State Security Operations Center; create within the Mississippi Department of Information Technology Services.
SB 2654 creates a State Security Operations Center (SSOC) within Mississippi’s Department of Information Technology Services (ITS) to serve as the state’s centralized cybersecurity operations hub. The SSOC will provide continuous monitoring, threat detection, incident response, and technical support to all state agencies subject to cybersecurity rules under Section 25-53-201, requiring agencies to report incidents, cooperate with SSOC efforts, and implement corrective actions. The Executive Director of ITS gains authority to enforce compliance through additional oversight, system access restrictions, or fees for noncompliance. The SSOC must submit annual reports detailing operations, incident responses, and future priorities to state leadership, all while complementing but not replacing existing cybersecurity governance under Section 25-53-201.
Bill status
signed
all 5 stages cleared
Introduction
Feb 2026
Committee Review
Mar 2026
Senate Passage
Feb 2026
House Passage
Mar 2026
Signed into Law
Apr 2026
Introduced Feb 6, 2026
Signed Apr 1, 2026
Maddy AI version diff · 3 comparisons
What changed between versions
As Passed the upper
→
Current version
·
4 edits
MODERATE
The bill was finalized and sent to the Governor, removing the "As Passed the Senate" status. Key substantive changes include expanding the Executive Director's enforcement authority to cover the entire Department rather than just ITS, clarifying that the Chief Information Security Officer (CISO) directs corrective actions, and removing a sunset clause that would have automatically ended the law on June 30, 2026, making the program permanent.
Scope change
The bill's scope was expanded to grant enforcement powers to the Executive Director of the entire Department of Information Technology Services, not just ITS, and the law is now permanent without an expiration date.
ENFORCEMENT
Enforcement powers were expanded from the Executive Director of ITS to the Executive Director of the entire Department of Information Technology Services.
DEFINITION
The term "CISO" was explicitly defined as the Chief Information Security Officer, replacing the previous reference to the CISO without a title.
TIMELINE
The automatic repeal date of June 30, 2026, was removed, making the legislation permanent.
REQUIREMENT
A reference to the reporting requirement being in addition to Section 25-53-201(4) was updated to refer to the current section instead of a specific subsection.
Floor votes · Senate Feb 4, 2026 · House Mar 5, 2026
How they voted
52–0
Passed
Total votes 52
Feb 4, 2026
D
Democratic18
100% Yea
R
Republican34
100% Yea
Vote distribution
All Yea
All Nay
Mixed
No data
Full legislative history
Actions timeline
Total actions
18
Key actions
9
Committee
6
Amendments
2
Apr 1, 2026
Signed into law
Approved by Governor
executive
Mar 25, 2026
Lower · Passed
Conference Report Adopted
lower
Mar 24, 2026
Lower · Passed
Conference Report Filed
lower
Mar 5, 2026
Lower · Passed
Passed As Amended
lower
Mar 5, 2026
Lower · Passed
Amended
lower
Mar 3, 2026
Lower · Passed
Title Suff Do Pass As Amended
lower
Feb 6, 2026
Committee
Referred To Accountability, Efficiency, Transparency
lower
Feb 6, 2026
Introduced
Transmitted To House
upper
Feb 4, 2026
Upper · Passed
Passed As Amended
upper
Feb 4, 2026
Upper · Passed
Amended
upper
Jan 28, 2026
Upper · Passed
Title Suff Do Pass Comm Sub
upper
Jan 19, 2026
Committee
Referred To Technology
upper
1 primary · 1 co-sponsor
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about SB 2654
Scope: MS
Hi! I can help you understand SB 2654. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline