Resources

Free reference material for Ohio township and village officials. Everything here links to its primary source, and nothing asks for your email address. Facts checked against the sources on July 22, 2026.

ORC §9.64: where things stand

Ohio’s local-government cybersecurity law (ORC §9.64, enacted through House Bill 96) took effect September 30, 2025. The adoption deadlines have now passed: January 1, 2026 for counties and cities, July 1, 2026 for townships, villages, and all other political subdivisions.

If your subdivision hasn’t adopted a cybersecurity program yet, the useful response is to adopt one now, not to wait for the next audit cycle — the Auditor of State has said compliance procedures will be incorporated into the Ohio Compliance Supplement, which is what auditors test against.

What the law requires (AOS Bulletin 2025-007): your legislative authority must adopt a cybersecurity program that safeguards the subdivision’s data and IT resources — availability, confidentiality, integrity — consistent with generally accepted best practices (NIST and CIS are the examples AOS names). The program should be tailored to your entity’s size and needs; a township program doesn’t need to look like a county’s.

Self-assessment checklist

The program elements below are from Bulletin 2025-007. This is a plain checklist, not a score — it exists so you can see where you stand.

If you have an incident right now

Two notifications are required by law after discovering a cybersecurity or ransomware incident:

  1. Within 7 days: Ohio Homeland Security’s Ohio Cyber Integration CenterOCIC@dps.ohio.gov or 614-387-1089.
  2. Within 30 days: the Ohio Auditor of State — Cyber@ohioauditor.gov, or the form on the AOS cybersecurity page.

Also worth knowing in the moment:

Free training that satisfies the law

The state’s O-PCI program (Ohio Persistent Cyber Improvement, run by the Ohio Cyber Range Institute) is free for local governments, role-based (executive / IT / general staff), and — per Bulletin 2025-007 — annual O-PCI training satisfies the §9.64 training requirement. Register at ohiocyberrangeinstitute.org/opci.

There is no reason for a township to pay for compliance training.

Grants: check unspent awards first

Before chasing new money, check whether your subdivision already has a cybersecurity or technology grant award with an unspent balance — that’s often the faster win. Federal SLCGP funding has declined and the most recent CyberOhio round has closed, so prior awards matter more than new applications right now.

Award recipient lists are public record, and subdivisions can generally spend their own awards on outside vendors and services. Current program status and resources: CyberOhio grants & resources.

Primary sources

Everything above, in the original: