West Virginia 2026 Session Status: Enacted

HB 5638 — Relating to the requirements of the state’s cyber security program and responsibilities and authority of the state chief information security officer

Last action — Chapter 192, Acts, Regular Session, 2026

  1. ✓
    Introduced
  2. ✓
    In Committee
  3. ✓
    Passed House of Delegates
  4. ✓
    Passed Senate
  5. ✓
    To Executive
  6. 6
    Enacted

This bill has been enacted into law. Introduced February 17, 2026. Enacted.

Odds of enactment

High chance

Based on the sponsor, cosponsors, and committee posture, this bill has a high chance of becoming law.

Upgrade to see the exact probability and what's driving it.

A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.

Prognosis

Likely to advance 70% · moderate confidence
  • Enacted

    Current position in the legislative process.

  • 1 sponsor

    1 primary, 0 co-sponsors signed on.

  • Cleared a recorded vote

    Passed 4 recorded votes so far.

Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.

In plain language

The bill outlines the state's cyber security program and the role of the chief information security officer.

This bill establishes requirements for the state's cyber security program and defines the responsibilities of the chief information security officer. It aims to enhance the state's approach to managing cyber risks and security measures.

Summary

Relating to the requirements of the state’s cyber security program and responsibilities and authority of the state chief information security officer

Bill Text

What changed in the latest version

118 added · 108 removed

Plain-language change summary

The recent amendments to House Bill 5638 establish the West Virginia Cybersecurity Office, which will develop standards and oversee cybersecurity for state agencies. Changes include defining key responsibilities for the Chief Information Security Officer and setting clear requirements for state agencies regarding cybersecurity assessments and reporting. This is important because it enhances the state's ability to protect sensitive information from cyber threats, ensuring better security protocols are in place across government entities.

