Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / Compliance

Compliance

What Ohio House Bill 96 Means for Local Governments and School Districts Before 2026

Ohio HB 96 sets January 1 and July 1, 2026 deadlines for local governments and school districts to build CIS Controls cybersecurity programs.

Ric Hall By Ric Hall Updated Sep 2026 2 min read Share

Ohio House Bill 96 requires every county, city, village, township, and school district in the state to build a cybersecurity program modeled on the CIS Controls, report qualifying security incidents to the Ohio Cyber Integration Center within seven days of discovery, and hit compliance deadlines that land on January 1 and July 1, 2026. The Auditor of State's office is already reviewing readiness, which means the window to prepare is closing faster than most boards realize.

What Does Ohio House Bill 96 Actually Require?

HB 96 imposes a formal cybersecurity program requirement on Ohio's political subdivisions, a category that includes local governments and public school districts. As Dinsmore & Shohl explains in its analysis of the law, the requirements are not aspirational language buried in a budget bill. They are specific obligations tied to a named framework, a defined reporting window, and an oversight body that already has audit authority over how public entities spend and manage public resources.

The law does not ask districts and municipalities to invent their own security standard. It points them directly at an existing one, which is both a relief and a forcing function, since there is no ambiguity left about what

Tagged Under Compliance

Join The Conversation

Have a question or perspective on this topic? Add it below.

Ric Hall

About The Author

Ric Hall · Chief Revenue Officer

Ric Hall is the Chief Revenue Officer at Securafy, with decades of experience in enterprise infrastructure, cloud technology, sales leadership, and business strategy.

He writes for leaders trying to make sense of big technology decisions without getting trapped in vague promises or polished sales language. His articles cover provider selection, IT budgeting, co-managed services, cybersecurity investments, modernization, and the questions businesses should ask before signing a contract.

Ric’s strength is connecting technical decisions to business outcomes, helping leaders understand not just what they are buying, but why it matters and whether it will still make sense 3 years from now.

Writes about: IT budgeting, provider evaluation, cybersecurity ROI, co-managed IT, cloud modernization, vendor selection, technology strategy

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime