it affects vendors that sell technology, data services, software, equipment, professional services, cloud services, or support to the state.

What it requires. Contractors should read the solicitation and all incorporated documents together. Confirm security representations, privacy terms, audit rights, insurance, subcontractor approval, data ownership, return or destruction terms, and incident-notice provisions before submitting a bid or signing the contract.

Why it matters. Procurement rules and standard terms often create the real contractor-facing cybersecurity duties. They can affect eligibility, responsiveness, evaluation, award, contract administration, payment, and post-award oversight.

Citation. IT Statutes

Cross-State Procurement Context

NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding Oregon law unless a Oregon statute, regulation, policy, solicitation, or contract adopts them.

For GovConCyber implementation, use this callout to help readers understand why a state may ask for cybersecurity documentation even when the state code is not written like a federal cybersecurity clause. Do not cite NASPO, NASCIO, CIS, or StateRAMP materials as the source of a binding state requirement unless the specific state has adopted or incorporated them.

Cross-state procurement context

NASPO and NASCIO materials are useful background for how states think about cybersecurity in public procurement. They support a practical approach: build security requirements into acquisition planning, solicitations, evaluation, contract terms, and post-award vendor oversight. They are not binding Oregon law unless a Oregon statute, regulation, policy, solicitation, or contract adopts them.