Loading chat...

AZ HB2809

Bill

Status

Engrossed

2/26/2026

Primary Sponsor

John Gillette

Click for details

Origin

House of Representatives

Fifty-seventh Legislature - Second Regular Session (2026)

AI Summary

  • Requires Arizona to implement a statewide post-quantum encryption cybersecurity system that meets or exceeds Department of Defense CMMC 2.0 certification standards across all state agencies handling personal information, election data, public safety, finance, or confidential data.

  • Restricts cybersecurity system procurement to 100% U.S.-based vendors with software, hardware, and cryptographic components developed, manufactured, and maintained exclusively in the United States, excluding any companies with foreign parent companies, subsidiaries, or data dependencies.

  • Designates the Auditor General as independent custodian of master encryption keys, responsible for establishing secure key management procedures, conducting periodic compliance audits, certifying system installations, and reporting noncompliance to the Governor, legislature, and Attorney General.

  • State agencies must install the post-quantum encryption system, validate operational effectiveness with the Auditor General, and maintain continuous compliance; noncompliant agencies face mandatory corrective action plans, legislative oversight hearings, and potential IT budget restrictions.

  • Vendors awarded contracts must provide technical training, support installation and audit activities, demonstrate CMMC 2.0 compliance, and may face suspension or contract termination for noncompliance.

Legislative Description

Statewide cybersecurity encryption system; requirements

Requirements

Last Action

Senate read second time

3/10/2026

Committee Referrals

Rules3/9/2026
Appropriations, Transportation and Technology2/26/2026
Rules1/21/2026
Science & Technology1/21/2026

Full Bill Text

No bill text available