Watch hub·govramp · stateramp · tx-ramp · ny-dfs-500

State & Local

GovRAMP, state cyber and privacy laws, municipal compliance, and the patchwork below the federal line.

Updated ·RSS ↗

States and municipalities are building their own cybersecurity regimes for vendors handling state and local data. GovRAMP (formerly StateRAMP) is the dominant cross-state framework; TX-RAMP, NY DFS Part 500, and CJIS run alongside it. This hub indexes those programs, tracks alignment (and divergence) with federal frameworks, and surfaces state-level enforcement and policy movement.

What changed in the last 30 days

  • state-privacy/trade-press

    AI inferences outrun state privacy laws, experts warn

    StateScoop reports that data-privacy experts on a recent panel warned state privacy laws often regulate what data brokers collect and sell, but not the conclusions those companies infer from it. Consumers and state privacy offices get the gap: a law can police the input while leaving the AI-generated profile largely outside the frame.

  • vuln-advisory/standards

    Microsoft patches 40-plus products, including SQL and LSASS

    Microsoft issued September 9 patches for more than 40 products, with MS-ISAC warning that the most severe vulnerabilities could allow remote code execution. Contractors, primes, subs and managed service providers should prioritize SQL Server, Windows PowerShell, Office, LSASS and SMBv3 exposures. MS-ISAC says it has no reports of exploitation in the wild, but the advisory does not specify CVSS scores, exploit timing or Windows Server 2019 and 2022 patch coverage.

  • vuln-advisory/standards

    Google fixes three Chrome code-execution vulnerabilities

    Google released Chrome 149.0.7827.200/201 for Windows and Mac and 149.0.7827.200 for Linux to fix CVE-2026-13281, CVE-2026-13282 and CVE-2026-13283. MS-ISAC rates the risk medium for government and business entities, with no known exploitation. State, municipal, contractor and MSP teams should apply updates after testing; admin-rights browsing can turn user-context code execution into full system control.

  • vuln-advisory/standards

    CIS flags CVE-2025-48703 pre-auth RCE in CWP

    CIS MS-ISAC advisory 2025-100 warns that CWP, also known as Control Web Panel or CentOS Web Panel, before 0.9.8.1205 allows unauthenticated remote code execution through shell metacharacters in filemanager changePerm requests. Primes, subs and municipal IT shops running CWP should patch after testing. Public proof-of-concept code means the safe assumption is scanning, not theory.

  • municipal/trade-press

    Arizona launches regional SOC for local governments, students

    StateScoop reports that Arizona has added a regional security operations center, run from two community college locations, to support under-resourced local governments and build a student talent pipeline. The affected agencies are the local governments least able to staff cyber defense on their own; the students are part of the operating model, not just the audience.

  • ssdf/standards

    CIS, SAFECode update Secure by Design for AI

    CIS and SAFECode updated Secure by Design: A Developer’s Guide to Building Safer Software to address AI’s role in software security. The change affects readers who track secure software development guidance, including independent software vendors, primes and contractors. The source does not disclose specific tool requirements, implementation timelines or procurement consequences.

  • ai-cybersecurity/trade-press

    Health groups press cyber funding after Commerce clears Mythos, Fable

    Health care advocates told Inside Health Policy they want federal cybersecurity funding and guidance after Commerce lifted controls on Anthropic’s Mythos and Fable models. The push targets hospitals, HIPAA covered entities and especially rural providers with scarce resources. Sen. Bill Cassidy’s Health Care Cybersecurity and Resiliency Act is moving as a fiscal 2027 NDAA amendment, while HHS lists HIPAA Security Rule final action for July 2027.

  • ssdf/trade-press

    Zabierek pushes state software liability for secure-by-design rules

    Former CISA secure-by-design co-lead Lauren Zabierek told Inside Cybersecurity that states should explore software liability rules, using privacy and product-liability frameworks to push manufacturers toward secure-by-default development. The argument lands on state procurement offices, legislatures and software vendors, especially around critical infrastructure. Her uncomfortable point is capacity: the Trump resiliency order puts more security and resilience on states she says do not yet have the resources.

Open questions

  • 01Which states are next to mandate a vendor authorization regime?
  • 02How aligned is GovRAMP's revised baseline with FedRAMP 20x?
  • 03How do state privacy laws and CJIS interact with federal CUI handling for cross-jurisdictional vendors?

Sources we watch

Earlier coverage