Back to research
18 min readResearch study

The K-12 Cybersecurity Floor: What States Require and Provide

A 51-jurisdiction scan of binding school-district cybersecurity duties, incident reporting, shared services, grants, ransomware rules, and framework alignment.

K-12 cybersecurity policy has an honesty problem. Guidance is often described as a requirement, a grant announcement gets mistaken for an operating service, and a general data breach law gets reported as though it were a school cyber standard. Those are different things. This study keeps them different.

The map asks a narrow question: what does each state actually require or provide for public school districts? A binding floor means the state imposes a cybersecurity control, plan, assessment, or exercise requirement. A reporting duty is shown separately. So are statewide services, grants, ransomware rules, and voluntary framework guidance.

As of August 1, 2026, this pass established a verified overall classification for 7 of 51 jurisdictions. The remaining 44 are shown as not yet verified, not as states with no protections. That distinction is the point.

51-jurisdiction dashboard

Requirements, reporting, and services are not the same thing.

Filter the evidence by legal floor, incident reporting, shared service, or region. Not yet verified means the current source set did not support a classification. It does not mean the state has nothing.

Binding cybersecurity floorBinding reporting dutyStatewide service floorVoluntary support onlyNot yet verified

B means a binding controls floor. R means a reporting-only floor. S means a state service floor. V means verified voluntary support. NR means not yet verified. These are research classifications, not legal advice.

What the dashboard measures

The dashboard tracks six signals that should never be collapsed into one score:

  • Binding cybersecurity controls, plans, assessments, or exercises
  • Mandatory cyber incident reporting and deadlines
  • Statewide SOC, MDR, shared tools, or technical assistance available to school districts
  • Cybersecurity grants open to school districts
  • Ransomware payment or reporting rules
  • Explicit alignment with CISA, NIST, CIS, MS-ISAC, or K12 SIX

The first read

  • 2 jurisdictions have a verified binding controls, plan, assessment, or exercise floor in this source set.
  • 2 jurisdictions have a verified reporting duty without a separately verified binding controls floor.
  • 0 jurisdictions have a verified statewide SOC, MDR, or equivalent service floor available to districts.
  • 3 jurisdictions have verified voluntary guidance, grants, shared tools, or assistance without a binding floor.
  • 44 jurisdictions remain not yet verified in this pass.

These are research classifications, not legal advice. They describe what the opened sources support as of the publication date.

Why reporting is not enough

Reporting can improve statewide visibility and speed response, but a deadline after an incident is not a control before an incident. The dashboard therefore shows reporting duties beside controls and services rather than using them as a proxy for readiness.

A state may require districts to notify a security office quickly while leaving authentication, backups, asset inventory, vulnerability management, and incident exercises to local choice. That state has a reporting floor, not necessarily a prevention floor.

Why services matter

Small and rural districts cannot build a full security operations capability alone. A statewide SOC, MDR service, shared monitoring platform, or expert response team can create a practical operating floor even when participation is voluntary. Grants help, but a short funding cycle is not the same thing as an enduring service.

The service classification is intentionally strict. A state receives credit only when an official source shows that the offer is available to public school districts. General local government eligibility, a procurement contract, or an expired pilot does not automatically qualify.

The federal baseline is guidance

CISA's 2023 K-12 report recommends that districts begin with high impact, low cost Cybersecurity Performance Goals. Those recommendations are useful and concrete. They are not state law.

GAO has documented both the threat to school operations and the fragmented federal support landscape. Federal incident response, monitoring tools, and guidance can help districts, but they do not answer the state policy question. This dashboard is about the layer between federal recommendations and local implementation.

How to use this study

For state leaders, the useful question is not whether a resource page exists. It is whether every district has a clear minimum expectation, a fast reporting path, and access to operational help.

For district leaders, a green state tile is not permission to relax. Verify the actual scope, deadline, and service eligibility. Then compare the state floor with the controls your students and staff need.

For policymakers, the strongest model is not a stack of compliance paperwork. It is a short, enforceable baseline paired with shared services that make compliance realistic.

Method and limitations

The unit of analysis is the public school district or local education agency. The research prioritizes enacted laws, official rules, state security directives, state education and technology agencies, and official service or grant pages. Search snippets are discovery only.

A law that applies only to state agencies is not assigned to school districts. An expired grant is not counted as a current service. Missing evidence is recorded as not yet verified rather than zero. The full methodology and source fields are preserved in the public record for each jurisdiction.

State law and program availability change. Verify the cited source before making a legal, procurement, or incident response decision.

National sources