Colorado 2026 Regular Session Status: Enacted Bipartisan · 2 D · 1 R cosponsors

SB 185 — Enhance Security of Office of Information Technology

Last action — Governor Signed

  1. ✓
    Introduced
  2. ✓
    In Committee
  3. ✓
    Passed Senate
  4. ✓
    Passed House
  5. ✓
    To Executive
  6. 6
    Enacted

This bill has been enacted into law. Introduced May 01, 2026. Enacted.

Signed by Governor Jared Polis (Democratic) on June 02, 2026.

Odds of enactment

High chance

Based on the sponsor, cosponsors, and committee posture, this bill has a high chance of becoming law.

Upgrade to see the exact probability and what's driving it.

A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.

Prognosis

Likely to advance 98% · high confidence
  • Enacted

    Current position in the legislative process.

  • 12 sponsors

    5 primary, 7 co-sponsors signed on.

  • Bipartisan support

    Sponsored across 2 parties (2 D · 1 R) — cross-party backing.

  • Cleared a recorded vote

    Passed 6 recorded votes so far.

Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.

In plain language

The bill enhances the security oversight of Colorado's Office of Information Technology.

This legislation allows for additional audits of the Office of Information Technology if security compliance issues persist. It also mandates that the office maintain updated vendor contracts and submit annual reports on security compliance and risks.

What this means for you
  • Workers: This means workers will benefit from improved security measures protecting the state's information technology systems.

Summary

The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding.     If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit.     The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies.     The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data.     The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually.     The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer.     The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor.     The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information.     The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)

Bill Text

What changed in the latest version

265 added · 354 removed

Plain-language change summary

The recent amendment to SB 185 added a note indicating that the bill is ready for the signatures of legislative officers and the Governor, and provided guidance on how to check the bill's status. Additionally, the bill now allows the Joint Technology Committee to call the Chief Information Security Officer to provide testimony regarding compliance reports on information technology security. These changes aim to improve oversight and accountability in information security procedures, ensuring that security measures are adequately addressed and followed.

