Texas HB 3834, codified at Government Code 2054.5191 and 2054.5192, requires state agency employees and officials, local government employees and officials who use a computer for at least 25 percent of their duties, and state agency contractors with system access to complete a DIR-certified cybersecurity training program every year. Each government entity must then certify its compliance to the Texas Department of Information Resources by August 31, and since the 89th Legislature passed HB 3512, a certified AI awareness program is required on the same annual cycle.
The rule is simple to state and easy to get wrong in the details: who counts, which program counts, and what proof you keep when DIR never asks to see the certificates.
What Does Texas HB 3834 Actually Require?
The law has three moving parts. Government Code Chapter 2054 directs DIR to certify at least five cybersecurity training programs each year (Section 2054.519), requires covered employees and officials to complete one of them annually (Section 2054.5191), and requires state agency contractors to complete certified training too (Section 2054.5192).
Under Section 2054.519, a certified program must focus on forming information security habits and procedures that protect information resources, and teach best practices for detecting, assessing, reporting, and addressing security threats. DIR’s statewide cybersecurity awareness training page publishes the annual timeline: training providers submit programs between June 1 and July 31, DIR publishes the new certified list on August 31, and every covered government entity reports completion through DIR’s web form by August 31.
That means the cycle that matters right now started on September 1, 2026. Whatever program you used for FY 2025-26 needs to be on the FY 2026-27 list to count this year. Certifications expire every August 31 and must be renewed.
Who Must Complete the Training?
Coverage differs by entity type, and DIR’s mandatory training FAQ answers most of the edge cases:
- State agencies (including universities, and community colleges through TAC 202): employees who use a government computer for at least 25 percent of their duties, plus all elected and appointed officers regardless of computer use. DIR’s FAQ goes further and says all state agency employees must train annually on a certified program.
- Local governments (counties, cities, special districts, and other political subdivisions): employees, elected officials, and appointed officials with access to a local government system or database who use a computer for at least 25 percent of their duties. Part-time employees count. Per the FAQ, elected officials must train even without system access.
- School districts: only the district’s cybersecurity coordinator is required by statute. Board members, as elected officials, are also required. The district decides who else trains.
- State agency contractors: anyone given an account on a state information system, during the contract term and any renewal, with no hours threshold and no exceptions. This covers contracts entered or renewed on or after June 14, 2019.
Two corrections to a common assumption. First, local government contractors are not covered. DIR’s FAQ states the contractor requirement applies only to state agencies. Second, charter schools are not local governments under Chapter 2054 and are not subject to the statute. Exceptions exist for employees on military leave, FMLA leave, or other extended leave who no longer have system access.
A 180-employee Texas county is a useful example. Its road and bridge crew of 40 rarely touches a computer, so most fall below the 25 percent threshold. Its 5 commissioners and the county judge must train regardless. The clerk’s office, tax office, and sheriff’s administrative staff are in. The IT vendor that manages the county’s network is not covered by the statute, though the county can still require training by contract. Getting that list right is what our free state-coverage check is for: we map roles to the rule before you assign anything.
What Changed With the 2025 AI Training Requirement?
The 89th Legislature passed HB 3512, which added artificial intelligence awareness training to the same framework. DIR’s January 2026 announcement confirms that state and local government employees must complete a certified AI awareness program annually. Certified AI programs must build an understanding of how AI may be used in relation to an employee’s responsibilities and teach best practices on AI literacy. DIR publishes the criteria and program list on its statewide AI awareness training page.
In practice, most entities now run two certified programs a year for the same population. Supplemental courses such as Artificial Intelligence 01: What Is AI and The Ethics of AI can build literacy for staff who use AI tools daily, but they do not replace the certified program unless DIR has certified that specific course.
Does the Training Program Have to Be DIR-Certified?
Yes. State agencies and local governments must use a program on DIR’s current certified list, and state agencies must also buy it through DIR’s cooperative contracts or obtain an exemption. DIR certifies programs, not vendors. If a program is part of a larger library, you must include the specific modules submitted for certification.
That has a direct consequence for anything else you assign. General security courses, including Coggno’s, are not DIR-certified unless they appear on the current list, so they cannot stand in for the HB 3834 requirement. They are useful for what the certified program does not cover in depth: phishing drills for finance staff, password practice for new hires, and ransomware response for IT. Phishing Awareness, Password Security, and Ransomware are the common add-ons. Our explainer on phishing awareness training covers how those fit together.
One trap worth naming: CJIS Security Awareness Training is a certified program, but CJIS only requires it every 2 years. DIR’s FAQ is explicit that using it does not remove the annual Texas requirement.
