Ohio's Cybersecurity RFP Surge Signals a Reckoning for Jurisdictions That Waited Too Long
A state mandate buried in Ohio's budget bill is now enforced by auditors and a revived class-action lawsuit that every local government just watched Columbus lose.
Five cybersecurity RFPs from Ohio public entities landed in a single month this September, against a 12-month average of fewer than one per month. That 5.5x spike is procurement data, but it is also a fear response, and the fear has a precise timestamp: September 28, 2026, the day an Ohio appeals court unanimously ruled that a class-action lawsuit against the City of Columbus, stemming from the July 2024 Rhysida ransomware attack, must proceed.
The lawsuit's revival is the alarm bell every Ohio jurisdiction had been hoping not to hear. Columbus's legal team argued for dismissal. The 10th District disagreed. Now roughly 3,900 counties, municipalities, townships, school districts, and special districts across the state are watching Columbus defend itself in court over a breach that exposed Social Security numbers and bank account data for 500,000 residents, and they are reaching for vendor contracts the way people reach for umbrellas in a downpour.
The legal pressure is layered on top of a statutory one. Ohio House Bill 96, signed by Governor Mike DeWine on June 30, 2025 and effective September 30, 2025, mandated formal cybersecurity programs for every Ohio political subdivision under ORC § 9.64. Before HB 96, the obligation applied only to state agencies. The new law set two compliance deadlines: counties and cities by January 1, 2026, and school districts and all other governing bodies by July 1, 2026. Both deadlines have now passed. The Ohio Auditor of State updated its 2026 Compliance Supplement to treat ORC § 9.64 adherence as a line item in routine public audits, meaning cybersecurity is no longer a matter of best practice but of audit finding.
Ohio dwarfs neighbors in cybersecurity RFPs, September 2026
Source: NationGraph.
The mandate was easy to miss. HB 96 was embedded in Ohio's 3,165-page FY2026–2027 biennial budget, not enacted as standalone legislation. Legal and compliance advisors have noted that many jurisdictions did not register the requirement until auditors began asking questions. The September RFP spike suggests a cohort that registered it late is now moving fast.
The five issuers span geography and sector. The Columbus Department of Technology, ground zero for the original breach, issued two RFPs, one for cybersecurity evaluation, one for enhancements, and has publicly committed to a Zero Trust Network architecture as part of its post-attack remediation. The City of Sandusky is seeking bids on a SCADA and critical infrastructure upgrade. The Ohio Department of Agriculture is procuring a cybersecurity tooling license. Wright-Patterson Air Force Base in Dayton, a federal installation that adds a defense-industrial dimension to the state's posture, issued its own solicitation. Together they represent a cross-section of the entities HB 96 targets: large urban governments, small cities, state agencies, and installations where Ohio's security posture intersects with federal priorities.
Ohio is not working without resources. The state holds $41 million in active federal cybersecurity grants across 24 awards, anchored by a $7.7 million DHS State and Local Cybersecurity Grant Program award administered through the Ohio Department of Public Safety. Critically, only $7.6 million of that $41 million has actually been outlayed. The bulk of the federal money has not yet moved into implementation spending. The RFPs being issued now are the mechanism by which that changes, vendor contracts will draw down grant dollars that have been sitting obligated but unspent. The federal SLCGP grant and HB 96 are legally independent: the mandate applies to every political subdivision whether or not it receives federal money. But for jurisdictions that do hold grants, the RFPs are how the two tracks finally converge.
No neighboring state comes close to Ohio's September volume. West Virginia issued two cybersecurity RFPs in the same window, Pennsylvania one, and Michigan, Indiana, and Kentucky combined for zero. That gap reflects both the scale of HB 96's reach and the specificity of Ohio's political moment: no other neighboring state has a comparable statutory mandate, an active auditor review process, and a high-profile ransomware case generating live appellate decisions simultaneously.
For residents, the most direct consequence is that the government systems handling their tax records, utility accounts, school enrollment data, and public health information are now subject to formal security requirements for the first time, and vendors who win these contracts will be implementing those requirements over the next 12 to 24 months. The $33 million in unspent federal grant money provides the funding runway.
What to watch next: how many of Ohio's 3,900 political subdivisions generate audit findings when the Auditor of State's 2026 cycle closes, and whether any of those findings appear in the same jurisdictions as pending breach claims. The Columbus lawsuit is a preview of how that sequence plays out. The RFP surge suggests at least some jurisdictions have read it carefully.