2026 Annual Certification

Related links

Contact

 
 
 
 
 
 
 
 
 
 
 
 
 
 

UPDATE 7-16-26: After reviewing agency feedback and considering the overall impact, we have decided to revert back to last year’s inventory template for this year’s inventory submission.

This is to reduce disruption, provide a more familiar process for agencies, and allow the WaTech TBM Program team to take additional time to review lessons learned before making future template updates.


Welcome to the 2026 Annual Technology Certification 

Per RCW 43.105.054 and POL-01 Technology Policies, Standards and Procedures, agency partners must report on their technology portfolio and compliance with statewide technology policies every year. Agencies must attest to compliance each year based on policies approved by the Technology Services Board (TSB) by June of that year.

Completing WaTech’s annual technology certification promptly is crucial for managing your agency’s IT assets. Washington residents rely on us to keep their data safe, and technology supports nearly every state government function. As fiscal stewards, we ensure resources support agency priorities effectively.

The 2026 technology certification covers topics with significant business implications and risk indicators for your agency. It’s an opportunity for agency business and IT leaders to engage in strategic conversations, such as legacy modernization and investment strategy. The information collected will help manage your IT assets and inform the state’s strategic focus areas.

The deadline for the Annual Certification is September 30, 2026.

The deadline for waiver requests is November 1, 2026.

The deadline for the Annual IT Cybersecurity Report is December 31, 2026.


2026 Certification Requirements

The 2026 Annual Technology Certification process has five parts with due dates that fall between September and December 2026, as indicated below.

Part 1 - Application Inventory | DUE SEPT. 30, 2026

Update your agency’s application inventory using the current application and infrastructure inventory template.


Part 2 - Infrastructure Inventory | DUE SEPT. 30, 2026

Update your infrastructure inventory using the current application and infrastructure inventory template.


Part 3 - Technology Policy Certification | DUE SEPT. 30, 2026

Complete the online 2026 Agency Technology Policy Certification form. For a preview of what you will find in the form, see the Technology Policy Certification Guide. This guide will give you the list of questions found in the Certification and some tips on completing the form.

  • Signing and submitting the form certifies your agency’s level of enterprise policy compliance.
  • If your agency is not compliant with a policy, waiver requests should be submitted using the Electronic Waiver Request Form as described in Technology Standard POL-01-02-S.
  • Upon completion of the form, a notification email will be sent to the provided agency contacts with an attached copy of the given responses and a list of policies that need waiver requests.

Part 4 - Privacy Assessment | DUE SEPT. 30, 2026

Complete the 2026 Annual Privacy Assessment using the online survey.

  • Each agency must submit the completed Privacy Assessment Survey by the deadline.

Part 5 - Annual IT Cybersecurity Report | DUE DEC. 31, 2026

The Office of Cybersecurity (OCS) requires each agency to complete the Agency Cyber Risk and Controls Assessment. This assessment replaces the prior NCSR (Nationwide Cybersecurity Review) and enables our state to establish risk metrics, data for legislatively required reporting, and critical forward planning regarding Washington’s cybersecurity posture. Additionally, the assessment aids agencies in gaining insight into their individual cybersecurity gaps, risks and capabilities.

The assessment is expected to be available online starting in October 2026 and must be completed by December 31, 2026. Additional information and instructions for completing the assessment will be distributed to agencies in early fall 2026.


2026 Certification questions:

If you have any other questions, please contact David Mendel with WaTech’s Strategy & Management Division.

Questions concerning the Technology Policy Certification should be directed to Kate O'Donnell with the Enterprise IT Policy Office.

Questions concerning the Privacy Assessment reporting should be directed to Zack Hudgins with the Office of Privacy & Data Protection.

Questions concerning IT security reporting should be directed to Kathlyn Hofmann with WaTech's Cyber Risk Management Office.