Ohio House Bill 96 requires every county, city, village, township, and school district in the state to build a cybersecurity program modeled on the CIS Controls, report qualifying security incidents to the Ohio Cyber Integration Center within seven days of discovery, and hit compliance deadlines that land on January 1 and July 1, 2026. The Auditor of State's office is already reviewing readiness, which means the window to prepare is closing faster than most boards realize.
What Does Ohio House Bill 96 Actually Require?
HB 96 imposes a formal cybersecurity program requirement on Ohio's political subdivisions, a category that includes local governments and public school districts. As Dinsmore & Shohl explains in its analysis of the law, the requirements are not aspirational language buried in a budget bill. They are specific obligations tied to a named framework, a defined reporting window, and an oversight body that already has audit authority over how public entities spend and manage public resources.
The law does not ask districts and municipalities to invent their own security standard. It points them directly at an existing one, which is both a relief and a forcing function, since there is no ambiguity left about what
By Ric Hall
Join The Conversation
Have a question or perspective on this topic? Add it below.