Ohio Revised Code 9.64 for local governments
Every political subdivision in Ohio has to adopt a cybersecurity program, report incidents to the state on a clock and get its legislative authority's approval before paying a ransom. Both adoption deadlines have already passed.
What the law requires
Section 9.64 came in with House Bill 96, signed June 30, 2025 and effective Sept. 30, 2025. It applies to every political subdivision: counties, townships, municipal corporations and any other body corporate and politic responsible for governmental activities in an area smaller than the state.
A cybersecurity program
Your legislative authority adopts a program that safeguards the entity's data, information technology and IT resources for availability, confidentiality and integrity. It has to be consistent with generally accepted best practices, and the statute names the NIST Cybersecurity Framework and the CIS best practices as examples. The components it lists are permissive rather than mandatory: identifying critical functions and risks, assessing the impact of a breach, threat detection, incident response procedures, recovery and continuity planning and employee training.
Reporting on a clock
After a cybersecurity or ransomware incident you notify two offices. The Ohio Department of Public Safety gets it as soon as possible and no later than seven days after discovery, submitted through the Ohio Cyber Integration Center. The Auditor of State gets it as soon as possible and no later than 30 days. Both deadlines run from discovery.
Ransom payments need a vote
A subdivision experiencing a ransomware incident cannot pay or otherwise comply with a ransom demand unless its legislative authority formally approves it, in a resolution or ordinance that specifically states why paying is in the best interest of the subdivision. Ohio's open meetings law has an emergency meeting provision. Ask your counsel now, not mid-incident, how fast your board can lawfully convene.
The Auditor of State set the dates for adopting a program in Bulletin 2025-007, and both have passed. Counties and cities were due Jan. 1, 2026, and every other political subdivision was due July 1, 2026.
- Sept. 30, 2025 Reporting duties and the ransom approval rule took effect.
- Jan. 1, 2026 Counties and cities were to have a program adopted.
- July 1, 2026 All other political subdivisions, including townships and villages.
What counts as a reportable incident
A cybersecurity incident is a substantial loss of confidentiality, integrity or availability of your information system or network, a serious impact on the safety and resiliency of your operational systems and processes, a disruption of your ability to engage in business or industrial operations or deliver goods or services, or unauthorized access to your system, or to the nonpublic information on it, reached through a compromised cloud provider, managed service provider or other third-party host, or through a supply chain compromise.
It excludes threats of disruption used as extortion, good-faith activity carried out at the request of the system owner or operator and lawfully authorized government activity. A vendor breach that exposes your data is in scope even though the vendor's systems were the ones attacked.
Records tied to your cybersecurity program, your incident reports and the related procurement documents are not public records under section 9.64 itself.
What we do
We write the program with your people, mapped to the NIST Cybersecurity Framework or the CIS controls and sized to the staff you have. A village with one IT contractor and a county with its own security team need different documents.
The statute sets two deadlines but does not say who meets them. We put that in your incident response procedures: who notifies the Ohio Cyber Integration Center, who files with the Auditor, who drafts the resolution if a ransom demand reaches your board.
A tabletop exercise then runs your team through a scenario with the clock going.
We will not tell you that you are compliant. That is for your legal counsel and your auditor. This page summarizes the statute in plain language, it is not legal advice, and you should read the statute itself.
Leadership
Spencer Wood was interim State Chief Information Officer of Ohio and Chief Information Officer for the Ohio Secretary of State before federal service. As a Cybersecurity Advisor with CISA he supported government agencies across the six states of Region 5, Ohio among them. Every consultant who works with Foundation Consultant Group served in that same CISA role.
Next step
Tell us what your subdivision has adopted so far, if anything, and we will tell you what is missing and what it would take to close it.
Get in Touch