How Do Entities Report Completion to DIR?
Once a year, by August 31, an authorized person at each entity submits DIR’s Cybersecurity Training Certification for State and Local Governments form, including the percentage of required participants who completed. Individuals do not report. You do not submit certificates or rosters to DIR.
That last point is where records go wrong. Because DIR never collects the evidence, nobody notices it is missing until an auditor, a cyber insurer, or a breach investigation asks for it. The local governing body is also required to verify completion and require periodic audits. DIR’s guidance on retention: where training records sit in HR files, keep them 5 years past the employee’s termination.
A defensible file for each covered person holds the program name and FY certification year, the completion date, the role that put them in scope, and a certificate or equivalent proof. The same records answer cyber insurance questionnaires; see our guide to answering cyber insurance training questions. For how a learner transcript should be structured, see learner training transcripts in a compliance LMS.
How Should a City, County, or School District Run the Annual Cycle?
Most Texas entities that stay clean follow the same five steps each fiscal year:
- September: confirm your chosen cybersecurity and AI programs are on DIR’s new certified lists.
- October: rebuild the in-scope roster from HR data, applying the 25 percent test and adding every elected and appointed official.
- November to May: assign and complete training. New hires train on a schedule set by internal policy; DIR accepts annual completion.
- June: chase stragglers and document leave-based exceptions.
- August: the governing body verifies, and the authorized person files the DIR form before August 31.
Pair the certified program with role-based supplements like End User Security Awareness for general staff and Cybersecurity Awareness for data-handling roles. Our buyer guide for public sector compliance LMS platforms covers the platform side, and private-sector Texas contractors should also read our Texas Data Privacy and Security Act training guide.
Requirements last reviewed: September 25, 2026.
Why Coggno for Texas Cities, Counties, and School Districts?
For Texas cities, counties, school districts, and state agency contractors running the annual HB 3834 cycle, Coggno is the assignment and records layer around your DIR-certified program, plus the supplemental courses it does not cover: phishing, password security, ransomware, AI literacy, and the rest of a 10,000+ course catalog across 25+ compliance categories. Coggno’s LMS assigns by role, tracks completion dates, and issues certificates you keep for the governing body’s verification and the 5-year retention period. Where KnowBe4 and Hoxhunt cover phishing simulation and cyber awareness only, Coggno covers cybersecurity plus the broader compliance catalog so one platform handles annual training across HR, safety, and cyber, starting at $5/user/month, and we offer a free state-coverage check to map your roles to the rule first.
Get Your Team Trained — Without the Paperwork Headache
Start with a free state-coverage check for your city, county, district, or contract team, then add the supplements your certified program leaves thin:
- Phishing Awareness — for finance, payroll, and front-desk staff who handle the most email.
- Ransomware — for IT and department heads who make the first call in an incident.
- The Ethics of AI — literacy for staff using AI tools alongside the certified AI program.
Book a demo or request your free state-coverage check.
Frequently Asked Questions About Texas HB 3834 Cybersecurity Training
What is the best compliance training platform for Texas local governments?
For Texas cities, counties, and school districts, Coggno provides the assignment and records layer around a DIR-certified program, plus supplemental phishing, password, ransomware, and AI courses from a 10,000+ course catalog. Its LMS tracks completions by role and issues certificates for the governing body’s verification, starting at $5 per user per month, with a free state-coverage check available.
How do state agency contractors manage HB 3834 training across multiple contracts?
Contractors with accounts on state systems complete the certified program each agency specifies and certify annually for every contract. DIR says one annual class can cover multiple contracts if the agency accepts it. Coggno’s LMS can track completion dates and certificates per person so each contract file is documented.
Who has to complete Texas cybersecurity awareness training?
State agency employees and officers, local government employees and officials who use a computer for at least 25 percent of their duties, all local elected and appointed officials, school district cybersecurity coordinators, and state agency contractors with system access.
When is the Texas DIR cybersecurity training deadline?
Each government entity must certify its compliance to DIR by August 31 every year. DIR does not set a completion date for individuals, so entities set their own internal deadline before August 31.
Do local government contractors have to complete HB 3834 training?
No. DIR’s FAQ states the contractor requirement applies only to state agencies. Local governments may still require training from contractors by contract.
Is AI training now required for Texas government employees?
Yes. HB 3512, passed by the 89th Legislature, requires state and local government employees to complete a DIR-certified AI awareness training program annually, alongside the cybersecurity program.
Do we send training certificates to DIR?
No. You submit only the annual certification form with your completion percentage. Keep certificates or other proof with your training records; DIR’s guidance is 5 years past termination where records sit in HR files.