What Is Cal-Secure? California's State Cybersecurity Roadmap

Written by: 
Team Knox
Published on: 
August 13, 2026

Governor Newsom announced Cal-Secure 2.0 on July 31, 2026, the second phase of California's statewide cybersecurity roadmap and the first full update since the original roadmap launched in October 2021. For a Head of Governance, Risk, and Compliance (GRC) or VP of Compliance at a SaaS company selling into California agencies, the announcement raises a practical question: is this something a vendor must certify against?

Cal-Secure sets the security priorities for the agencies that buy your software, and its procurement practices indirectly affect vendors through security questionnaires. Contracts also incorporate cloud breach-notification clauses and California authorization expectations, the paperwork that stalls deals late in a procurement cycle. California's procurement mechanics determine how existing Federal Risk and Authorization Management Program (FedRAMP) work can reduce California-specific compliance work.

Key Takeaways

  • Vendor scope. The California Department of Technology (CDT) defines Cal-Secure as California's internal maturity roadmap for Executive Branch agencies.
  • Risk-based approach. CDT rebuilt the 2021 roadmap around AI-driven threats and three statewide priorities.
  • Procurement requirements. Agencies translate the roadmap into National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53-aligned questionnaires and contract terms. Those terms include breach clauses with 24- to 72-hour notice requirements, as well as data ownership terms.
  • FedRAMP portability. Statewide FedRAMP cloud contracts are structured around FedRAMP authorization levels, which makes a federal authorization the strongest single piece of security evidence to bring to a California deal, though it doesn't formally replace an agency's own authorization step.

Cal-Secure Is a Statewide Agency Maturity Roadmap

Cal-Secure is California's multi-year maturity roadmap for information security across Executive Branch agencies, not a vendor certification program. CDT's Cal-Secure 2.0 page describes it as "California's multi-year roadmap for information security maturity across California's Executive Branch." It is an internal improvement plan, and state agencies measure their security programs against it through structured reporting to CDT.

The roadmap tracks agency progress along a defined set of dimensions:

  • Maturity metric. CDT collects an annual maturity score that captures how far each agency has advanced along the roadmap's priorities.
  • Self-attestation. Agencies report their progress through an annual self-attestation process that is reviewed by CDT.
  • People, process, and technology. The framework organizes measurement into three pillars, so scores reflect gains in staffing and workflow rather than tooling upgrades.

Because Cal-Secure targets agencies rather than vendors, it sits alongside (but does not replace) the vendor-facing authorization programs that GRC teams already know. FedRAMP and the Government Risk and Authorization Management Program (GovRAMP) are vendor-facing authorization programs, and they do the certification work that Cal-Secure deliberately does not.

That distinction is what makes the roadmap useful to a vendor even without a certification hook: it signals what California's security leadership will fund and demand over the next several years, which is exactly the horizon the 2.0 refresh reshapes.

Cal-Secure 2.0 Replaces the Original 2021 Roadmap for AI-Era Threats

The original 2021 Cal-Secure roadmap was a five-year maturity roadmap, organized into nine priorities and 15 initiatives. It used People, Process, and Technology as its pillars. Cal-Secure 2.0 keeps those pillars and revises the roadmap beneath them.

Two Forces Prompted the Cal-Secure Update

Two forces drove the revision. The first is the calendar: the 2021 roadmap's five-year horizon ended.

The second is AI. CDT now frames the time-to-exploit window as having collapsed from months to hours. In response, CDT says it has "matured a compliance-based checklist into a flexible, risk-based strategy tailored to the distinct missions of the state's agencies, departments, and offices." The update was developed with the California Cybersecurity Integration Center and the Governor's Office of Emergency Services (CalOES). The California Highway Patrol and the California Military Department also contributed.

State chief information officer (CIO) and CDT Director Chris Given framed the intent at launch: "Cyber threats don't stand still, and neither can we."

