- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

SB 185
Colorado Senate•Passed
Summary
SB 185, “Enhance Security of Office of Information Technology”, was introduced in the Senate on May 1, 2026 by Rep. Mark Baisley (R) with 11 co-sponsors. It last saw action on Jun 2, 2026: Governor Signed.
Record
Text
SB 185 has 11 co-sponsors and 7 roll calls.
sb185/enrolled.txtNOTE: This bill has been prepared for the signatures of the appropriate legislativeofficers and the Governor. To determine whether the Governor has signed the billor taken other action on it, please consult the legislative status sheet, the legislativehistory, or the Session Laws.SENATE BILL 26-185BY SENATOR(S) Marchman and Baisley, Coleman;also REPRESENTATIVE(S) Titone and Keltie, Paschal, Bacon, Carter,Clifford, Jackson, Marshall, Rutinel.CONCERNING MEASURES TO ENHANCE THE OFFICE OF INFORMATIONTECHNOLOGY'S SECURITY PROCEDURES.Be it enacted by the General Assembly of the State of Colorado:SECTION 1. In Colorado Revised Statutes, 2-3-1704, add (13),(14), and (15) as follows:2-3-1704. Powers and duties of the joint technology committee.(13) THE COMMITTEE MAY CALL THE CHIEF INFORMATION SECURITYOFFICER TO TESTIFY BEFORE THE COMMITTEE REGARDING THE WRITTENINFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT THAT THE CHIEFINFORMATION SECURITY OFFICER IS REQUIRED TO SUBMIT TO THECOMMITTEE PURSUANT TO SECTION 24-37.5-403 (2)(j).(14) WITHIN NINETY DAYS AFTER THE DAY THAT THE CHIEFINFORMATION SECURITY OFFICER OF THE OFFICE OF INFORMATION________Capital letters or bold & italic numbers indicate new material added to existing law; dashesthrough words or numbers indicate deletions from existing law and such material is not part ofthe act.TECHNOLOGY FILES A WRITTEN INFORMATION TECHNOLOGY SECURITYCOMPLIANCE REPORT AS REQUIRED BY SECTION 24-37.5-403 (2)(j), THECOMMITTEE MAY VOTE TO FORMALLY REQUEST THAT THE LEGISLATIVEAUDIT COMMITTEE, PURSUANT TO SECTION 2-3-108, VOTE TO DIRECT ASPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT OF THE OFFICE INACCORDANCE WITH THE STATE AUDITOR'S AUTHORITY RELATED TOINFORMATION TECHNOLOGY SYSTEMS AS DESCRIBED IN SECTION 2-3-103(1.5), IF:(a) THE WRITTEN INFORMATION TECHNOLOGY SECURITYCOMPLIANCE REPORT REQUIRED BY SECTION 24-37.5-403 (2)(j) INDICATESTHAT ONE OR MORE AUDIT RECOMMENDATIONS MADE BY THE STATEAUDITOR IS UNRESOLVED TWO OR MORE YEARS PAST THE IMPLEMENTATIONDATE FOR THE AUDIT RECOMMENDATION TO WHICH THE OFFICE COMMITTEDIN A PRIOR COMPLIANCE REPORT; OR(b) A MATERIAL DISCREPANCY EXISTS BETWEEN A REPRESENTATIONMADE IN THE WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCEREPORT REQUIRED BY SECTION 24-37.5-403 (2)(j) AND A FINDING MADE INA PREVIOUS AUDIT BY THE STATE AUDITOR.(15) (a) IF A MAJORITY OF THE COMMITTEE VOTES TO REQUEST THATTHE LEGISLATIVE AUDIT COMMITTEE DIRECT A SPECIAL INFORMATIONTECHNOLOGY SECURITY AUDIT PURSUANT TO SUBSECTION (14) OF THISSECTION AND IF A MAJORITY OF THE LEGISLATIVE AUDIT COMMITTEE VOTESTO APPROVE AN AUDIT PURSUANT TO SECTION 2-3-108, THE STATE AUDITORSHALL CONDUCT THE INFORMATION TECHNOLOGY SECURITY AUDIT AND MAYCONTRACT WITH A QUALIFIED THIRD-PARTY INFORMATION TECHNOLOGYSECURITY FIRM TO CONDUCT THE AUDIT. THE STATE AUDITOR SHALL OBTAININPUT FROM THE OFFICE OF INFORMATION TECHNOLOGY WHEN THE STATEAUDITOR DETERMINES THE SCOPE AND BOUNDARIES OF THE AUDIT, TAKINGINTO CONSIDERATION THE RESOURCES AVAILABLE TO THE OFFICE TOREIMBURSE THE AUDITOR FOR THE COST OF THE AUDIT PURSUANT TOSUBSECTION (15)(b) OF THIS SECTION.