Ohio ORC § 9.64 Cybersecurity Compliance Software

The GRC Assessment Platform™ for Ohio political subdivision cybersecurity programs

Isora GRC helps Ohio’s counties, municipalities, and special districts implement and maintain cybersecurity programs that meet ORC § 9.64, with risk assessments aligned to NIST CSF and the CIS Controls, a connected system and vendor inventory, risk tracking and remediation with assigned owners, and program documentation for the Auditor of State produced from that same record, all in one place.

Trusted by established organizations & partners
https://vt.eduhttps://www.af.milhttps://utexas.eduhttps://yale.eduhttps://www.tdi.texas.govhttps://www.ttuhsc.eduhttps://aws.amazon.comhttps://www.osu.eduhttps://www.wilcotx.govhttps://www.utoronto.cahttps://www.tdcj.texas.govhttps://www.uchicago.edu/enhttps://www.utah.eduhttps://dir.texas.govhttps://www.dps.texas.govhttps://www.berkeley.eduhttps://www.techstars.comhttps://cccs.eduhttps://www.iwu.eduhttps://msu.eduhttps://www.auburn.eduhttps://www.stthomas.eduhttps://www.getezmoney.comhttps://www.sait.cahttps://www.ubc.cahttps://www.cuanschutz.eduhttps://www.tjc.eduhttps://marymount.eduhttps://www.umt.eduhttps://www.pdx.eduhttps://www.tccd.eduhttps://ltu.eduhttps://morantechnology.comhttps://www.merit.eduhttps://www.tccd.eduhttps://www.gonzaga.eduhttps://www.bhc.eduhttps://www.dallascollege.edu

Problem

ORC § 9.64 asks local governments to start from scratch

Building the six required program components for ORC 9.64 is difficult when the system inventory, risk register, incident procedures, and training records live in separate spreadsheets and shared drives. When the Auditor of State opens an audit cycle, teams must gather documentation from files that were never designed to connect.

Solution

One platform for building and documenting an ORC § 9.64 program
Isora GRC brings the six ORC 9.64 program components into one connected workspace, with risk assessments aligned to CyberOhio guidance, NIST CSF and the CIS Controls, system and vendor inventories, risk tracking with assigned owners, and AOS reporting. The documentation stays current because the work and the record happen in the same system.
Assessment Management
Assess the six § ORC 9.64 program components

Launch risk assessments using prebuilt questionnaires aligned to NIST CSF and the CIS Controls, the two frameworks the statute names. Target departments, systems, and service providers, and collect policies, procedures, and training records inline so responses and proof stay connected. Recurring cycles keep the program current between audits.

Learn More
Inventory Management
Build the system inventory the statute requires

Every system, application, and vendor record links to its assessments, risks, and documentation, with critical function designations, dependencies, and owners captured alongside it. ORC 9.64 calls for a complete inventory of systems and interdependencies, and that inventory stays current because maintaining it is part of the assessment workflow.

Learn More
Risk Management
Turn assessment findings into a risk register with tracking

Publish a gap to the risk register as soon as an assessment identifies it. Every finding carries lineage back to the program component it maps to, the assessment that surfaced it, and the system it affects. Assign owners, set completion dates, and track progress while an append-only audit log records every decision.

Learn More
Reports & Scorecards
Produce documentation for the Ohio Auditor of State

Generate reports and scorecards that pull from live assessment scores, risk register entries, inventory records, and training completion. Show coverage across all six program components without weeks of manual assembly, and drill into any metric to reach the assessment response behind it.

Learn More
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo
Latest Content
Our latest content
Stay ahead of the curve with our latest research on a diverse range of topics exploring the ever-changing world of governance, risk, and compliance.

State Information Security Regulations: Complete Guide Across the U.S., all fifty state governments have issued their own state information security...

Complete guide for Ohio ORC § 9.64 requirements including deadlines, program components, incident reporting, and compliance strategies.

Frequently Asked Questions
Ohio ORC § 9.64 Cybersecurity Compliance FAQs
Find the answers you need here, or chat with us.
Contact Sales
What does ORC § 9.64 require from political subdivisions?

Ohio Revised Code § 9.64 requires every political subdivision to adopt a cybersecurity program covering six components, which are risk identification and critical functions, impact assessment, threat detection, incident response, infrastructure repair and maintenance, and employee training. The statute directs subdivisions to build programs consistent with NIST CSF and the CIS Controls, leaving control selection to each subdivision. Isora GRC provides the assessment, inventory, risk tracking, and reporting workflows to operationalize those components.

Which subdivisions are covered, and when are the deadlines?

The law covers counties, municipalities, townships, and special districts, while state agencies fall under ORC § 125.18 instead. It took effect September 30, 2025, and audits of counties and municipalities began January 1, 2026. All other subdivisions were required to adopt a program by July 1, 2026.

How does Isora align with NIST CSF and the CIS Controls?

Isora includes prebuilt questionnaires mapped to NIST CSF functions and CIS Control safeguards, so a subdivision can launch an assessment without building templates first. Because ORC 9.64 asks for programs consistent with these frameworks, assessments can usually be scoped to the size, mission, and risk profile of each subdivision.

Does Isora support incident reporting to OCIC and the Auditor of State?

Isora maintains the record behind both notifications, including the incident response procedures, the systems affected, the risks and remediation actions tied to an event, and the audit log documenting each step. That record supplies the documentation for the seven-day Ohio Cyber Integration Center (OCIC) notification and the thirty-day Auditor of State submission, though the subdivision files them.

Does using a managed service provider satisfy ORC § 9.64?

Political subdivisions remain accountable for the program regardless of who operates the controls, so a managed service provider arrangement still has to be documented. Isora tracks service providers in the same inventory as internal systems, keeping provider assessments, contract terms, and associated risks alongside the rest of the program record.