
Ohio ORC 9.64 is ushering in a significant shift for public entities in Ohio, presenting substantial growth opportunities for MSPs and MSSPs. The legislation requires cities, counties, school districts, and libraries to comply with new, comprehensive cybersecurity mandates. However, many of these entities operate with limited resources and lack the in-house expertise to meet these stringent requirements on their own.
As a result, they need reliable partners with proven cybersecurity knowledge. This creates an opportunity for your organization to build lasting partnerships, deliver high-value services, and support the cyber resilience of Ohio’s communities by positioning your services as the essential solution for achieving and maintaining compliance with ORC 9.64.
What is Ohio ORC 9.64 (Ohio HB 96)?
Ohio Revised Code (ORC) 9.64, enacted as part of the 2025 legislative budget bill, Ohio HB 96, requires local governments, including cities, counties, school districts, and libraries, to establish comprehensive, risk-based cybersecurity programs. The goal is to protect the confidentiality, integrity, and availability (CIA) of their systems and data against rising cyber threats.
The law doesn’t just suggest security improvements, it mandates them. It sets strict requirements for incident reporting, especially concerning ransomware payments, and requires entities to adopt a program based on recognized cybersecurity frameworks, such as NIST or CIS. For many public organizations with limited resources, meeting these requirements is a monumental task, making expert support from MSPs and MSSPs indispensable.
Who is Impacted and What Are the Deadlines?
ORC 9.64 applies to a wide range of public entities across Ohio, each with specific deadlines. The tiered timeline creates a sustained demand for cybersecurity services over the next year.
- January 1, 2026: Counties and cities are required to adopt a cybersecurity plan.
- July 1, 2026: School districts, libraries, and all other political subdivisions are required to adopt a cybersecurity plan..
A previous deadline of September 30, 2025, already put rules in place for incident reporting and ransomware payment restrictions, adding to the urgency. These deadlines are firm, and entities will be expected to provide documented proof of compliance.
The Six Core Components of an ORC 9.64 Program
The legislation outlines six fundamental components that must be included in every cybersecurity program. This provides a clear roadmap for MSPs to structure their service offerings.
- Risk Identification and Critical Functions: Identifying and assessing risks to essential systems and data.
- Threat Detection Mechanisms: Implementing tools and processes to detect potential cyber threats.
- Incident Response Procedure: Establishing a formal, documented plan for responding to security incidents.
- Infrastructure Repair and Maintenance: Creating procedures for restoring systems after an incident.
- Employee Training Requirements: Developing and implementing ongoing cybersecurity awareness training for all staff.
- Impact Assessment: Evaluating the potential impact of a cybersecurity event on the organization’s operations and data.
For an MSP, these components translate directly into service offerings like risk assessments, managed detection and response (MDR), incident response planning, business continuity and disaster recovery (BCDR), and security awareness training.
A Major Opportunity for Service Providers
The introduction of ORC 9.64 has created a vast new market for cybersecurity services in Ohio. Consider the numbers:
- 615 school districts
- 721 libraries
- 88 counties
- 931 municipalities
Each of these entities is now legally required to develop, implement, and document a cybersecurity program. Many, if not most, face significant hurdles that make achieving compliance on their own nearly impossible.
Key Challenges Facing Ohio Public Entities
Your services are the direct solution to the primary challenges these organizations are facing:
- Limited Expertise and Staffing: Most local governments and schools do not have a dedicated CISO or a team of cybersecurity experts.
- Mandatory, Unforgiving Deadlines: The work required is substantial, and the deadlines are fast approaching.
- Uncertainty About Requirements: Many organizations are unsure where to start or how to interpret the law’s requirements.
- Lack of Documented Processes: Existing security efforts are often informal and not documented in a way that would satisfy an audit.
- Concern About Scrutiny: Public entities are accountable to auditors, boards, and the public, increasing the pressure to get compliance right.
This is where your business can become a strategic partner. You can provide the expertise, tools, and structured approach needed to navigate these challenges efficiently.
How to Position Your Services for ORC 9.64 Compliance
To capture this opportunity, you need to align your offerings directly with the pain points and requirements of ORC 9.64. Frame your services not just as technical solutions, but as a complete compliance package.
You can deliver a program that meets the state’s mandates by offering:
- Framework-Aligned Programs
- Business Impact Analysis & Continuity Planning
- Risk Management
- Vendor Risk Assessments
- Documentation and Policy Development
- Incident Response and Ransomware Reporting Readiness
- Continuous Compliance Management
By using a centralized platform like Cynomi that automates and standardizes assessments and workflow processes, you can deliver audit-ready programs in days rather than months. This allows you to serve more clients with fewer resources, increasing your margins and scaling your business effectively.
Start Seizing the Opportunity Today with Cynomi
ORC 9.64 is a catalyst for growth for proactive MSPs and MSSPs. By providing a streamlined, efficient, and scalable solution, you can help Ohio’s public entities protect their communities while building a strong, recurring revenue stream for your business. The deadlines are approaching, and these organizations need expert help now.
Cynomi is a Service Provider Growth Enablement Engine that empowers MSPs to streamline compliance and cybersecurity management. By automating time-consuming tasks and standardizing workflows, you can deliver comprehensive, audit-ready ORC 9.64 programs efficiently. Learn more about Cynomi’s ORC 9.64 solutions here.
Download the Ohio ORC 9.64 Sales Kit to streamline your offerings, demonstrate value to your clients, and drive revenue growth with audit-ready solutions.