Idaho Capitol Watch

HB 35: INFORMATION TECHNOLOGY SERVICES – Amends and adds to existing law to require the implementation of cybersecurity best practices and the use of multifactor identification in Idaho state government.

Requires Idaho state agencies to implement cybersecurity best practices and mandatory multifactor authentication for accessing state IT systems. Expands Office of Information Technology duties and extends MFA requirements to legislative, judicial branches, and constitutional officers. Effective July 1, 2025.

Status

Signed by Governor (February 25, 2025) · Originated in the Idaho House · Introduced January 22, 2025

Sponsors

  • COMMERCE AND HUMAN RESOURCES COMMITTEE

Committees

  • JRA for Printing

Bill history

  • February 11, 2025 — Senate: Read second time; filed for Third Reading
  • February 18, 2025 — Senate: Read third time in full – PASSED - 31-4-0AYES – Adams, Anthon, Bernt, Bjerke, Blaylock, Burtenshaw, Cook, Den Hartog, Foreman, Galloway, Grow, Guthrie, Harris, Hart, Keyser, Lakey, Lenney, Lent, Nicho (passed)
  • February 20, 2025 — House: Reported Enrolled; Signed by Speaker; Transmitted to Senate
  • February 21, 2025 — Senate: Received from the House enrolled/signed by Speaker
  • February 21, 2025 — Senate: Signed by President; returned to House
  • February 21, 2025 — Senate: Returned Signed by the President; Ordered Transmitted to Governor
  • February 24, 2025 — Senate: Delivered to Governor at 11:46 a.m. on February 21, 2025
  • February 25, 2025 — Senate: Reported Signed by Governor on February 24, 2025 Session Law Chapter 6 Effective: 07/01/2025

If this preview does not update automatically, use the full page link.

Canonical URL: https://idahocapitolwatch.com/bills/2025-HB35