(b) THE STATE AUDITOR SHALL, WITHIN TWELVE MONTHS OF THEAFFIRMATIVE VOTE OF A MAJORITY OF THE LEGISLATIVE AUDIT COMMITTEE,PRODUCE AN INFORMATION TECHNOLOGY SECURITY AUDIT REPORT ANDSUBMIT THE AUDIT REPORT TO THE LEGISLATIVE AUDIT COMMITTEE, AFTERWHICH THE STATE AUDITOR SHALL SUBMIT THE REPORT TO THE COMMITTEE,PAGE 2-SENATE BILL 26-185THE JOINT BUDGET COMMITTEE, AND THE GOVERNOR. PURSUANT TO SECTION2-3-110, THE OFFICE SHALL REIMBURSE THE STATE AUDITOR FOR AN AUDITCONDUCTED PURSUANT TO SUBSECTION (14) OF THIS SECTION. THEREIMBURSEMENT MAY BE PAID FROM THE TECHNOLOGY RISK PREVENTIONAND RESPONSE FUND CREATED IN SECTION 24-37.5-120.SECTION 2. In Colorado Revised Statutes, 24-37.5-105, amend(3)(c), (3)(d), (6)(c), and (6)(d); and add (3)(f), (4.5), and (6)(e) as follows:24-37.5-105. Office - roles - responsibilities - state searchinterface - rules - legislative declaration - definitions.(3) The office shall:(c) Assist the joint technology committee as necessary to facilitatethe committee's oversight of the office; and(d) Establish, maintain, and keep an inventory of informationtechnology owned by or held in trust for every state agency; AND(f) (I) ESTABLISH, MAINTAIN, KEEP, QUARTERLY UPDATE, AND MAKEAVAILABLE TO STATE AGENCY INFORMATION TECHNOLOGY LEADERSHIP ANDTHE MEMBERS OF THE JOINT TECHNOLOGY COMMITTEE, A LIST OF ALL ACTIVEINFORMATION TECHNOLOGY VENDOR CONTRACTS FOR STATE AGENCIES ASDESCRIBED IN SUBSECTION (6) OF THIS SECTION. FOR EACH INFORMATIONTECHNOLOGY VENDOR CONTRACT, THE LIST MUST INCLUDE:(A) THE NAME OF THE VENDOR;(B) THE VALUE OF THE CONTRACT;(C) THE DATE ON WHICH THE CONTRACT EXPIRES; AND(D) THE DATA CLASSIFICATION - BUSINESS CRITICALITY TIER OF THECONTRACT.(II) IF A STATE AGENCY INITIATES SOLICITATIONS AND CONTRACTSFOR INFORMATION TECHNOLOGY RESOURCES WITH PRIOR APPROVAL OF THEPROCUREMENT OFFICIAL FOR THE OFFICE PURSUANT TO SUBSECTION (6) OFTHIS SECTION, THE STATE AGENCY SHALL PROVIDE TO THE OFFICE THEPAGE 3-SENATE BILL 26-185INFORMATION SPECIFIED IN SUBSECTION (3)(f)(I) OF THIS SECTION FOR EACHINFORMATION TECHNOLOGY VENDOR CONTRACT, AND THE OFFICE SHALLINCLUDE THE INFORMATION IN THE LIST REQUIRED BY THIS SUBSECTION(3)(f).(III) THE OFFICE SHALL SUBMIT A ONE-TIME INFORMATIONTECHNOLOGY BUDGET REQUEST TO THE JOINT TECHNOLOGY COMMITTEE FORTHE COST OF BUILDING AND IMPLEMENTING THE LIST REQUIRED BY THISSUBSECTION (3)(f). IF, AFTER THE BUDGET REQUEST IS APPROVED, THEOFFICE DETERMINES THAT MORE MONEY IS NEEDED TO IMPLEMENT ANDMAINTAIN THE LIST, THE OFFICE MAY REQUEST THAT THE GENERALASSEMBLY ALLOCATE ADDITIONAL MONEY FROM THE TECHNOLOGY RISKPREVENTION AND RESPONSE FUND CREATED IN SECTION 24-37.5-120.(4.5) Technical information technology standards.(a) EXCEPT AS OTHERWISE PROVIDED IN SUBSECTION (4.5)(b) OF THISSECTION, THE OFFICE SHALL NOT PUBLISH OR IMPLEMENT A TECHNICALINFORMATION TECHNOLOGY STANDARD THAT IS ESTABLISHED PURSUANT TOSUBSECTION (4) OF THIS SECTION, AND THE STANDARD IS VOID, UNLESS:(I) THE OFFICE HAS PUBLICLY POSTED THE STANDARD; AND(II) THE CHIEF INFORMATION SECURITY OFFICER HAS APPROVED THESTANDARD, IF THE STANDARD RELATES TO SECURITY, ACCESS CONTROLS, ORTHE HANDLING OF DATA.(b) THE PROVISIONS OF SUBSECTION (4.5)(a) OF THIS SECTION DO NOTAPPLY WHEN THE CHIEF INFORMATION SECURITY OFFICER DETERMINES INWRITING THAT AN INFORMATION TECHNOLOGY SECURITY EMERGENCYEXISTS. FOR PURPOSES OF THIS SUBSECTION (4.5), AN INFORMATIONTECHNOLOGY SECURITY EMERGENCY MEANS A SITUATION IN WHICH ANIMMINENT OR ACTIVE THREAT TO STATE INFORMATION TECHNOLOGYSYSTEMS REQUIRES THE IMMEDIATE IMPLEMENTATION OF A SECURITYSTANDARD TO PREVENT OR MITIGATE SIGNIFICANT HARM TO STATE DATA,SYSTEMS, OR OPERATIONS.(c) IF THE OFFICE IMPLEMENTS A SECURITY STANDARD IN RESPONSETO AN INFORMATION TECHNOLOGY SECURITY EMERGENCY PURSUANT TOSUBSECTION (4.5)(b) OF THIS SECTION, THE OFFICE SHALL POST THEPAGE 4-SENATE BILL 26-185STANDARD ON THE OFFICE'S WEBSITE WITHIN SEVENTY-TWO HOURS OF THEIMPLEMENTATION OF THE SECURITY STANDARD. A SECURITY STANDARDIMPLEMENTED PURSUANT TO SUBSECTION (4.5)(b) OF THIS SECTION EXPIRESNINETY DAYS AFTER IMPLEMENTATION UNLESS, PRIOR TO EXPIRATION, THEOFFICE COMPLIES WITH THE REQUIREMENTS OF SUBSECTION (4.5)(a) OF THISSECTION.