→
Previous
Latest
Second Regular Session Seventy-fifth General Assembly STATE OF COLORADO REREVISED This Version Includes All Amendments Adopted in the Second House LLS NO.
NOTE:
26-0979.02 Nicole Myers x4326 SENATE BILL 26-185 SENATE SPONSORSHIP Marchman and Baisley, Coleman HOUSE SPONSORSHIP Titone and Keltie, Paschal, Bacon, Carter, Clifford, Jackson, Marshall, Rutinel e n m 2 E n 2 U U 3 O i 1 H a a Senate Committees House Committees R M Business, Labor, & Technology State, Civic, Military, & Veterans Affairs r Appropriations Appropriations 3 d A BILL FOR AN ACT d e 2 C ONCERNING MEASURES TO ENHANCE THE OFFICE OF INFORMATION S a 2 U U 1 TECHNOLOGY S SECURITY PROCEDURES .
This bill has been prepared for the signatures of the appropriate legislative officers and the Governor.
H g y d M e Bill Summary d (Note:
To determine whether the Governor has signed the bill or taken other action on it, please consult the legislative status sheet, the legislative history, or the Session Laws.
This summary applies to this bill as introduced and does notreflectanyamendmentsthatmaybesubsequentlyadopted.Ifthisbill d passes third reading in the house of introduction, a bill summary that e m 2 applies to the reengrossed version of this bill will be available at T n 2 http://leg.colorado.gov/.) N g 8 E i y S e M Joint Technology Committee.
SENATE BILL 26-185 BY SENATOR(S) Marchman and Baisley, Coleman;
The bill allows the joint R r technology committee (JTC), within 90 days after the day that the chief 3 information security officer of the office of information technology (securityofficer)filesawritteninformationtechnologycompliancereport (compliancereport)withtheJTCasrequiredbythebill,tovotetorequest i a that the legislative audit committee direct the state auditor to conduct a e 2 T d 0 A n , E d y Shading denotes HOUSE amendment.
also REPRESENTATIVE(S) Titone and Keltie, Paschal, Bacon, Carter, Clifford, Jackson, Marshall, Rutinel.
Double underlining denotes SENATE amendment.
CONCERNING MEASURES TO ENHANCE THE OFFICE OF INFORMATION TECHNOLOGY S SECURITY PROCEDURES .
S d a Capital letters or bold & italic numbers indicate new material to be added to existing law.n M Dashes through the words or numbers indicate deletions from existing law.
m A special information technology security audit (IT security audit) of the officeofinformationtechnology(OIT)ifthecompliancereportindicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding.
If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the bill requires:
! The state auditor to conduct the IT security audit;
! The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;
! The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor;
and ! OIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit.
The bill requires OIT to establish, maintain, keep, update, and makeavailabletostateagencyinformationtechnologyleadershipandthe members of the JTC, a list of all active information technology vendor contracts for state agencies.
The bill specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technologystandard, and that the standard is void, unless the standard:
! Was publicly posted;
and ! Received approval fromthe securityofficerif the standard relates to security, access controls, or the handling of data.
The bill requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, that the contract maintains current architecture diagrams that are updated at least annually.
The bill prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer.
The bill requires the securityofficer to submit 2 annual reports to theJTC.ThefirstreportisawrittencompliancereportthatincludesOIT's current compliance status with applicable security standards;
all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made;
and a timeline for remediationandamitigationplanorcompensationcontrolsforeachopen audit recommendation made by the state auditor.
The second report is a written statewide information technology securityriskreport(securityriskreport)thatassesses the overall security risk posture of state agencyinformation technology systems.
To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, -2- 185 including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews.
Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information.
The bill requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.
Powersanddutiesofthejointtechnologycommittee.
Powers and duties of the joint technology committee.
(13) THE COMMITTEE MAY CALL THE CHIEF INFORMATION SECURITY OFFICER TO TESTIFY BEFORE THE COMMITTEE REGARDING THE WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT THATTHECHIEFINFORMATIONSECURITYOFFICERISREQUIREDTOSUBMIT TO THE COMMITTEE PURSUANT TO SECTION 24-37.5-403 (2)(j).
(13) THECOMMITTEEMAYCALLTHECHIEFINFORMATIONSECURITY OFFICER TO TESTIFY BEFORE THE COMMITTEE REGARDING THE WRITTEN INFORMATIONTECHNOLOGYSECURITYCOMPLIANCEREPORTTHATTHECHIEF INFORMATION SECURITY OFFICER IS REQUIRED TO SUBMIT TO THE COMMITTEE PURSUANT TO SECTION 24-37.5-403 (2)(j).
(14) W ITHIN NINETY DAYS AFTER THE DAY THAT THE CHIEF INFORMATION SECURITY OFFICER OF THE OFFICE OF INFORMATION TECHNOLOGY FILES A WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT AS REQUIRED BY SECTION 24-37.5-403 (2)(jTHE COMMITTEE MAY VOTE TO FORMALLY REQUEST THAT THE LEGISLATIVE AUDIT COMMITTEE ,PURSUANT TO SECTION 2-3-108,VOTE TO DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT OF THE OFFICE IN ACCORDANCE WITH THE STATE AUDITOR 'S AUTHORITY RELATED TO INFORMATION TECHNOLOGY SYSTEMS AS DESCRIBED IN SECTION 2-3-103 (1.5),F:
(14) W ITHIN NINETY DAYS AFTER THE DAY THAT THE CHIEF INFORMATION SECURITY OFFICER OF THE OFFICE OF INFORMATION ________ Capital letters or bold & italic numbers indicate new material added to existing law;
(a) T HE WRITTEN INFORMATION TECHNOLOGY SECURITY -3- 185 COMPLIANCEREPORTREQUIREDBYSECTION 24-37.5-403(2)(INDICATES THAT ONE OR MORE AUDIT RECOMMENDATIONS MADE BY THE STATE AUDITOR IS UNRESOLVED TWO OR MORE YEARS PAST THE IMPLEMENTATIONDATEFORTHEAUDITRECOMMENDATIONTOWHICHTHE OFFICE COMMITTED IN A PRIOR COMPLIANCE REPOR;OR (b) A MATERIAL DISCREPANCY EXISTS BETWEEN A REPRESENTATION MADE IN THE WRITTEN INFORMATION TECHNOLOGY SECURITYCOMPLIANCEREPORTREQUIREDBYSECTION 24-37.5-403(2)(j) AND A FINDING MADE IN A PREVIOUS AUDIT BY THE STATE AUDI.OR (15) (a) IA MAJORITY OF THE COMMITTEE VOTES TO REQUEST THAT THE LEGISLATIVE AUDIT COMMITTEE DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT PURSUANT TO SUBSECTION (14)OF THIS SECTION AND IF A MAJORITY OF THE LEGISLATIVE AUDIT COMMITTEEVOTESTOAPPROVEANAUDITPURSUANTTOSECTION 2-3-108, THE STATE AUDITOR SHALL CONDUCT THE INFORMATION TECHNOLOGY SECURITY AUDIT AND MAY CONTRACT WITH A QUALIFIED THIRD-PARTY INFORMATIONTECHNOLOGYSECURITYFIRMTOCONDUCTTHEAUDIT .THE STATE AUDITOR SHALL OBTAIN INPUT FROM THE OFFICE OF INFORMATION TECHNOLOGY WHEN THE STATE AUDITOR DETERMINES THE SCOPE AND BOUNDARIESOFTHEAUDIT ,TAKINGINTOCONSIDERATIONTHERESOURCES AVAILABLE TO THE OFFICE TO REIMBURSE THE AUDITOR FOR THE COST OF THE AUDIT PURSUANT TO SUBSECTION(15)(b)OF THIS SECTI.N (b) THE STATE AUDITOR SHAL,WITHIN TWELVE MONTHS OF THE AFFIRMATIVE VOTE OF A MAJORITY OF THE LEGISLATIVE AUDIT COMMITTEE ,PRODUCE AN INFORMATION TECHNOLOGY SECURITY AUDIT REPORT AND SUBMIT THE AUDIT REPORT TO THE LEGISLATIVE AUDIT COMMITTEE , AFTER WHICH THE STATE AUDITOR SHALL SUBMIT THE -4- 185 REPORT TO THE COMMITTEE ,THE JOINT BUDGET COMMITTEE ,AND THE GOVERNOR .
dashes through words or numbers indicate deletions from existing law and such material is not part of the act.
PURSUANT TO SECTION 2-3-110,THE OFFICE SHALL REIMBURSETHESTATEAUDITORFORANAUDITCONDUCTEDPURSUANTTO SUBSECTION (14)OF THIS SECTIO.
TECHNOLOGY FILES A WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT AS REQUIRED BY SECTION 24-37.5-403 (2)(jTHE COMMITTEE MAY VOTE TO FORMALLY REQUEST THAT THE LEGISLATIVE AUDIT COMMITTEE , PURSUANT TO SECTION 2-3-108,VOTE TO DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT OF THE OFFICE IN ACCORDANCE WITH THE STATE AUDITOR S AUTHORITY RELATED TO INFORMATION TECHNOLOGY SYSTEMS AS DESCRIBED IN SECTION 2-3-103 (1.5),F:
THE REIMBURSEMENT MAY BE PAID FROMTHETECHNOLOGYRISKPREVENTIONANDRESPONSEFUNDCREATED IN SECTION24-37.5-120.
(a) T HE WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT REQUIRED BY SECTION 24-37.5-403 (2)(jINDICATES THAT ONE OR MORE AUDIT RECOMMENDATIONS MADE BY THE STATE AUDITOR IS UNRESOLVED TWOORMORE YEARSPAST THE IMPLEMENTATION DATEFORTHEAUDITRECOMMENDATIONTOWHICHTHEOFFICECOMMITTED IN A PRIOR COMPLIANCE REPORT;OR (b) AMATERIALDISCREPANCYEXISTSBETWEENAREPRESENTATION MADE IN THEWRITTENINFORMATIONTECHNOLOGYSECURITY COMPLIANCE REPORT REQUIRED BY SECTION 24-37.5-403 (2)(AND A FINDING MADE IN A PREVIOUS AUDIT BY THE STATE AUDITOR (15)(a) IAMAJORITYOFTHECOMMITTEEVOTESTOREQUESTTHAT THE LEGISLATIVE AUDIT COMMITTEE DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT PURSUANT TO SUBSECTION (14) OF THIS SECTION AND IFA MAJORITYOFTHELEGISLATIVEAUDIT COMMITTEE VOTES TOAPPROVEANAUDITPURSUANTTOSECTION 2-3-108,THESTATEAUDITOR SHALLCONDUCTTHEINFORMATIONTECHNOLOGYSECURITYAUDITANDMAY CONTRACT WITH A QUALIFIED THIRD -PARTY INFORMATION TECHNOLOGY SECURITYFIRMTOCONDUCTTHEAUDIT .THESTATEAUDITORSHALLOBTAIN INPUT FROM THE OFFICE OF INFORMATION TECHNOLOGY WHEN THE STATE AUDITOR DETERMINES THE SCOPE AND BOUNDARIES OF THE AUDIT,TAKING INTO CONSIDERATION THE RESOURCES AVAILABLE TO THE OFFICE TO REIMBURSE THE AUDITOR FOR THE COST OF THE AUDIT PURSUANT TO SUBSECTION (15)(b)OF THIS SECTIO.
SECTION2.
(b) THE STATE AUDITOR SHALL ,WITHIN TWELVE MONTHS OF THE AFFIRMATIVEVOTEOFAMAJORITYOFTHELEGISLATIVEAUDITCOMMITTEE , PRODUCE AN INFORMATION TECHNOLOGY SECURITY AUDIT REPORT AND SUBMIT THE AUDIT REPORT TO THE LEGISLATIVE AUDIT COMMITTEEAFTER WHICHTHESTATEAUDITORSHALLSUBMITTHEREPORTTOTHECOMMITTEE , PAGE 2-SENATE BILL 26-185 THEJOINTBUDGETCOMMITTEE ,ANDTHEGOVERNOR .PURSUANTTOSECTION 2-3-110,THE OFFICE SHALL REIMBURSE THE STATE AUDITOR FOR AN AUDIT CONDUCTED PURSUANT TO SUBSECTION (14) OF THIS SECTION .
InColoradoRevisedStatutes,24-37.5-105,amend (3)(c), (3)(d), (6)(c), and (6)(d);
THE REIMBURSEMENT MAY BE PAID FROM THE TECHNOLOGY RISK PREVENTION AND RESPONSE FUND CREATED IN SECTION 24-37.5-120.
and add (3)(e), (4.5), and (6)(e) as follows:
SECTION 2.
In Colorado Revised Statutes, 24-37.5-105, amend (3)(c),(3)(d),(6)(c),and(6)(d);andadd(3)(f),(4.5),and(6)(e)asfollows:
(c) Assistthejointtechnologycommitteeasnecessarytofacilitate the committee's oversight of the office;
(c) Assist the joint technology committee as necessary to facilitate the committee's oversight of the office;
(e) (I) ETABLISH,MAINTAIN ,KEEP, QUARTERLY UPDATE , AND MAKE AVAILABLE TO STATE AGENCY INFORMATION TECHNOLOGY LEADERSHIP AND THE MEMBERS OF THE JOINT TECHNOLOGY COMMITTEE , A LIST OF ALL ACTIVE INFORMATION TECHNOLOGY VENDOR CONTRACTS FOR STATE AGENCIES AS DESCRIBED IN SUBSECTIO(6)OF THIS SECTIO.
(f)(I)ESTABLISH ,MAINTAIN KEEP ,QUARTERLYUPDATE ,ANDMAKE AVAILABLETOSTATEAGENCYINFORMATIONTECHNOLOGYLEADERSHIPAND THEMEMBERSOFTHEJOINTTECHNOLOGYCOMMITTEE ALISTOFALLACTIVE INFORMATION TECHNOLOGY VENDOR CONTRACTS FOR STATE AGENCIES AS DESCRIBED IN SUBSECTION (6)OF THIS SECTION.
FOREACHINFORMATIONTECHNOLOGYVENDORCONTRACT THELISTMUST INCLUDE :
FOR EACH INFORMATION TECHNOLOGY VENDOR CONTRACT ,THE LIST MUST INCLUDE :
(A) THE NAME OF THE VENDOR ;
(A) T HE NAME OF THE VENDOR ;
Show all 83 changed rows (43 more)
Previous
Latest
(B) THE VALUE OF THE CONTRACT;
(B) T HE VALUE OF THE CONTRACT ;
(C) THE DATE ON WHICH THE CONTRACT EXPIRES;AND (D) T HE DATA CLASSIFICATION-BUSINESS CRITICALITY TIER OF -5- 185 THE CONTRACT .
(C) T HE DATE ON WHICH THE CONTRACT EXPIRES ;AND (D) T HEDATACLASSIFICATION -BUSINESSCRITICALITYTIEROFTHE CONTRACT .
