- Services
- Products
-
-
- Online Training
- Information Security Awareness Training Course
- PCI DSS Compliance Bundle
- GLBA Awareness Training Course
- CMMC Training Course
- HIPAA Awareness Training Course
- Data Privacy Training Course
- Payments Security Training Course
- Phishing Awareness Training Course
- GDPR Training Course
- FERPA Training Course
- FACTA Training Course
- Online Training
-
- Compliance
- Markets
- Insights
- About
Cybersecurity requirements for Maryland K-12 school systems are changing. With the passage of House Bill 957, also known as Chapter 34, local school systems now face new responsibilities related to cybersecurity leadership, security standards, maturity assessments and compliance certification.
The law was approved by Governor Wes Moore on April 14, 2026, and took effect on July 1, 2026. While some requirements are already in effect, the law establishes additional cybersecurity compliance obligations beginning in 2027.
For school and district leaders, the new requirements create an important opportunity to evaluate current cybersecurity practices and prepare before the first certification deadline arrives.
What Does Maryland HB 957 Require?
HB 957, titled “Cybersecurity – Standards and Compliance – Alterations,” establishes several new cybersecurity requirements for Maryland local school systems.
The law requires each local school system to:
- Designate a local point of contact for cybersecurity-related communications.
- Comply with Maryland’s state minimum cybersecurity standards beginning in 2027.
- Conduct a cybersecurity maturity assessment every two years.
- Certify compliance with the State minimum cybersecurity standards every two years.
- Stay prepared for annual updates to the state’s cybersecurity standards.
These requirements make cybersecurity an ongoing responsibility rather than a one-time compliance exercise.
1. Designate a Cybersecurity Point of Contact
One of the first requirements for local school systems is to designate a local point of contact for cybersecurity-related communications.
The school system must notify Maryland’s State Chief Information Security Officer of the designated contact and provide updates when that designation changes.
For school systems, this role can help establish clear ownership for cybersecurity communications. Having a designated contact can also make it easier to coordinate with state officials, technology teams, administrators, and other stakeholders when cybersecurity concerns arise.
School systems should make sure the designated individual understands their responsibilities and has a clear process for receiving and responding to cybersecurity communications.
2. Prepare for State Cybersecurity Standards
Beginning in 2027, Maryland local school systems must comply with the state minimum cybersecurity standards established by the Department of Information Technology (DoIT).
This shift is significant for K-12 organizations because compliance will require more than individual security tools. School systems will need to understand how their policies, procedures, technology, and security practices align with the state’s standards.
Maryland DoIT has previously published a State Minimum Cybersecurity Standards Best Practices Guidebook designed to provide a foundation for developing cybersecurity maturity and supporting compliance efforts. The guidebook includes areas such as cybersecurity governance, access management, vulnerability management, and other security practices.
Because cybersecurity requirements can change, school systems should avoid treating compliance as a checklist that is completed once and then forgotten.
3. Conduct a Cybersecurity Maturity Assessment Every Two Years
Starting in 2027, each local school system must conduct a cybersecurity maturity assessment every two years.
A maturity assessment can help school and technology leaders understand where their current cybersecurity program stands, identify gaps, and prioritize improvements.
For K-12 organizations, this type of assessment can provide visibility into areas such as:
- Governance and cybersecurity policies
- Identity and access management
- Network security
- Vulnerability management
- Incident response
- Data protection
- Security awareness and training
- Third-party and vendor risk
- Business continuity and recovery
The goal should not simply be to identify weaknesses. A useful assessment should help school systems determine which improvements should be addressed first based on risk, available resources, and operational priorities.
4. Certification Becomes a Recurring Requirement
The law also establishes a recurring cybersecurity compliance certification requirement.
On or before June 30, 2027, and every two years thereafter, each local school system must certify to the Office of Security Management within Maryland’s Department of Information Technology that it complies with the state minimum cybersecurity standards.
This makes preparation especially important during the months leading up to the first certification deadline.
Rather than waiting until 2027 to begin evaluating cybersecurity practices, school systems can use this time to identify gaps, document existing controls, and establish a plan for addressing areas that need improvement.
5. Cybersecurity Standards May Continue to Change
Another important part of HB 957 is that Maryland’s Office of Security Management must review the state minimum cybersecurity standards annually and update them when necessary.
For school systems, this means cybersecurity compliance should be viewed as an ongoing process.
Technology changes quickly. Threats change even faster. New vulnerabilities, attack methods, and security risks can affect school systems at any time. Annual review of the state’s standards allows Maryland to adjust its expectations as the cybersecurity landscape evolves.
For K-12 leaders, staying informed about changes to the standards will be an important part of maintaining compliance.
What Should Maryland School Systems Do Now?
Although the major compliance requirements begin in 2027, school systems do not need to wait until then to start preparing. Here are some actions to take now:
-
Identify the Cybersecurity Point of Contact
Confirm who will serve as the local cybersecurity point of contact and establish a process for managing cybersecurity-related communications.
-
Review Current Cybersecurity Practices
Take an inventory of existing policies, procedures, technologies, and security controls. Identify areas that may need additional attention before the first certification deadline.
-
Establish a Cybersecurity Maturity Baseline
Conduct an assessment of the current cybersecurity program to understand strengths, weaknesses, and potential gaps. Establishing a baseline can make it easier to measure progress over time.
-
Map Existing Controls to State Standards
Compare current cybersecurity practices with Maryland’s state minimum cybersecurity standards. This can help identify areas where documentation, technology, or processes may need to be strengthened.
-
Develop a Remediation Plan
Not every cybersecurity gap can be addressed immediately. Prioritize findings based on risk and create a realistic remediation roadmap that identifies responsibilities, timelines, and resources.
-
Document the Work
Documentation will become increasingly important as school systems prepare for recurring assessments and compliance certifications. Maintain records of assessments, policies, remediation efforts, and other evidence demonstrating that cybersecurity practices are being maintained.
Why This Matters for K-12 Cybersecurity
Schools are responsible for protecting a wide range of sensitive information while maintaining technology environments that support students, teachers, and administrators.
Student records, employee information, financial data, and other valuable data can make school systems attractive targets for cybercriminals. At the same time, schools often operate complex technology environments with limited resources and large numbers of users.
HB 957 places greater emphasis on establishing a consistent cybersecurity foundation across Maryland’s local school systems.
The law’s requirements also reinforce an important principle of cybersecurity: compliance should support security, not replace it.
Meeting a regulatory requirement is important, but a mature cybersecurity program should ultimately help an organization reduce risk, respond to incidents, and protect the people and information it serves.
Preparing for 2027 and Beyond
Maryland school systems have an opportunity to use the time before the first certification deadline to build a stronger cybersecurity program.
The first step is understanding where the organization stands today. From there, school leaders can identify gaps, prioritize improvements, and establish processes for maintaining compliance as state standards evolve.
With the first certification deadline set for June 30, 2027, preparation should begin now rather than waiting until the deadline approaches.
Cybersecurity compliance is not a one-time project. It requires continuous evaluation, documentation, and improvement. By approaching HB 957 as part of a broader cybersecurity maturity strategy, Maryland K-12 organizations can work toward both regulatory compliance and stronger protection against evolving cyber threats.
If your school system needs help preparing for Maryland’s new cybersecurity requirements, CampusGuard can help you assess your current security posture, identify gaps, and develop a clear path toward compliance.
Contact CampusGuard to learn more about how we can support your K-12 cybersecurity and compliance needs.