← North Carolina profile

North Carolina

Current

G.S. 143B-1379(c) — School cybersecurity incident reporting

Local school administrative units must report cybersecurity incidents to the Department of Information Technology.

Jurisdiction
North Carolina · State / DC
Policy status
Effective
Implementation phase
Current
Requirement
Required
Grades
All K-12
Audience
Districts / LEAs
Learning evidence
No student-learning claim
Instrument
Statute / enacted law

Dates & implementation

Ongoing statutory incident-reporting requirement; subsection (c) sets no separate number-of-hours reporting deadline.

A legal effective date can precede school implementation. This record documents policy intent or requirements; it does not independently confirm delivery in every classroom.

Funding & support

Funding details not confirmed

Dedicated funding and current award availability are not established in this collection. This does not mean no funding exists.

Evidence & source location

GS143B-1379(c); covered-entity definition in GS143-800(c)(1)

School units included through G.S. 143-800(c)(1). Do not import the separate 24-hour state-agency deadline into subsection (c). Relevant to protection of school/student information; broader infrastructure detail excluded.

Review history

Reviewed against official sources

Source availability checked Oct 4, 2026: Source reopened. This is separate from verification of the policy claim below.

Source review date recorded in database: 2026-10-04

2026-10-03 — Carried forward from the source-linked baseline; topic, grade and evidence-type inventory reviewed. Individual source was not re-opened in this update. 2026-10-04 — Substantive source review: Current GS143B-1379(c) and cross-reference to GS143-800(c)(1) confirm school administrative units are covered local government entities.

Record ID: NC-CYBER-REPORT-001

Suggest a correction to this record