(II) IASTATEAGENCYINITIATESSOLICITATIONSANDCONTRACTS FORINFORMATIONTECHNOLOGYRESOURCESWITHPRIORAPPROVALOFTHE PROCUREMENTOFFICIALFORTHEOFFICEPURSUANTTOSUBSECTION (6)OF THIS SECTION, THE STATE AGENCY SHALL PROVIDE TO THE OFFICE THE INFORMATION SPECIFIED IN SUBSECTION (3)(e)(IOF THIS SECTION FOR EACH INFORMATION TECHNOLOGY VENDOR CONTRACT ,AND THE OFFICE SHALL INCLUDE THE INFORMATION IN THE LIST REQUIRED BY THIS SUBSECTION (3)(e).
(II) I A STATE AGENCY INITIATES SOLICITATIONS AND CONTRACTS FORINFORMATIONTECHNOLOGYRESOURCESWITHPRIORAPPROVALOFTHE PROCUREMENT OFFICIAL FOR THE OFFICE PURSUANT TO SUBSECTION (6)OF THIS SECTION, THE STATE AGENCY SHALL PROVIDE TO THE OFFICE THE PAGE 3-SENATE BILL 26-185 INFORMATIONSPECIFIEDINSUBSECTION (3)(f)(OFTHISSECTIONFOREACH INFORMATION TECHNOLOGY VENDOR CONTRACT ,AND THE OFFICE SHALL INCLUDE THE INFORMATION IN THE LIST REQUIRED BY THIS SUBSECTION (3)(f).
(III) THE OFFICE SHALL SUBMIT A ONE -TIME INFORMATION TECHNOLOGY BUDGET REQUEST TO THE JOINT TECHNOLOGY COMMITTEE FOR THE COST OF BUILDING AND IMPLEMENTING THE LIST REQUIRED BY THIS SUBSECTION (3)(e).F,AFTER THE BUDGET REQUEST IS APPROVED , THE OFFICE DETERMINES THAT MORE MONEY IS NEEDED TO IMPLEMENT AND MAINTAIN THE LIST ,THE OFFICE MAY REQUEST THAT THE GENERAL ASSEMBLY ALLOCATE ADDITIONAL MONEY FROM THE TECHNOLOGY RISK PREVENTION AND RESPONSE FUND CREATED IN SECTION 24-37.5-120.
(III) THE OFFICE SHALL SUBMIT A ONE TIME INFORMATION TECHNOLOGYBUDGETREQUESTTOTHEJOINTTECHNOLOGYCOMMITTEEFOR THE COST OF BUILDING AND IMPLEMENTING THE LIST REQUIRED BY THIS SUBSECTION (3)(f).F,AFTER THE BUDGET REQUEST IS APPROVED ,THE OFFICE DETERMINES THAT MORE MONEY IS NEEDED TO IMPLEMENT AND MAINTAIN THE LIST , THE OFFICE MAY REQUEST THAT THE GENERAL ASSEMBLY ALLOCATE ADDITIONAL MONEY FROM THE TECHNOLOGY RISK PREVENTION AND RESPONSE FUND CREATED IN SECTION 24-37.5-120.
(4.5) Technicalinformationtechnology standards.(a) EXCEPT AS OTHERWISE PROVIDED IN SUBSECTION (4.5)(bOF THIS SECTION,THE OFFICE SHALL NOT PUBLISH OR IMPLEMENT A TECHNICAL INFORMATION TECHNOLOGYSTANDARDTHATISESTABLISHEDPURSUANTTOSUBSECTION (4)OF THIS SECTION,AND THE STANDARD IS VOID,UNLESS:
(4.5) Technical information technology standards.
(I) THE OFFICE HAS PUBLICLY POSTED THE STANDARD;AND (II) THE CHIEF INFORMATION SECURITY OFFICER HAS APPROVED THE STANDARD , IF THE STANDARD RELATES TO SECURITY , ACCESS CONTROLS ,OR THE HANDLING OF DATA.
(a) EXCEPTASOTHERWISEPROVIDEDINSUBSECTION (4.5)(bOFTHIS SECTION, THE OFFICE SHALL NOT PUBLISH OR IMPLEMENT A TECHNICAL INFORMATIONTECHNOLOGYSTANDARDTHATISESTABLISHEDPURSUANTTO SUBSECTION (4)OF THIS SECTION,AND THE STANDARD IS VOID ,UNLESS:
(b) THE PROVISIONS OF SUBSECTION (4.5)(aOF THIS SECTION DO -6- 185 NOTAPPLYWHENTHECHIEFINFORMATIONSECURITYOFFICERDETERMINES IN WRITING THAT AN INFORMATION TECHNOLOGY SECURITY EMERGENCY EXISTS.
(I) THE OFFICE HAS PUBLICLY POSTED THE STANDARD ;AND (II) HECHIEFINFORMATIONSECURITYOFFICERHASAPPROVEDTHE STANDARD IFTHESTANDARDRELATESTOSECURITY ,ACCESSCONTROLS ,OR THE HANDLING OF DATA .
FOR PURPOSES OF THIS SUBSECTION (4.5),AN INFORMATION TECHNOLOGY SECURITY EMERGENCY MEANS A SITUATION IN WHICH AN IMMINENT OR ACTIVE THREAT TO STATE INFORMATION TECHNOLOGY SYSTEMS REQUIRES THE IMMEDIATE IMPLEMENTATION OF A SECURITY STANDARD TO PREVENT OR MITIGATE SIGNIFICANT HARM TO STATE DAT, SYSTEMS ,OR OPERATIONS.
(b) THEPROVISIONSOFSUBSECTION (4.5)(aOFTHISSECTIONDONOT APPLY WHEN THE CHIEF INFORMATION SECURITY OFFICER DETERMINES IN WRITING THAT AN INFORMATION TECHNOLOGY SECURITY EMERGENCY EXISTS.
(c) ITHEOFFICEIMPLEMENTSASECURITYSTANDARDINRESPONSE TO AN INFORMATION TECHNOLOGY SECURITY EMERGENCY PURSUANT TO SUBSECTION (4.5)(bOF THIS SECTION, THE OFFICE SHALL POST THE STANDARDONTHEOFFICE SWEBSITEWITHINSEVENTY -TWOHOURSOFTHE IMPLEMENTATION OF THE SECURITY STANDARD .
FOR PURPOSES OF THIS SUBSECTION (4.5),AN INFORMATION TECHNOLOGY SECURITY EMERGENCY MEANS A SITUATION IN WHICH AN IMMINENT OR ACTIVE THREAT TO STATE INFORMATION TECHNOLOGY SYSTEMS REQUIRES THE IMMEDIATE IMPLEMENTATION OF A SECURITY STANDARD TO PREVENT OR MITIGATE SIGNIFICANT HARM TO STATE DATA , SYSTEMS ,OR OPERATIONS .
ASECURITY STANDARD IMPLEMENTED PURSUANT TO SUBSECTION (4.5)(b)OF THIS SECTION EXPIRES NINETY DAYS AFTER IMPLEMENTATION UNLESS ,PRIOR TO EXPIRATION, THE OFFICE COMPLIES WITH THE REQUIREMENTS OF SUBSECTION (4.5)(aOF THIS SECTIO.
(c) ITHE OFFICE IMPLEMENTS A SECURITY STANDARD IN RESPONSE TO AN INFORMATION TECHNOLOGY SECURITY EMERGENCY PURSUANT TO SUBSECTION (4.5)(b)OF THIS SECTION , THE OFFICE SHALL POST THE PAGE 4-SENATE BILL 26-185 STANDARD ON THE OFFICE S WEBSITE WITHIN SEVENTY -TWO HOURS OF THE IMPLEMENTATION OF THE SECURITY STANDARD .
A SECURITY STANDARD IMPLEMENTEDPURSUANTTOSUBSECTION (4.5)(b) OFTHISSECTIONEXPIRES NINETY DAYS AFTER IMPLEMENTATION UNLESS ,PRIOR TO EXPIRATION ,THE OFFICECOMPLIESWITHTHEREQUIREMENTSOFSUBSECTION (4.5)(a)OFTHIS SECTION .
A state agency may initiate solicitations and contracts for information technology resources only with prior approval of the procurement official for the office, and must include provisions allowing the office to enforce technology and security standards or conductduediligenceorauditsofthecontractors.Ifthestateagencydoes notreceivewrittenapprovalordisapprovalfromtheprocurementofficial -7- 185 fortheofficewithinthirtybusinessdaysaftersubmittingtheprocurement request to the office for review, the state agency may assume that it has receivedthepriorapprovaloftheoffice,asrequiredbythissubsection(6), and is authorized to initiate the procurement or solicitation process.
A state agency may initiate solicitations and contracts for information technologyresources onlywith prior approval of the procurement official for the office, and must include provisions allowingtheofficetoenforcetechnologyandsecuritystandardsorconduct due diligence or audits of the contractors.
In connectionwiththeprocurementofinformationtechnologyresources,the office shall:
If the state agency does not receive written approval or disapproval from the procurement official for the office within thirty business days after submitting the procurement request to the office for review, the state agency may assume that it has received the prior approval of the office, as required bythis subsection (6), and is authorized to initiate the procurement or solicitation process.
(c) Overseeinformationtechnologyvendorsonbehalf of thestate and state agencies except when delegated to a state agency pursuant to section 24-37.5-105.4;
In connection with the procurement of information technologyresources, the office shall:
and (d) If the office does not have oversight of an information technologyorservicescontract,ensurethatthestateagencywithoversight of the contract operates pursuant to section 24-37.5-105.4 regarding the delegation of authority;
(c) Oversee information technology vendors on behalf of the state and state agencies except when delegated to a state agency pursuant to section 24-37.5-105.4;
(e) IACONTRACT PROVIDESONGOINGSERVICEANDDELIVERYTO C OLORADANS , ENSURE THAT THE CONTRACT MAINTAINS CURRENT ARCHITECTURE DIAGRAMS THAT ARE UPDATED AT LEAST ANNUALLY .
and (d) If the office does not have oversight of an information technologyor services contract, ensure that thestate agencywith oversight of the contract operates pursuant to section 24-37.5-105.4 regarding the delegation of authority;AND (e) IF A CONTRACT PROVIDES ONGOING SERVICE AND DELIVERY TO C OLORADANS , ENSURE THAT THE CONTRACT MAINTAINS CURRENT ARCHITECTURE DIAGRAMS THAT ARE UPDATED AT LEAST ANNUALLY .
SECTION 3.
SECTION3.
In Colorado Revised Statutes, 24-37.5-105.4, amend (1) introductory portion as follows:
InColoradoRevisedStatutes,24-37.5-105.4,amend (1) introductory portion as follows:
24-37.5-105.4.
PAGE 5-SENATE BILL 26-185 24-37.5-105.4.
(1) The chief information officer may delegate an information technologyfunction of the office to another state agencybyagreement or other means authorized by law,CEPT THAT THE CHIEF INFORMATION OFFICERSHALLNOTDELEGATEADUTY RESPONSIBILITYORPOWEROFTHE CHIEFINFORMATIONSECURITYOFFICER .Thechiefinformationofficermay delegate an information technology function of the office if in the judgment of the director of the state agency and the chief information officer:
(1) The chief information officer may delegate an information technology function of the office to another state agency by agreement or other means authorized by law, EXCEPT THAT THE CHIEF INFORMATION OFFICER SHALL NOT DELEGATE A DUTY ,RESPONSIBILITY ,OR POWER OF THE CHIEFINFORMATION SECURITY OFFICER .
-8- 185 SECTION4.
The chief information officer may delegateaninformationtechnologyfunctionoftheofficeifinthejudgment of the director of the state agency and the chief information officer:
InColoradoRevisedStatutes,24-37.5-403,amend (1), (2)(h), and (2)(i);
SECTION 4.
In Colorado Revised Statutes, 24-37.5-403, amend (1), (2)(h), and (2)(i);
(1) Thechiefinformationofficershallappointachiefinformation security officer who shall serve at the pleasure of the chief information officer.
(1) The chief information officer shall appoint a chief information security officer who shall serve at the pleasure of the chief information officer.
The security officer shall exhibit a background and expertise in security and risk management for communicationsand informatioTECHNOLOGY resources.Intheeventthe security officer is unavailable to perform the duties and responsibilities under this part 4, all powers and authority granted to the security officer may MUST be exercised by the chief information officer.
The security officer shall exhibit a background and expertise in security and risk management for communications and information TECHNOLOGY resources.
In the event the security officer is unavailable to perform the duties and responsibilities under this part 4, all powers and authority granted to the security officer may MUST be exercised by the chief information officer.
(h) In coordination and consultation with the office of state planning and budgeting and the chief information officer, review public agency budget requests related to information security systems and approve such budget requests for state agencies other than the legislative department;
(h) Incoordinationandconsultationwiththeofficeofstateplanning and budgeting and the chief information officer, review public agency budget requests related to information security systems and approve such budgetrequestsforstateagenciesotherthanthelegislativedepartment;and (i) Coordinate with the Colorado commission on higher education for purposes of reviewing and commenting TO REVIEW AND COMMENT on information security plans adopted by institutions of higher education that are submitted pursuant to section 24-37.5-404.5 (3);
and (i) CoordinatewiththeColoradocommissiononhighereducation for purposes of reviewing and commentingVIEWANDCOMMENT on informationsecurityplansadoptedbyinstitutionsofhighereducationthat are submitted pursuant to section 24-37.5-404.5 (3);
(j) SBMIT TO THE JOINT TECHNOLOGY COMMITTEE ,ON OR BEFORE N OVEMBER 1, 2027, AND ON OR BEFORE NOVEMBER 1 OF EACH YEAR PAGE 6-SENATE BILL 26-185 THEREAFTER , A WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT THAT INCLUDES THE FOLLOWING INFORMATION :
(j) SBMITTOTHEJOINTTECHNOLOGYCOMMITTEE ,ONORBEFORE N OVEMBER 1, 2027AND ON OR BEFORE NOVEMBER 1 OF EACH YEAR THEREAFTER , A WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT THAT INCLUDES THE FOLLOWING INFORMATION:
(I) THE OFFICS CURRENT COMPLIANCE STATUS WITH APPLICABLE SECURITY STANDARDS ;
-9- 185 (I) HEOFFICE'SCURRENT COMPLIANCESTATUSWITHAPPLICABLE SECURITY STANDARDS ;
(II) ALL OPEN AUDIT RECOMMENDATIONS MADE BY THE OFFICE OF THESTATEAUDITORANDTHEDATEONWHICHEACHRECOMMENDATIONWAS MADE ;
(II) ALOPENAUDIT RECOMMENDATIONSMADE BYTHE OFFICE OF THE STATE AUDITOR AND THE DATE ON WHICH EACH RECOMMENDATION WAS MADE ;