(6) Technology purchasing. The office shall initiate theprocurement of information technology resources for state agencies andenter into agreements or contracts on behalf of a state agency, multipleagencies, or the office, or be a party to procurement contracts that areinitiated by state agencies. A state agency may initiate solicitations andcontracts for information technology resources only with prior approval ofthe procurement official for the office, and must include provisionsallowing the office to enforce technology and security standards or conductdue diligence or audits of the contractors. If the state agency does notreceive written approval or disapproval from the procurement official forthe office within thirty business days after submitting the procurementrequest to the office for review, the state agency may assume that it hasreceived the prior approval of the office, as required by this subsection (6),and is authorized to initiate the procurement or solicitation process. Inconnection with the procurement of information technology resources, theoffice shall:(c) Oversee information technology vendors on behalf of the stateand state agencies except when delegated to a state agency pursuant tosection 24-37.5-105.4; and(d) If the office does not have oversight of an informationtechnology or services contract, ensure that the state agency with oversightof the contract operates pursuant to section 24-37.5-105.4 regarding thedelegation of authority; AND(e) IF A CONTRACT PROVIDES ONGOING SERVICE AND DELIVERY TOCOLORADANS, ENSURE THAT THE CONTRACT MAINTAINS CURRENTARCHITECTURE DIAGRAMS THAT ARE UPDATED AT LEAST ANNUALLY.SECTION 3. In Colorado Revised Statutes, 24-37.5-105.4, amend(1) introductory portion as follows:PAGE 5-SENATE BILL 26-18524-37.5-105.4. Delegation of authority.(1) The chief information officer may delegate an informationtechnology function of the office to another state agency by agreement orother means authorized by law, EXCEPT THAT THE CHIEF INFORMATIONOFFICER SHALL NOT DELEGATE A DUTY, RESPONSIBILITY, OR POWER OF THECHIEF INFORMATION SECURITY OFFICER. The chief information officer maydelegate an information technology function of the office if in the judgmentof the director of the state agency and the chief information officer:SECTION 4. In Colorado Revised Statutes, 24-37.5-403, amend(1), (2)(h), and (2)(i); and add (2)(j), (2)(k), and (4) as follows:24-37.5-403. Chief information security officer - duties andresponsibilities.(1) The chief information officer shall appoint a chief informationsecurity officer who shall serve at the pleasure of the chief informationofficer. The security officer shall report to and be under the supervision ofthe chief information officer. The security officer shall exhibit abackground and expertise in security and risk management forcommunications and information TECHNOLOGY resources. In the event thesecurity officer is unavailable to perform the duties and responsibilitiesunder this part 4, all powers and authority granted to the security officermay MUST be exercised by the chief information officer.(2) The chief information security officer shall:(h) In coordination and consultation with the office of state planningand budgeting and the chief information officer, review public agencybudget requests related to information security systems and approve suchbudget requests for state agencies other than the legislative department; and(i) Coordinate with the Colorado commission on higher educationfor purposes of reviewing and commenting TO REVIEW AND COMMENT oninformation security plans adopted by institutions of higher education thatare submitted pursuant to section 24-37.5-404.5 (3);(j) SUBMIT TO THE JOINT TECHNOLOGY COMMITTEE, ON OR BEFORENOVEMBER 1, 2027, AND ON OR BEFORE NOVEMBER 1 OF EACH YEARPAGE 6-SENATE BILL 26-185THEREAFTER, A WRITTEN INFORMATION