ORC §9.64 • Compliance Guide

Ohio's §9.64 Cybersecurity Law: What It Really Requires and How to Get It Right

A plain-English guide for Ohio political subdivisions on compliance requirements, audit exposure, incident response planning, and practical implementation.

  • Ohio Local Government
  • School Districts
  • Compliance Readiness
  • ~7 Minute Read

Key Deadlines

  • Counties & Cities: Jan 1, 2026
  • Townships & Schools: Jul 1, 2026
  • Compliance Required Now

What the Law Really Says

Ohio Revised Code §9.64 requires political subdivisions to adopt a cybersecurity program aligned to recognized frameworks such as NIST CSF or CIS Controls. The program must address identification, protection, detection, response, recovery, staff training, incident reporting, and ransomware governance.

How Professionals Actually Read It

Compliance is not achieved by adopting a template. Auditors, insurers, and legal counsel evaluate whether controls are actually implemented, maintained, and exercised.

Key Takeaway

A binder that references controls you don't actually run is not compliance.

It is a finding waiting to be written and a liability waiting to be argued.

Inside a Real Incident Response Policy

  • Roles & Severity — Incident ownership and classification.
  • Response Lifecycle — Preparation through recovery.
  • Communications & Evidence — Preserve communications and evidence.
  • Statutory Reporting — Meet all state reporting requirements.
  • Ransomware Governance — Board approval processes.
  • Board Documentation — Resolutions, forms, workflows, and contacts.

Build It In-House or Bring Help?

Free state resources are valuable, but they are not a complete cybersecurity program. Organizations must still tailor, adopt, implement, and maintain the program.

The Dollars and Cents

The cost of a ransomware event, investigation, recovery effort, legal review, and operational downtime often exceeds the investment required to establish a compliant program.

Start Now, Get Compliant, Build As You Go

Begin with governance, multifactor authentication, backups, incident response planning, and staff training. Then mature the program over time.

Free Assessment

Not sure where your subdivision stands?

Request Aftermath Security's §9.64 readiness self-assessment and identify compliance gaps before auditors or attackers do.

Request Assessment