(III) A TIMELINE FOR REMEDIATION FOR EACH OPEN RECOMMENDATION MADE BY THE OFFICE OF THE STATE AUDITOR ;AND (IV) A MITIGATION PLAN OR COMPENSATING CONTROLS FOR THE REMEDIATION OF EACH OPEN RECOMMENDATION MADE BY THE OFFICE OF THE STATE AUDITOR;AND (k) (I) UBMIT TO THE JOINT TECHNOLOGY COMMITTEE ,ON OR BEFORE NOVEMBER 1,2027,ANDONORBEFORE NOVEMBER 1OFEACHYEAR THEREAFTER ,A WRITTEN STATEWIDE INFORMATION TECHNOLOGY SECURITY RISK REPORT THAT ASSESSES THE OVERALL SECURITY RISK POSTURE OF STATE AGENCY INFORMATION TECHNOLOGY SYSTEMS .
(III) A TIMELINE FOR REMEDIATION FOR EACH OPEN RECOMMENDATION MADE BY THE OFFICE OF THE STATE AUDITOR;AND (IV) A MITIGATION PLAN OR COMPENSATING CONTROLS FOR THE REMEDIATION OF EACH OPEN RECOMMENDATION MADE BY THE OFFICE OF THE STATE AUDITOR;AND (k) (I) SBMIT TO THE JOINT TECHNOLOGY COMMITTEE ,ON OR BEFORE N OVEMBER 1, 2027,AND ON OR BEFORE NOVEMBER 1OF EACH YEAR THEREAFTER ,A WRITTEN STATEWIDE INFORMATION TECHNOLOGY SECURITY RISK REPORT THAT ASSESSES THE OVERALL SECURITY RISK POSTURE OF STATE AGENCY INFORMATION TECHNOLOGY SYSTEMS .
(II) T SUPPORT THE PREPARATION OF THE SECURITY RISK REPORT REQUIRED BY SUBSECTION (2)(k)(I)OF THIS SECTION , THE CHIEF INFORMATION SECURITY OFFICER MAY CONDUCT EVALUATIONS OF STATE AGENCY INFORMATION TECHNOLOGY SYSTEMS AS THE CHIEFINFORMATION SECURITY OFFICER DEEMS NECESSARY,INCLUDING PENETRATION TESTING, VULNERABILITY SCANNING ,CONFIGURATION EVALUATIONS ,AND VENDOR AND SYSTEM REVIEWS .
(II) TSUPPORT THEPREPARATIONOFTHESECURITYRISKREPORT REQUIRED BY SUBSECTION (2)(k)(I)OF THIS SECTION, THE CHIEF INFORMATION SECURITY OFFICER MAY CONDUCT EVALUATIONS OF STATE AGENCYINFORMATIONTECHNOLOGYSYSTEMSASTHECHIEFINFORMATION SECURITYOFFICERDEEMSNECESSARY ,INCLUDINGPENETRATIONTESTING , VULNERABILITYSCANNING ,CONFIGURATIONEVALUATIONS ,ANDVENDOR AND SYSTEM REVIEWS .
(III) EACH STATE AGENCY SHALL PROVIDE TO THE CHIEF INFORMATION SECURITY OFFICER , UPON REQUEST , THE ACCESS AND INFORMATION NECESSARY TO CONDUCT EVALUATIONS PURSUANT TO SUBSECTION (2)(k)(IIOF THIS SECTION, INCLUDING SYSTEM ACCESS , PRODUCT INFORMATION ,AND ARCHITECTURE INFORMATION .
(III) EACH STATE AGENCY SHALL PROVIDE TO THE CHIEF INFORMATION SECURITY OFFICER , UPON REQUEST ,THE ACCESS AND INFORMATION NECESSARY TO CONDUCT EVALUATIONS PURSUANT TO SUBSECTION (2)(k)(IIOF THIS SECTION,INCLUDING SYSTEM ACCESS , PRODUCT INFORMATION ,AND ARCHITECTURE INFORMATION .
(4) T HE CHIEF INFORMATION SECURITY OFFICER, OR THE CHIEF INFORMATION OFFICER IF THE SECURITY OFFICER IS UNAVAILABLESHALL PERFORMTHEDUTIESANDUPHOLDTHERESPONSIBILITIESASSIGNEDTOTHE PAGE 7-SENATE BILL 26-185 CHIEF INFORMATION SECURITY OFFICER PURSUANT TO THIS PART 4.
-10- 185 (4) T HE CHIEF INFORMATION SECURITY OFFICER, OR THE CHIEF INFORMATION OFFICER IF THE SECURITY OFFICER IS UNAVAILAB,SHALL PERFORMTHEDUTIESANDUPHOLDTHERESPONSIBILITIESASSIGNEDTOTHE CHIEF INFORMATION SECURITY OFFICER PURSUANT TO THIS PART 4.
THE CHIEF INFORMATION OFFICER SHALL NOT DELEGATE THE DUTIES , RESPONSIBILITIES,OR POWERS OF THE CHIEF INFORMATION SECURITY OFFICER TO ANY PERSON OTHER THAN THE CHIEF INFORMATION SECURITY OFFICER.
HE CHIEF INFORMATION OFFICER SHALL NOT DELEGATE THE DUTIES , RESPONSIBILITIE, OR POWERS OF THE CHIEF INFORMATION SECURITY OFFICER TO ANY PERSON OTHER THAN THE CHIEF INFORMATION SECURITY OFFICER.
NOTHING IN THIS SECTION PREVENTS THE CHIEF INFORMATION SECURITY OFFICER FROM DIRECTING PERSONNEL WITHIN THE INFORMATION SECURITY OFFICE TO CARRY OUT SECURITY FUNCTIONS UNDER THE CHIEF INFORMATIONSECURITYOFFICER SSUPERVISIONANDACCOUNTABILITY .THE CHIEFINFORMATIONSECURITYOFFICERISRESPONSIBLEFORTHEACCURACY OF THE COMPLIANCE REPORT REQUIRED IN SUBSECTION (2)(jOF THIS SECTION AND THE SECURITY RISK REPORT REQUIRED IN SUBSECTION (2)(k) OFTHISSECTION ,REGARDLESSOFWHICHPERSONNELCONTRIBUTEDTOTHE PREPARATION OF THE REPORTS .
NOTHING IN THIS SECTION PREVENTS THE CHIEF INFORMATION SECURITYOFFICERFROMDIRECTINGPERSONNELWITHINTHEINFORMATION SECURITY OFFICE TO CARRY OUT SECURITY FUNCTIONS UNDER THE CHIEF INFORMATION SECURITY OFFICER S SUPERVISION AND ACCOUNTABILITY .
T HE CHIEF INFORMATION SECURITY OFFICER IS RESPONSIBLE FOR THE ACCURACY OF THE COMPLIANCE REPORT REQUIRED IN SUBSECTION (2)(j) OF THIS SECTION AND THE SECURITY RISK REPORT REQUIRED IN SUBSECTION (2)(k)OF THIS SECTIO,REGARDLESS OF WHICH PERSONNEL CONTRIBUTED TO THE PREPARATION OF THE REPORTS .
on the day following the expiration of the ninety-dayperiodafterfinaladjournmentofthegeneralassembly(August 12, 2026, if adjournment sine die is on May 13, 2026);
on the day following the expiration of the ninety-dayperiod after final adjournment of the general assembly(August 12, 2026, if adjournment sine die is on May 13, 2026);
except that, if a referendum petition is filed pursuant to section 1 (3) of article V of the state constitution against this act or an item, section, or part of this act within such period, then the act, item, section, or part will not take effect unless approved by the people at the general election to be held in November 2026 and, in such case, will take effect on the date of the official declaration of the vote thereon by the governor.
except that, if a referendumpetitionisfiledpursuanttosection1(3)ofarticleVofthestate constitution against this act or an item, section, or part of this act within such period, then the act, item, section, or part will not take effect unless PAGE 8-SENATE BILL 26-185 approvedbythepeopleatthegeneralelectiontobeheldinNovember2026 and, in such case, will take effect on the date of the official declaration of the vote thereon by the governor.
-11- 185
____________________________ ____________________________ James Rashad Coleman, Sr.
Julie McCluskie PRESIDENT OF SPEAKER OF THE HOUSE THE SENATE OF REPRESENTATIVES ____________________________ ____________________________ Esther van Mourik Vanessa Reilly SECRETARY OF CHIEF CLERK OF THE HOUSE THE SENATE OF REPRESENTATIVES APPROVED________________________________________ (Date and Time) _________________________________________ Jared S.
Polis GOVERNOR OF THE STATE OF COLORADO PAGE 9-SENATE BILL 26-185
View plain text versions (7)

Action History

  1. Governor Signed

  2. Signed by the President of the Senate

  3. Signed by the Speaker of the House

  4. Sent to the Governor

  5. House Third Reading Passed - No Amendments

  6. House Committee on Appropriations Refer Unamended to House Committee of the Whole

  7. House Second Reading Special Order - Passed - No Amendments

  8. House Committee on State, Civic, Military, & Veterans Affairs Refer Unamended to Appropriations

  9. Senate Third Reading Passed - No Amendments

  10. Introduced In House - Assigned to State, Civic, Military, & Veterans Affairs

  11. Senate Committee on Appropriations Refer Unamended - Consent Calendar to Senate Committee of the Whole

  12. Senate Second Reading Special Order - Passed with Amendments - Committee

  13. Senate Committee on Business, Labor, & Technology Refer Amended to Appropriations

  14. Introduced In Senate - Assigned to Business, Labor, & Technology

Sponsors

  • M. Rutinel · Cosponsor
  • B. Marshall · Cosponsor
  • J. Jackson · Cosponsor
  • C. Clifford · Cosponsor
  • M. Carter · Cosponsor
  • J. Bacon · Cosponsor
  • A. Paschal · Primary
  • B. Titone · Primary
  • R. Keltie · Primary
  • Mark Baisley · Primary
  • Janice Marchman · Primary
  • James Coleman · Cosponsor

Sponsorship breakdown

Export CSV (upgrade) →

5 sponsors · 7 co-sponsors · 89 not signed on

Sponsors (5)

Co-sponsors (7)

  • M. Rutinel
  • B. Marshall
  • J. Jackson
  • C. Clifford
  • M. Carter
  • J. Bacon
  • James Coleman Democrat

Not signed on (89)

89 members have not signed on to this bill.

