{"data":{"id":"us-in/ic-4-13.1-4-8","jurisdiction":"us-in","citation":"IC 4-13.1-4-8","heading":"Requirements for connection to state technology infrastructure","body":"Sec. 8. (a) A public entity that connects to the technology infrastructure of the state after July 1, 2027, must:\n(1) have completed a cybersecurity assessment within the three (3) year period immediately preceding the first date after July 1, 2027, on which the public entity connects to the technology infrastructure of the state;\n(2) complete a cybersecurity assessment at least once every three (3) years after the first date after July 1, 2027, on which the public entity connects to the technology infrastructure of the state;\n(3) provide proof to the office of the public entity's compliance with subdivisions (1) and (2) upon request by the office;\n(4) if the public entity is a state agency or political subdivision, have an \"in.gov\" or \".gov\" domain name; and\n(5) have a secondary end user authentication mechanism.\n(b) An entity that is not a public entity and that connects to the technology infrastructure of the state after July 1, 2026, must:\n(1) have completed a cybersecurity assessment within the two (2) year period immediately preceding the first date after July 1, 2026, on which the entity connects to the technology infrastructure of the state;\n(2) complete a cybersecurity assessment:\n(A) at least once every two (2) years after the first date after July 1, 2026, on which the entity connects to the technology infrastructure of the state; and\n(B) biennially for as long as the entity connects to the technology infrastructure of the state;\n(3) provide proof to the office of the entity's compliance with subdivisions (1) and (2) upon request by the office; and\n(4) have a secondary end user authentication mechanism.\n(c) At the discretion of the office:\n(1) a public entity that is not in compliance with subsection (a); or\n(2) an entity that is not in compliance with subsection (b);\nmay be disconnected from the technology infrastructure of the state.","path":["TITLE 4. STATE OFFICES AND ADMINISTRATION","ARTICLE 13.1. OFFICE OF TECHNOLOGY","Chapter 4. Technology Resources, Cybersecurity, and Infrastructure Standards"],"source_url":"https://iga.in.gov/ic/2026/Title_4.html#4-13.1-4-8","current_through":"2026","vintage":"2026","retrieved_at":"2026-08-30T06:26:00Z","sha256":"5a2022d15c8a9aacc0f663761af152b46e111411d368180284cd0ce877c3a93b","source_id":"us-in","stale":false,"prev":"us-in/ic-4-13.1-4-7","next":"us-in/ic-4-13.1-4-9"},"notice":"GroundRules: Original legal text. Not legal advice."}
