North Carolina's new state budget makes a commitment to cybersecurity in two connected ways: significant new funding and a permanent legal framework to guide how that funding and future security investments get put to work.
The Funding: $60 Million, Two Sources
The budget allocates to the N.C. Department of Information Technology $60 million for fiscal year 2026-27: $18 million in recurring state funding plus $42 million drawn from the statewide IT Reserve.
The recurring piece signals a lasting commitment – it renews annually rather than expiring after one year – and pays for both maintaining existing security tools and standing up new capabilities as threats evolve. The IT Reserve draw functions as a one-time infusion for larger, up-front investments.
Together, this funding supports enterprise cybersecurity tools across the state's network and adds eight new positions to the Enterprise Security and Risk Management Office, roughly doubling that team to 20 staff.
The Mandate: A New Statute for Identity and Access
Section 40.5 of the budget establishes a statewide Enterprise ICAM (Identity, Credential, and Access Management) framework to shape how the cybersecurity funding above gets deployed.
The statute directs NCDIT to set minimum standards across nine areas, including multifactor authentication, privileged access management, fraud detection, logging and auditability, and a technology-neutral, modular architecture.
Compliance is not optional: Agencies covered by the law cannot procure, renew, or substantially modify a system requiring authentication unless it meets these standards, or the agency secures a written waiver from the State Chief Information Officer. Legacy systems under existing contracts may continue, but agencies must coordinate with NCDIT on a path toward compliance.
The State CIO also gains authority to require integration with designated enterprise identity services, set migration timelines, and prioritize public-facing systems in the rollout.
What's Next
Within 12 months, NCDIT must complete a comprehensive review of the state's existing identity environment – contracts, authentication platforms, and identity-assurance services – to determine whether it meets enterprise interoperability, zero-trust, and fraud-reduction requirements. If gaps are found, NCDIT will issue competitive solicitations for new enterprise identity services.
Why It Matters
Funding and mandate work as a pair. The $60 million buys the tools and people; Section 40.5 gives NCDIT the authority to make adoption stick across every participating agency. For CIOs and security liaisons, that means a new procurement process to plan for – and a shared identity framework that should reduce duplicative logins and strengthen the state's overall security posture over time.