→
Previous
Latest
WEST VIRGINIA LEGISLATURE REGULAR SESSION ENGROSSED House Bill 5638 By Delegate Linville [By Request of the Department of Administration] [Introduced February 17,2026;
WEST VIRGINIA LEGISLATURE REGULAR SESSION ENROLLED House Bill 5638 BYD ELEGATE LINVILLE (BYR EQUEST OF THEDEPARTMENT OF ADMINISTRATION) [Passed March 14, 2026;
referred to the Committee on Energy and Public Works] Eng HB 5638 A BILL to amend and reenact §5A-6B-1, §5A-6B-2, §5A-6B-3, §5A-6B-4, §5A-6B-5, and §5A-6B-6 of the Code of West Virginia, 1931, as amended, relating to the requirements of the states cyber security program and responsibilities and authority of the state Chief Information Security Officer.
in effect 90 days from passage (June 12, 2026)] Enr HB 5638 AN ACT to amend and reenact §5A-6B-1, §5A-6B-2, §5A-6B-3, §5A-6B-4, §5A-6B-5, and §5A- 6B-6 of the Code of West Virginia, 1931, as amended, relating to the requirements of the states cyber security program and responsibilities and authority of the state Chief Information Security Officer.
CYBER SECURITY PROGRAM .
CYBER SECURITY PROGRAM.
The office has the authority to may set standards for cybersecurity and is charged with managing the cybersecurity framework.
The office may set standards for cybersecurity and is charged with managing the cybersecurity framework.
(b) The provisions of this article are applicable to all state agencies, excluding higher education institutions, the State Police, state constitutional officers identified in §6-7-2 of this code, the Legislature and the Judiciary.
(b) The provisions of this article are applicable to all state agencies, excluding higher education institutions, the State Police, state constitutional officers identified in §6-7-2 of this code, the Legislature, and the Judiciary.
"Cyber risk assessment Cybersecurity program review" means the process of identifying, analyzing and evaluating risk and applying the appropriate security controls relevant to the information custodian.
"Cybersecurity program review" means the process of identifying, analyzing and evaluating risk, and applying the appropriate security controls relevant to the information custodian.
"Cyber risk management service" means technologies, practices and policies that address threats and vulnerabilities in networks, computers, programs, and data flowing from or enabled by Eng HB 5638 connection to digital infrastructure, information systems, networks, devices, or industrial control systems, including, but not limited to, information security, supply chain assurance, information assistance and hardware or software assurance.
"Cyber risk management service" means technologies, practices, and policies that address threats and vulnerabilities in networks, computers, programs, and data flowing from or enabled by connection to digital infrastructure, information systems, networks, devices, or Enr HB 5638 industrial control systems, including, but not limited to, information security, supply chain assurance, information assistance, and hardware or software assurance.
"Enterprise" means the collective departments, agencies and boards within state government that provide services to citizens and other state entities.
"Enterprise" means the collective departments, agencies, and boards within state government that provide services to citizens and other state entities.
"Information custodian" means a state or local department, agency, or person that has the actual custody of, or is responsible for the accountability for a set of office, board, commission, or other spending unit with custody of, or responsibility for, data assets residing on a state system, device, account or network.
"Information custodian" means a state or local department, agency, office, board, commission, or other spending unit with custody of, or responsibility for, data assets residing on a state system, device, account, or networks owned, monitored, or maintained by the West Virginia Office of Technology.
Networks owned, monitored, or maintained by the West Virginia Office of Technology.
"Plan of action and milestones" means a remedial plan, or the process of accepting or resolving risk, which helps the information custodian to identify and assess information system security and privacy weaknesses, set priorities, and monitor progress toward mitigating the weaknesses.
"Plan of action and milestones" means a remedial plan, or the process of accepting or resolving risk, which helps the information custodian to identify and assess information system security and privacy weaknesses, set priorities and monitor progress toward mitigating the weaknesses.
"User" means an entity or person with access to a state system, device, account or network.
"User" means an entity or person with access to a state system, device, account, or network.
Eng HB 5638 (a) The West Virginia Cybersecurity Office is under the supervision and control of a Chief Information Security Officer appointed by the Chief Technology Information Officer and shall be staffed appropriately by the Office of Technology to implement the provisions of this article.
(a) The West Virginia Cybersecurity Office is under the supervision and control of a Chief Information Security Officer appointed by the Chief Information Officer and shall be staffed appropriately by the Office of Technology to implement the provisions of this article.
(b) The Chief Information Security Officer has the following powers and duties may:
(b) The Chief Information Security Officer may:
(1) Develop policies, procedures and standards necessary to establish an enterprise cybersecurity program that recognizes the interdependent relationship and complexity of technology in government operations and the nature of shared risk of cyber threats to the state;
Enr HB 5638 (1) Develop policies, procedures, and standards necessary to establish an enterprise cybersecurity program that recognizes the interdependent relationship and complexity of technology in government operations and the nature of shared risk of cyber threats to the state;
(4) Establish the cyber risk assessment requirements such as assessment type, scope, frequency and reporting;
(4) Establish the cyber risk assessment requirements such as assessment type, scope, frequency, and reporting;
(6) Assist agencies in the development of plans and procedures to manage, assist and recover in the event of a cyber incident;
(6) Assist agencies in the development of plans and procedures to manage, assist, and recover in the event of a cyber incident;
(7) Assist agencies in the management of the framework relating to information custody, classification, accountability and protection;
(7) Assist agencies in the management of the framework relating to information custody, classification, accountability, and protection;
(9) Notwithstanding the provisions of §5A-6B-1(b) of this code, enter into fee based agreements with state government entities exempted from the application of this article or other political subdivisions of the state that desire to voluntarily participate in the cybersecurity program administered pursuant to this article;
(9) Notwithstanding the provisions of §5A-6B-1(b) of this code, enter into fee-based agreements with state government entities exempted from the application of this article or other political subdivisions of the state that desire to voluntarily participate in the cybersecurity program administered pursuant to this article;
Eng HB 5638 (10) Develop policy outlining use of the privacy impact assessment as it relates to safeguarding of data and its relationship with technology;
(10) Develop policy outlining use of the privacy impact assessment as it relates to safeguarding of data and its relationship with technology;
and (11) Establish minimal training requirements for users of state networks, systems, or devices.
(11) Establish minimal training requirements for users of state networks, systems, or devices.
(12) Perform such other functions and duties as provided by law and as or directed by the Chief Technology Information Officer.
Enr HB 5638 (12) Perform such other functions and duties as provided by law or directed by the Chief Information Officer.
(c) The Secretary of the Department of Administration shall propose rules for legislative approval in accordance with §29A-3-1 et seq.
(c) The Chief Information Security Officer, along with the Chief Information Officer, shall ensure that any state contract for licensing software applications, which are designed to run on generally available desktop or server hardware, shall not limit the state’s ability to install or run the software on the hardware of the state’s choosing.
(d) The Secretary of the Department of Administration shall propose rules for legislative approval in accordance with §29A-3-1 et seq.
Responsibilities of agencies for cybersecurity.
Responsibilities for cybersecurity.
State agencies and other entities (a) Each information custodian receiving centralized support from the West Virginia Office of Technology, or any other entity subject to the provisions of this article, shall:
(a) Each information custodian receiving centralized support from the West Virginia Office of Technology, or any other entity subject to the provisions of this article, shall:
(6) Complete and submit a cyber risk self-assessment report to the Chief Information Security Officer by December 31, 2020;
(6) Participate in at least one annual cybersecurity program review with representatives of the West Virginia Office of Technology before November 30 of each year.
(7) Manage a plan of action and milestones based on the findings of the cyber risk assessment and business needs;
The review will provide the Office of Technology with an analysis and evaluation of each information custodian’s cybersecurity readiness, ability to keep user data safe, data classifications, and other steps that Enr HB 5638 the information custodian has taken towards safeguarding, risk management, cybersecurity readiness, or information technology modernization.
and Eng HB 5638 (8) Submit annual reports to the Chief Security Information Officer no later than November 1 of each year beginning on November 1, 2023.
(b) If an information custodian fails to participate in the annual cybersecurity program review, the West Virginia Office of Technology may recover expenses associated with conducting any diagnostics or evaluations performed to assure safety of the network, devices, and systems.
The report shall contain an (6) Participate in at least one annual cybersecurity program review with representatives of the West Virginia Office of Technology before November 30 of each year.
The review will provide the Office of Technology with an analysis and evaluation of each agency or entity’s information custodian’s cybersecurity readiness, ability to keep user data safe, data classifications, and other steps that the agency, or entity information custodian has taken towards safeguarding, risk management, cybersecurity readiness, or information technology modernization.
that are consistent with the objectives of §5A-6-4d and §5A-6-4e of this code (A) If an information custodian fails to participate in the annual cybersecurity program review, the West Virginia Office of Technology may recover expenses associated with conducting any diagnostics or evaluations performed to assure safety of the network, devices, and systems.
Any information, including, but not limited to, cyber risk assessments, cybersecurity program review, plans of action and milestones, remediation plans, or information indicating the cyber threat, vulnerability, information, or data that may identify or expose potential impacts or risk to agencies or to the state or that could threaten the technology infrastructure critical to government operations and or services, public safety, or health is exempt from §29B-1-1 et seq.
Any information, including, but not limited to, cyber risk assessments, cybersecurity program review, plans of action and milestones, remediation plans, or information indicating the cyber threat, vulnerability, information, or data that may identify or expose potential impacts or risk to agencies or to the state or that could threaten the technology infrastructure critical to government operations or services, public safety, or health is exempt from §29B-1-1 et seq.
The Chief Information Security Officer shall annually, beginning on December 1, 2019, and on December 1 of each year thereafter report to the Joint Committee on Government and Finance and to the Governor on the status of the cybersecurity program, including any recommended Eng HB 5638 statutory changes.
The Chief Information Security Officer shall annually, on December 1 of each year report to the Joint Committee on Government and Finance and to the Governor on the status of the cybersecurity program, including any recommended statutory changes.
The report shall include a comprehensive summary of each state agency’s report submitted the annual cybersecurity program reviews completed pursuant to §5A-6B-4 of this code regarding the agency’s information custodian’s cybersecurity readiness and the agency’s a list of information technology modernization efforts taken by the West Virginia Office of Technology.
The report shall include a comprehensive summary of the annual cybersecurity program reviews completed pursuant to §5A-6B-4 of this code regarding the information custodian’s cybersecurity readiness and a list of information technology modernization efforts taken by the West Virginia Office of Technology.
Enr HB 5638 The Clerk of the House of Delegates and the Clerk of the Senate hereby certify that the foregoing bill is correctly enrolled.
...............................................................
Clerk of the House of Delegates ...............................................................
Clerk of the Senate Originated in the House of Delegates.
In effect 90 das from passage.
Show all 47 changed rows (7 more)
Previous
Latest
...............................................................
Speaker of the House of Delegates ...............................................................
President of the Senate __________ The within is ................................................
this the...........................................
Day of ..........................................................................................................., 2026.
.............................................................
Governor 7
View plain text versions (4)