Three Priorities Define Cal-Secure 2.0

The Governor's announcement organizes the refreshed roadmap around three priorities that will shape agency spending and vendor scrutiny over the next several years:

  • Cyber workforce development. The state plans to recruit and retain security staff across state government while expanding training programs. Expect sustained state investment in security staffing and training programs.
  • Improved information sharing. The plan pushes agencies to coordinate incident information and respond faster. Shared lessons will help agencies learn from one another. The coordination runs agency to agency, which should raise the practical bar on the consistency of vendor incident reporting.
  • Continued technology modernization. The state plans to invest in stronger security tools while "preparing for emerging technologies, including artificial intelligence." CDT separately names post-quantum cryptography readiness, a topic worth watching in future California requests for proposal.

These priorities set the direction, but they only bind the entities that Cal-Secure formally reaches, which is where the roadmap's legal scope becomes relevant to any vendor building a California pursuit plan.

Cal-Secure Binds State Agencies Directly

The roadmap's obligations fall on covered Executive Branch entities under Government Code Section 11546.1: agencies and offices within the Executive Branch under the Governor's direct authority.

The enforcement machinery behind the roadmap is California's policy stack, a layered set of statutes and manuals that translate Cal-Secure's priorities into binding controls, program requirements, and contract terms:

  • Government Code Section 11546.1. Defines the covered Executive Branch entities that must operate under CDT's information security authority, establishing who Cal-Secure formally reaches.
  • SAM Section 5300.5. State Administrative Manual SAM Section 5300.5 adopts NIST SP 800-53 as the state's minimum security control requirement, and every state entity must build its security program on that baseline.
  • SIMM 5305-A. Statewide Information Management Manual SIMM 5305-A establishes California's information security program management requirements, including requirements that apply when state data or systems involve external providers.
  • DGS cloud special provisions. Agencies translate the manuals into contracts; Department of General Services (DGS) cloud special provisions impose security and breach-notification obligations directly on vendors.
  • CDT confidential control parameters. CDT's confidential control parameters are classified, so vendors see them only under a nondisclosure agreement (NDA) during a procurement.

These instruments give CDT and contracting officers a clear chain from statute to contract clause, which is why Cal-Secure's priorities show up in vendor paperwork even though the roadmap itself never mentions vendors.

Agencies are under real pressure to close their own gaps. Cybersecurity remained on the state's high-risk list in the California State Auditor's December 2025 report. The report cited a CDT finding that 46 percent of nonreporting entities were out of compliance with either their security certification or their plan of action and milestones.

Limited annual CDT audits cover only a fraction of its reporting entities. Agencies unable to fully verify their own posture will likely rely more heavily on documented vendor evidence.

State Agencies Translate Cal-Secure Priorities Into Vendor Requirements During Procurement

The roadmap becomes real for a SaaS vendor at four points in the procurement process, each of which converts a Cal-Secure priority into a contract clause or evidence request.

1. NIST-Aligned Security Evidence

SAM Section 5300.5 requires state entities to use NIST SP 800-53 as their minimum security control baseline. SIMM 5305-A establishes information security program requirements for access control and identification and authentication. It also covers technology upgrades. Vendors should be prepared to map their evidence to that baseline.

2. Incident Notification Timelines Written Into Contracts

Under the DGS cloud special provisions for infrastructure and platform services, the vendor must notify the state by telephone within 24 hours of a confirmed data breach. CDT's statewide FedRAMP cloud agreements with Oracle and Google FedRAMP Moderate set a 72-hour notification standard. DGS's draft SaaS special provisions add daily status updates until the breach is resolved to the state's satisfaction.

3. Data Handling Attestations

Procurement may cover data ownership and residency. Access attestations may also apply. CDT's Oracle FedRAMP High agreement states that "all State Data shall become and remain the property of the State." CDT's Microsoft FedRAMP High agreement adds a state data-classification requirement.

4. A Federal-Grade Authorization as a Shortcut Signal

CDT's statewide cloud contracts are labeled by FedRAMP level:

Arriving with a FedRAMP authorization covers much of the NIST SP 800-53 evidence behind steps one through three; however, SIMM 5305-A still requires the agency's security authorization before deployment.

