Ohio's House Bill 96 requires every political subdivision, meaning cities, counties, townships, and school districts, to adopt a formal, documented cybersecurity program aligned to a recognized framework such as NIST CSF or the CIS Controls. It also requires 7-day and 30-day incident reporting and restricts ransomware payments without a public vote.
Key dates
- Incident reporting has been required since September 30, 2025.
- Counties and cities were required to adopt a program by January 1, 2026.
- School districts and other subdivisions were required to adopt a program by July 1, 2026.
Both adoption deadlines have now passed. A subdivision that has not yet adopted a documented, framework-aligned program is past the date the law set, and the reporting requirements apply either way. If that describes you, the task now is to adopt a program and document it, rather than wait for an audit or an incident to expose the gap.
How Tech Dynamix helps you meet HB 96
- Framework-aligned cyber program: policies, standards, and controls mapped to NIST CSF or CIS, sized for your staff, systems, and budget
- Threat detection and response: around-the-clock monitoring, EDR and SIEM tuning, playbooks, and tabletop exercises, so your team knows what to do on the first day of an incident
- Incident reporting and governance: the 7-day and 30-day workflows put into practice, with the documentation and approvals a ransomware decision would need
- Annual staff training: role-based awareness that turns your people into a first line of defense
- Resilient infrastructure: network hardening, MFA, secure backups, and recovery plans that get you back online without paying a ransom
Based in Northeast Ohio, Tech Dynamix works with municipalities and K-12 districts to build practical roadmaps, put controls in place, and stay audit-ready, so you can get back to serving your community.
We can help you get compliant. Contact us to schedule an HB 96 readiness assessment and a plan matched to your subdivision.