Action History

  1. Filed for introduction

  2. To Energy and Public Works

  3. Introduced in House

  4. To House Energy and Public Works

  5. Markup Discussion

  6. Do pass

  7. On 1st reading, Special Calendar

  8. Read 1st time

  9. On 2nd reading, Special Calendar

  10. Read 2nd time

  11. On 3rd reading, Special Calendar

  12. Read 3rd time

  13. Passed House (Roll No. 251)

  14. Communicated to Senate

  15. Introduced in Senate

  16. To Government Organization

  17. To Government Organization

  18. Reported do pass, with amendment

  19. Immediate consideration

  20. Read 1st time

  21. On 2nd reading

  22. Read 2nd time

  23. Committee amendment adopted (Voice vote)

  24. On 3rd reading

  25. Read 3rd time

  26. Passed Senate (Roll No. 514)

  27. Senate requests House to concur

  28. House received Senate message

  29. House concurred in Senate amendment and passed bill (Roll No. 644)

  30. Communicated to Senate

  31. Completed legislative action

  32. House Message received

  33. To Governor 3/25/2026 - Senate Journal

  34. To Governor 3/25/26

  35. Approved by Governor 4/1/2026 - Senate Journal

  36. Approved by Governor 4/1/2026 - House Journal

  37. Approved by Governor 4/1/2026

  38. Chapter 192, Acts, Regular Session, 2026

Sponsors

  • Linville · Primary

Sponsorship breakdown

Export CSV (upgrade) →

1 sponsors · 0 co-sponsors · 151 not signed on · 1 voted No

Sponsors (1)

  • Linville

Co-sponsors (0)

None.