Cal-Secure and FedRAMP Solve Compliance at Different Levels of Government

Cal-Secure and FedRAMP share the same control foundation, NIST SP 800-53, but they operate on different actors. Cal-Secure directs state agencies to mature their internal programs; its output is an agency maturity roadmap. FedRAMP provider assessments include an independent assessment and continuous monitoring, and produce an authorization that is listed for reuse by every federal agency.

California's own cloud security authorization process under SIMM 5305-A follows the same NIST risk-management approach and requires agencies to obtain a security authorization before deploying cloud workloads. FedRAMP evidence therefore maps cleanly onto California's asks.

The transfer extends beyond California. The multi-state GovRAMP program, formerly called StateRAMP, offers a GovRAMP Fast Track program that lets vendors with FedRAMP Ready, Authority to Operate (ATO), or Provisional ATO status reuse their FedRAMP documentation without a new audit, substantially compressing the standard timeline. Vendors weighing the sequencing question should note that FedRAMP work feeds both paths; state-specific work feeds only one.

A GRC leader must decide whether to assemble a California-specific evidence package for each agency or to use the authorization that California's statewide contracts already treat as the benchmark.

SaaS Vendors Can Sell Into California Without Rebuilding Their Compliance Programs

Cal-Secure 2.0's risk-based flexibility is likely to increase the verification burden on vendors, and agencies with limited review capacity, now holding discretion over which risks to prioritize, will lean on vendor-supplied proof to close the gap. That pressure raises the question for any GRC leader with California in the pipeline: build a California-specific evidence package, agency by agency or inherit an authorization that the state's own statewide contracts already treat as the benchmark?

Inheritance is the more efficient path. A control set mapped to NIST SP 800-53 and independently assessed supplies most of the evidence California's questionnaires and federal procurement ask for on a single investment. The same control set also supports GovRAMP's Fast Track, so the federal work feeds both federal and state pursuits at once. Building that evidence base per-state is the expensive path.

Positioning for Cal-Secure 2.0 With a Portable Authorization

Cal-Secure 2.0 rewards vendors who arrive with recognized authorizations. California's statewide cloud agreements are structured around FedRAMP levels, which means a FedRAMP authorization is the closest thing to a universal California signal, one investment that clears NIST alignment, informs breach and data-handling clauses, and shortens the agency's own SIMM 5305-A authorization step.

Knox Systems is a FedRAMP-as-a-Service platform with a pre-authorized Knox FedRAMP boundary that customers deploy into. While traditional FedRAMP authorization can take 12 to 36 months and cost upwards of $3.5 million, Knox's managed service helps customers achieve federal authorization in approximately 90 days and at approximately $500,000 per application, roughly 90% less.

Because California FedRAMP cloud agreements are structured around FedRAMP levels, the authorization Knox customers earn on the government cloud platform is evidence California's own statewide contracts already treat as a benchmark.

If California is in your pipeline, book a meeting with Knox Systems to map the fastest path to authorization.

FAQs about Cal-Secure

Does Cal-Secure Apply to California Cities, Counties, and Local Agencies?

No. Cities, counties, and local agencies can still buy from CDT's FedRAMP-based statewide cloud contracts.

What Is the California Cloud Services Assessment (CCSA)?

The CCSA review process is mandatory before cloud services procured through CDT can be deployed. It covers commercial and government cloud providers, and security operations onboarding is mandatory for new cloud deployments.

Does California Formally Require GovRAMP Authorization?

No statewide SaaS authorization mandate follows from California's participation in GovRAMP alone. Such a mandate would require formal adoption of GovRAMP.

How Does Cal-Secure Relate to California's AI Procurement Rules?

California's separate administrative rules require agencies to evaluate generative AI (GenAI) vendors for compliance with NIST SP 800-53. GenAI disclosure requirements also apply to all state information technology (IT) solicitations, while Cal-Secure 2.0 signals further AI-specific security scrutiny.

Who Leads Cal-Secure Implementation?

CDT's Office of Information Security runs Cal-Secure. State chief information security officer (CISO) Vitaliy Panych announced his departure in July 2026, so vendors in active sales cycles should watch for a successor announcement.