Show all 89 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Votes

BILL

Passed 64 Yea · 1 Nay
Party YeaNayPresentNot Voting
Democrat 41000
Republican 19000
Unaffiliated 4100
Total 64100
% of votes cast 98%2%0%0%
How each member voted (65)
Member Party Vote
Gonzalez R. — Nay
Stewart K. — Yea
Stewart R. — Yea
Winter T. — Yea
Garcia Sander — Yea
Alex Valdez Democrat Yea
Amy Paschal Democrat Yea
Andrew Boesenecker Democrat Yea
Bob Marshall Democrat Yea
Brianna Titone Democrat Yea
Cecelia Espenoza Democrat Yea
Chad Clifford Democrat Yea
Eliza Hamrick Democrat Yea
Elizabeth Velasco Democrat Yea
Emily Sirota Democrat Yea
Gretchen Rydin Democrat Yea
Jacque Phillips Democrat Yea
Jamie Jackson Democrat Yea
Javier Mabrey Democrat Yea
Jennifer Bacon Democrat Yea
Jenny Willford Democrat Yea
Julie McCluskie Democrat Yea
Junie Joseph Democrat Yea
Karen McCormick Democrat Yea
Kenny Nguyen Democrat Yea
Kyle Brown Democrat Yea
Lesley Smith Democrat Yea
Lindsay Gilchrist Democrat Yea
Lisa Feret Democrat Yea
Lorena Garcia Democrat Yea
Lori Goldstein Democrat Yea
Mandy Lindsay Democrat Yea
Manny Rutinel Democrat Yea
Matthew Martinez Democrat Yea
Meg Froelich Democrat Yea
Meghan Lukens Democrat Yea
Michael Carter Democrat Yea
Monica Duran Democrat Yea
Naquetta Ricks Democrat Yea
Regina English Democrat Yea
Sean Camacho Democrat Yea
Sheila Lieder Democrat Yea
Steven Woodrow Democrat Yea
Tammy Story Democrat Yea
Tisha Mauro Democrat Yea
Yara Zokaie Democrat Yea
Anthony Hartsook Republican Yea
Ava Flanell Republican Yea
Brandi Bradley Republican Yea
Carlos Barron Republican Yea
Chris Richardson Republican Yea
Dan Woog Republican Yea
Dusty Johnson Republican Yea
Jarvis Caldwell Republican Yea
Ken DeGraaf Republican Yea
Larry Don Suckla Republican Yea
Mary Bradfield Republican Yea
Matt Soper Republican Yea
Max Brooks Republican Yea
Rebecca Keltie Republican Yea
Rick Taggart Republican Yea
Ron Weinberg Republican Yea
Scott Bottoms Republican Yea
Scott Slaugh Republican Yea
Stephanie Luck Republican Yea

Official roll call →

Passed 10 Yea · 0 Nay · 1 Other
Party YeaNayPresentNot Voting
Democrat 7001
Republican 3000
Total 10001
% of votes cast 91%0%0%9%
How each member voted (11)
Member Party Vote
Andrew Boesenecker Democrat Yea
Brianna Titone Democrat Yea
Elizabeth Velasco Democrat Yea
Emily Sirota Democrat Yea
Junie Joseph Democrat Yea
Karen McCormick Democrat Yea
Kyle Brown Democrat Yea
Yara Zokaie Democrat Not Voting
Matt Soper Republican Yea
Rick Taggart Republican Yea
Scott Bottoms Republican Yea

Official roll call →

Passed 11 Yea · 0 Nay
Party YeaNayPresentNot Voting
Republican 3000
Democrat 8000
Total 11000
% of votes cast 100%0%0%0%
How each member voted (11)
Member Party Vote
Cecelia Espenoza Democrat Yea
Chad Clifford Democrat Yea
Jenny Willford Democrat Yea
Kenny Nguyen Democrat Yea
Lisa Feret Democrat Yea
Meg Froelich Democrat Yea
Michael Carter Democrat Yea
Naquetta Ricks Democrat Yea
Brandi Bradley Republican Yea
Ken DeGraaf Republican Yea
Stephanie Luck Republican Yea

Official roll call →

Passed 7 Yea · 0 Nay
Party YeaNayPresentNot Voting
Democrat 4000
Republican 3000
Total 7000
% of votes cast 100%0%0%0%
How each member voted (7)
Member Party Vote
Chris Kolker Democrat Yea
Jeff Bridges Democrat Yea
Judy Amabile Democrat Yea
Julie Gonzales Democrat Yea
Barbara Kirkmeyer Republican Yea
Byron Pelton Republican Yea
Larry Liston Republican Yea

Official roll call →

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

What does SB 185 do?
The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding.     If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit.     The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies.     The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data.     The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually.     The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer.     The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor.     The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information.     The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
Who sponsors SB 185?
SB 185 is sponsored by M. Rutinel, B. Marshall, J. Jackson, C. Clifford, M. Carter, J. Bacon, A. Paschal, B. Titone, R. Keltie, Mark Baisley (Republican), Janice Marchman (Democrat), and James Coleman (Democrat).
What is the current status of SB 185?
This bill has been enacted into law. Introduced May 01, 2026. Enacted.
Where can I track SB 185?
Track SB 185 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on SB 185

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of SB 185

Last checked for changes 3 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →