Texas Cyber Command (TXCC) has certified 86 cybersecurity training programs for Fiscal Year 2027, establishing the options state and local government personnel can use to meet annual cybersecurity training requirements.
The certified programs are valid through Aug. 31, 2027, and vary by audience, cost, delivery method, accessibility and subject matter. TXCC allows users to filter the catalog based on whether programs are available to state agencies, local governments or K-12 school districts as well as features including assessments, phishing simulations and Spanish-language availability.
State law requires state and local government employees and officials to complete certified cybersecurity training annually. Contractors with access to a state computer system or database are also subject to training requirements during their contracts and renewal periods. For school districts, the annual statutory requirement applies to the district’s cybersecurity coordinator.
The catalog includes programs from Sam Houston State University, the University of Texas at Arlington, Texas State University, the Texas Health and Human Services Commission, the Texas Department of Insurance, the Texas Water Development Board, Hidalgo County and VIA Metropolitan Transit. CDW also has a security awareness training program among the certified offerings.
FY 2027 certification criteria add required content addressing business email compromise attacks and foreign adversary influence operations. Business email compromise training must address indicators including forced urgency, unnatural text patterns, repetitive writing and unverifiable details.
Programs must also address foreign adversary influence operations, including how to identify suspected activity and requirements for certain employees or volunteers of state agencies and political subdivisions to report interactions, communications or meetings with individuals representing foreign adversaries to the Texas Ethics Commission within 30 days. Training must also address potential consequences for violations.
For employees in IT roles, TXCC recommends additional training on third-party operational risk management, including business continuity and disaster recovery.
Under state law, certified programs must focus on developing information security habits and procedures that protect information resources.
TXCC develops the certification criteria in consultation with the Texas Cybersecurity Council. Programs must be renewed annually, and there is no cost for providers to submit a program for certification review. Applications for FY 2027 are closed.
The training catalog is among the statewide cybersecurity responsibilities now administered by TXCC, which was established as Texas’ centralized authority for cybersecurity operations, threat intelligence, incident response and digital forensics.
Texas Cyber Command Certifies 86 Cybersecurity Training Programs for FY27
What to Know:
- New required topics include business email compromise and foreign adversary activity.
- Public agencies and private providers are represented among the certified offerings.