Related links
- 2026 Annual Certification Memo (PDF)
- 2026 Annual Certification Schedule (PDF)
- 2026 Annual Technology Policy Certification Guide (PDF)
Contact
- General questions: David Mendel
- Technology Policy Certification: Kate O'Donnell
- Privacy Assessment Reporting: Zack Hudgins
- IT Security Reporting: Kathlyn Hoffman
UPDATE 7-16-26: After reviewing agency feedback and considering the overall impact, we have decided to revert back to last year’s inventory template for this year’s inventory submission.
This is to reduce disruption, provide a more familiar process for agencies, and allow the WaTech TBM Program team to take additional time to review lessons learned before making future template updates.
-
The new inventory template is optional. The previous 2025-2026 inventory template is available on the Technology Portfolio Foundation - Applications Standard and Technology Portfolio Foundation - Infrastructure pages.
-
Agencies should use the previous 2025-2026 template for this year’s submission.
-
Agencies may use the new updated template if they choose to do so.
Welcome to the 2026 Annual Technology Certification
Per RCW 43.105.054 and POL-01 Technology Policies, Standards and Procedures, agency partners must report on their technology portfolio and compliance with statewide technology policies every year. Agencies must attest to compliance each year based on policies approved by the Technology Services Board (TSB) by June of that year.
Completing WaTech’s annual technology certification promptly is crucial for managing your agency’s IT assets. Washington residents rely on us to keep their data safe, and technology supports nearly every state government function. As fiscal stewards, we ensure resources support agency priorities effectively.
The 2026 technology certification covers topics with significant business implications and risk indicators for your agency. It’s an opportunity for agency business and IT leaders to engage in strategic conversations, such as legacy modernization and investment strategy. The information collected will help manage your IT assets and inform the state’s strategic focus areas.
The deadline for the Annual Certification is September 30, 2026.
The deadline for waiver requests is November 1, 2026.
The deadline for the Annual IT Cybersecurity Report is December 31, 2026.
2026 Certification Requirements
The 2026 Annual Technology Certification process has five parts with due dates that fall between September and December 2026, as indicated below.
Part 1 - Application Inventory | DUE SEPT. 30, 2026
Update your agency’s application inventory using the current application and infrastructure inventory template.
- There are no new questions, but some template modifications exist this year.
- Include new applications, updates, and removals compared to last year’s data.
- Review the application inventory template and the guidelines document for instructions.
- Submit your completed inventory to WaTech’s annual certification mailbox.
Part 2 - Infrastructure Inventory | DUE SEPT. 30, 2026
Update your infrastructure inventory using the current application and infrastructure inventory template.
- There are no new questions this year.
- Include additions, updates, and removals compared to last year’s information.
- Agencies already enrolled in Apptio Cloudability through the TBM Cloud Kick Start do not need to include third-party cloud resources; these will be captured automatically.
- Submit your completed inventory to WaTech’s annual certification mailbox.
Part 3 - Technology Policy Certification | DUE SEPT. 30, 2026
Complete the online 2026 Agency Technology Policy Certification form. For a preview of what you will find in the form, see the Technology Policy Certification Guide. This guide will give you the list of questions found in the Certification and some tips on completing the form.
- Signing and submitting the form certifies your agency’s level of enterprise policy compliance.
- If your agency is not compliant with a policy, waiver requests should be submitted using the Electronic Waiver Request Form as described in Technology Standard POL-01-02-S.
- Upon completion of the form, a notification email will be sent to the provided agency contacts with an attached copy of the given responses and a list of policies that need waiver requests.
Part 4 - Privacy Assessment | DUE SEPT. 30, 2026
Complete the 2026 Annual Privacy Assessment using the online survey.
- Each agency must submit the completed Privacy Assessment Survey by the deadline.
Part 5 - Annual IT Cybersecurity Report | DUE DEC. 31, 2026
The Office of Cybersecurity (OCS) requires each agency to complete the Agency Cyber Risk and Controls Assessment. This assessment replaces the prior NCSR (Nationwide Cybersecurity Review) and enables our state to establish risk metrics, data for legislatively required reporting, and critical forward planning regarding Washington’s cybersecurity posture. Additionally, the assessment aids agencies in gaining insight into their individual cybersecurity gaps, risks and capabilities.
The assessment is expected to be available online starting in October 2026 and must be completed by December 31, 2026. Additional information and instructions for completing the assessment will be distributed to agencies in early fall 2026.
2026 Certification questions:
If you have any other questions, please contact David Mendel with WaTech’s Strategy & Management Division.
Questions concerning the Technology Policy Certification should be directed to Kate O'Donnell with the Enterprise IT Policy Office.
Questions concerning the Privacy Assessment reporting should be directed to Zack Hudgins with the Office of Privacy & Data Protection.
Questions concerning IT security reporting should be directed to Kathlyn Hofmann with WaTech's Cyber Risk Management Office.