TECHNOLOGY SECURITYCOMPLIANCE REPORT THAT INCLUDES THE FOLLOWING INFORMATION:(I) THE OFFICE'S CURRENT COMPLIANCE STATUS WITH APPLICABLESECURITY STANDARDS;(II) ALL OPEN AUDIT RECOMMENDATIONS MADE BY THE OFFICE OFTHE STATE AUDITOR AND THE DATE ON WHICH EACH RECOMMENDATION WASMADE;(III) ATIMELINE FOR REMEDIATION FOR EACH OPENRECOMMENDATION MADE BY THE OFFICE OF THE STATE AUDITOR; AND(IV) A MITIGATION PLAN OR COMPENSATING CONTROLS FOR THEREMEDIATION OF EACH OPEN RECOMMENDATION MADE BY THE OFFICE OFTHE STATE AUDITOR; AND(k) (I) SUBMIT TO THE JOINT TECHNOLOGY COMMITTEE, ON ORBEFORE NOVEMBER 1, 2027, AND ON OR BEFORE NOVEMBER 1 OF EACH YEARTHEREAFTER, A WRITTEN STATEWIDE INFORMATION TECHNOLOGYSECURITY RISK REPORT THAT ASSESSES THE OVERALL SECURITY RISKPOSTURE OF STATE AGENCY INFORMATION TECHNOLOGY SYSTEMS.(II) TO SUPPORT THE PREPARATION OF THE SECURITY RISK REPORTREQUIRED BY SUBSECTION (2)(k)(I) OF THIS SECTION, THE CHIEFINFORMATION SECURITY OFFICER MAY CONDUCT EVALUATIONS OF STATEAGENCY INFORMATION TECHNOLOGY SYSTEMS AS THE CHIEF INFORMATIONSECURITY OFFICER DEEMS NECESSARY, INCLUDING PENETRATION TESTING,VULNERABILITY SCANNING, CONFIGURATION EVALUATIONS, AND VENDORAND SYSTEM REVIEWS.(III) EACH STATE AGENCY SHALL PROVIDE TO THE CHIEFINFORMATION SECURITY OFFICER, UPON REQUEST, THE ACCESS ANDINFORMATION NECESSARY TO CONDUCT EVALUATIONS PURSUANT TOSUBSECTION (2)(k)(II) OF THIS SECTION, INCLUDING SYSTEM ACCESS,PRODUCT INFORMATION, AND ARCHITECTURE INFORMATION.(4) THE CHIEF INFORMATION SECURITY OFFICER, OR THE CHIEFINFORMATION OFFICER IF THE SECURITY OFFICER IS UNAVAILABLE, SHALLPERFORM THE DUTIES AND UPHOLD THE RESPONSIBILITIES ASSIGNED TO THEPAGE 7-SENATE BILL 26-185CHIEF INFORMATION SECURITY OFFICER PURSUANT TO THIS PART 4. THECHIEF INFORMATION OFFICER SHALL NOT DELEGATE THE DUTIES,RESPONSIBILITIES, OR POWERS OF THE CHIEF INFORMATION SECURITYOFFICER TO ANY PERSON OTHER THAN THE CHIEF INFORMATION SECURITYOFFICER. NOTHING IN THIS SECTION PREVENTS THE CHIEF INFORMATIONSECURITY OFFICER FROM DIRECTING PERSONNEL WITHIN THE INFORMATIONSECURITY OFFICE TO CARRY OUT SECURITY FUNCTIONS UNDER THE CHIEFINFORMATION SECURITY OFFICER'S SUPERVISION AND ACCOUNTABILITY. THECHIEF INFORMATION SECURITY OFFICER IS RESPONSIBLE FOR THE ACCURACYOF THE COMPLIANCE REPORT REQUIRED IN SUBSECTION (2)(j) OF THISSECTION AND THE SECURITY RISK REPORT REQUIRED IN SUBSECTION (2)(k)OF THIS SECTION, REGARDLESS OF WHICH PERSONNEL CONTRIBUTED TO THEPREPARATION OF THE REPORTS.SECTION 5. Act subject to petition - effective date. This acttakes effect at 12:01 a.m. on the day following the expiration of theninety-day period after final adjournment of the general assembly (August12, 2026, if adjournment sine die is on May 13, 2026); except that, if areferendum petition is filed pursuant to section 1 (3) of article V of the stateconstitution against this act or an item, section, or part of this act withinsuch period, then the act, item, section, or part will not take effect unlessPAGE 8-SENATE BILL 26-185approved by the people at the general election to be held in November 2026and, in such case, will take effect on the date of the official declaration ofthe vote thereon by the governor.____________________________ ____________________________James Rashad Coleman, Sr. Julie McCluskiePRESIDENT OF SPEAKER OF THE HOUSETHE SENATE OF REPRESENTATIVES____________________________ ____________________________Esther van Mourik Vanessa ReillySECRETARY OF CHIEF CLERK OF THE HOUSETHE SENATE OF REPRESENTATIVESAPPROVED________________________________________(Date and Time)_________________________________________Jared S. PolisGOVERNOR OF THE STATE OF COLORADOPAGE 9-SENATE BILL 26-185
Concerning measures to enhance the office of information technology's security procedures.
Sponsors
Rep. Mark Baisley (R) sponsors SB 185, and 11 members have co-sponsored it.

Rep. · R–4 · Sponsor

Sen. · D–15 · Co-sponsor

Rep. · R–16 · Co-sponsor

Rep. · D–27 · Co-sponsor

Rep. · D–18 · Co-sponsor

Sen. · D–33 · Co-sponsor

Rep. · D–7 · Co-sponsor

Rep. · D–36 · Co-sponsor

Rep. · D–37 · Co-sponsor

Rep. · D–41 · Co-sponsor
Committees
SB 185 went before 3 committees: Business, Labor, & Technology, Appropriations and State, Civic, Military and Veterans Affairs.

History
SB 185 has taken 14 actions since May 1, 2026, the latest on Jun 2, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
Jun 2, 2026 | — | Governor Signed | ||
May 22, 2026 | Senate | Signed by the President of the Senate | ||
May 22, 2026 | House | Signed by the Speaker of the House | ||
May 22, 2026 | — | Sent to the Governor | ||
May 13, 2026 | House | House Third Reading Passed - No Amendments |
Votes
SB 185 went to 7 roll calls across both chambers, the latest on May 13, 2026 at 64–1.
| Chamber | Question | Yea | Nay | |||
|---|---|---|---|---|---|---|
May 13, 2026 | House | House: Third Reading Bill | 64 | 1 | ||
May 12, 2026 | House | House Appropriations: Refer Senate Bill 26-185 to the Committee of the Whole. | 10 | 0 | ||
May 9, 2026 | House | House State, Civic, Military, & Veterans Affairs: Refer Senate Bill 26-185 to the Committee on Appropriations. | 11 | 0 | ||
May 8, 2026 | Senate | Senate: Third Reading Bill | 34 | 0 | ||
May 7, 2026 | Senate | Senate Appropriations: Refer Senate Bill 26-185 to the Committee of the Whole and with a recommendation that it be placed on the consent calendar. | 7 | 0 |
Source: leg.colorado.gov · legiscan.com