Not signed on (151)

151 members have not signed on to this bill.

Show all 151 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Votes

PASSAGE-SENATE AMENDED HB

Passed 96 Yea · 1 Nay · 2 Other
Party YeaNayPresentNot Voting
Republican 85102
Democrat 9000
Unaffiliated 2000
Total 96102
% of votes cast 97%1%0%2%
How each member voted (99)
Member Party Vote
Flanigan — Yea
Linville — Yea
Anitra Hamilton Democrat Yea
Evan Hansen Democrat Yea
Hollis Lewis Democrat Yea
John Williams Democrat Yea
Kayla Young Democrat Yea
Mike Pushkin Democrat Yea
Rick Garcia Democrat Yea
Sean Hornbuckle Democrat Yea
Shawn Fluharty Democrat Yea
Adam Burkhammer Republican Yea
Adam Vance Republican Yea
Andy Shamblin Republican Yea
Betsy Kelly Republican Yea
Bill Bell Republican Yea
Bill Ridenour Republican Yea
Bob Fehrenbacher Republican Yea
Bryan Smith Republican Not Voting
Bryan Ward Republican Yea
Carl "Bill" Roop Republican Yea
Carl Martin Republican Yea
Charles Sheedy Republican Yea
Chris Phillips Republican Yea
Christopher W. Toney Republican Yea
Chuck Horst Republican Yea
Clay Riley Republican Yea
D. Rolland Jennings Republican Yea
Dana Ferrell Republican Nay
Dave Foggin Republican Yea
David Cannon Republican Yea
David Green Republican Yea
David McCormick Republican Yea
Dean Jeffries Republican Yea
Doug Smith Republican Yea
Elias Coop-Gonzalez Republican Yea
Eric Brooks Republican Yea
Erica Moore Republican Yea
Evan Worrell Republican Yea
Gary G. Howell Republican Yea
Geno Chiarelli Republican Yea
George Miller Republican Yea
George Street Republican Yea
Gregory A. Watt Republican Yea
Guy Ward Republican Yea
Henry Dillon Republican Yea
Ian T. Masters Republican Yea
James Robert "JB" Akers II Republican Yea
Jarred Cannon Republican Yea
Jeff Campbell Republican Yea
Jeff Eldridge Republican Yea
Jeffrey Stephens Republican Yea
Jim Butler Republican Yea
Jimmy Willis Republican Yea
Joe Ellington Republican Yea
Joe Funkhouser Republican Yea
Joe Parsons Republican Yea
Joe Statler Republican Yea
John Jordan Republican Yea
John Paul Hott Republican Yea
Jonathan Kyle Republican Yea
Jonathan Pinson Republican Yea
Jordan Bridges Republican Yea
Jordan Maynor Republican Yea
Josh Holstein Republican Yea
Kathie Hess Crouse Republican Yea
Keith Marple Republican Not Voting
Laura Kimble Republican Yea
Lisa White Republican Yea
Lori Dittman Republican Yea
Margitta Mazzocchi Republican Yea
Mark Dean Republican Yea
Mark Zatezalo Republican Yea
Marshall W. Clay Republican Yea
Marty Gearheart Republican Yea
Matthew Rohrbach Republican Yea
Michael Amos Republican Yea
Michael Hite Republican Yea
Michael Hornby Republican Yea
Mickey Petitto Republican Yea
Pat McGeehan Republican Yea
Patrick Lucas Republican Yea
Phil Mallow Republican Yea
Ray Canterbury Republican Yea
Rick Hillenbrand Republican Yea
Roger Hanshaw Republican Yea
Roy Cooper Republican Yea
Ryan Browning Republican Yea
S. Chris Anders Republican Yea
Sarah Drennan Republican Yea
Scot C. Heckert Republican Yea
Stanley Adkins Republican Yea
Tresa Howell Republican Yea
Tristan Leavitt Republican Yea
Vacant1 Republican Yea
Vernon Criss Republican Yea
Walter Hall Republican Yea
Wayne Clark Republican Yea
William Anderson Republican Yea

Official roll call →

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

What does HB 5638 do?
Relating to the requirements of the state’s cyber security program and responsibilities and authority of the state chief information security officer
Who sponsors HB 5638?
HB 5638 is sponsored by Linville.
What is the current status of HB 5638?
This bill has been enacted into law. Introduced February 17, 2026. Enacted.
Where can I track HB 5638?
Track HB 5638 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HB 5638

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HB 5638

Last checked for changes about 1 month ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →