How the FY2027 State Budget Reshapes Technology Procurement

July 13, 2026

Insights

By: Colton R. Overcash

public safety technology north carolina

After 1,008 days, North Carolina has a fully enacted state budget. Governor Josh Stein signed Senate Bill 257, the 2026 Appropriations Act, into law on July 7, 2026, as Session Law 2026-41.

The roughly $34.4 billion plan makes major investments in cybersecurity, data storage, elections systems, corrections technology, and identity management. It also shows how the state intends to govern those investments through staged funding, stronger statewide standards, and different oversight structures for selected agencies.

For technology vendors, the key questions are how much funding is available now, what remains dependent on future appropriations, and who controls procurement: the North Carolina Department of Information Technology (NCDIT) or individual agencies.

How the Budget Funds Multiyear Technology Projects

The Information Technology Reserve includes approximately $153 million in nonrecurring funding for FY2027, along with roughly $4.1 million associated with a federal infrastructure match. Those funds are transferred to agencies for projects authorized in the budget.

For many projects, the legislation identifies three separate figures: the maximum amount that may be spent from all sources, the amount allocated for the current fiscal year, and the amount expected to be needed in future years.

That structure allows the General Assembly to support large modernization programs while retaining authority over later phases. It also means that total project authorization should not be interpreted as money that is currently available.

Some projects are substantially or fully funded. The Department of Information Technology’s cybersecurity initiative has a total authorization of approximately $92.8 million and receives $42 million in FY2027, with earlier appropriations covering the remaining authorized amount. Data storage modernization receives $25 million, while health information exchange work receives approximately $3.8 million.

Other projects remain dependent on future appropriations. The State Board of Elections’ Statewide Elections Information Management System modernization is authorized at $60 million but receives $15 million for FY2027, leaving $45 million for later phases. The Department of Adult Correction’s Offender Population Unified System is authorized at $50 million, with $18 million provided now and $32 million remaining.

The North Carolina Community College System’s business systems modernization is the largest initiative listed, with total authorization exceeding $208 million and more than $100 million still expected in future allocations.

For vendors, this creates a distinction between project authorization and appropriation certainty. A contract associated with an early phase may provide a position in a multiyear program, but later work may still depend on future budgets, legislative priorities, project performance, and available revenue.

Identity Rules Will Affect What Agencies Buy

The budget also gives NCDIT a larger role in identity and access management across participating agencies.

NCDIT must establish statewide standards for systems requiring authentication, identity verification, or authorization. Those standards may address identity proofing, multifactor authentication, federation, privileged access, logging, auditability, and the ability to transition between vendors.

Participating agencies generally may not procure, implement, renew, substantially modify, or operate a covered system unless it complies with the standards or receives a written waiver from the state Chief Information Officer. Existing agreements may continue through their current terms, but agencies must coordinate future compliance with NCDIT.

The budget also directs the department to evaluate the state’s existing identity environment and, if necessary, conduct one or more competitive procurements for statewide identity services.

North Carolina already operates the North Carolina Identity Management service and requires many interagency and public-facing applications to use it. The budget strengthens that approach by connecting identity compliance more directly to procurement and system operation.

For vendors, identity architecture will therefore need to be addressed early in the sales and implementation process. Citizen portals, case-management platforms, benefits systems, licensing tools, grant systems, records platforms, and public-safety applications may all need to integrate with statewide identity services and meet common requirements for access control, logging, and auditability.

Cybersecurity Receives Recurring Funding

The budget provides NCDIT with $42 million in nonrecurring cybersecurity funding and an additional $18 million in recurring funding.

The recurring allocation is particularly significant because it treats cybersecurity as an ongoing operating requirement rather than a limited modernization project. It can support continuing needs such as monitoring, staffing, licensing, shared security services, threat response, and maintenance.

The budget also continues efforts to identify technology spending within individual agency budgets and directs NCDIT to examine duplicated expenditures across state government.

These provisions indicate that North Carolina intends to expand cybersecurity capabilities while also placing greater emphasis on enterprise coordination and cost control. Vendors may find opportunities in shared services and statewide platforms, but they should expect scrutiny of overlapping tools, recurring licensing costs, and agency-specific systems that duplicate capabilities available through NCDIT.

Public-Safety Agencies Retain Separate Technology Authority

The budget applies a different governance model to certain public-safety agencies.

The State Bureau of Investigation remains exempt from significant portions of NCDIT’s procurement and technology oversight. The Division of Emergency Management also continues operating its technology as a separate function within the Department of Public Safety through 2027.

These exceptions reflect the operational requirements of agencies responsible for criminal investigations, emergency response, forensic systems, sensitive information, and disaster operations. They also mean that vendors cannot assume that all state technology purchases follow the same approval structure.

The SBI receives approximately $8.5 million for technology needs that include headquarters hardware, network and cybersecurity improvements, and criminal information and identification systems. The budget also extends the tenure of the current SBI director, providing greater leadership continuity while limiting the current governor’s ability to make a near-term appointment.

Taken together, the provisions give SBI greater continuity and independence over its technology environment. That autonomy affects how projects are governed, which officials influence procurement, and how closely the agency must coordinate with centralized state technology authorities.

OPUS Expands the State’s Corrections Technology Investment

The Department of Adult Correction’s OPUS project is one of the budget’s larger agency-specific technology commitments.

Corrections systems support inmate records, facility operations, population management, security workflows, health coordination, transportation, programming, reporting, and reentry services. Modernizing those systems is therefore connected directly to institutional safety, operational continuity, and accountability.

The $50 million authorization includes $18 million in FY2027 funding and $32 million expected in future phases. The program is likely to require more than a core software platform. Additional needs may include data migration, systems integration, workflow redesign, training, testing, reporting, cybersecurity, and long-term maintenance.

Vendors evaluating the opportunity should distinguish between the currently funded phase and the broader authorized program. They should also account for the operational complexity of replacing systems used across correctional facilities and administrative functions.

Technology Oversight Will Vary by Agency

The budget does not establish a single model for state technology governance.

NCDIT receives greater authority where lawmakers are concerned about fragmented security, identity management, duplicated spending, and enterprise risk. Selected public-safety agencies retain independence where operational speed, sensitive information, or mission-specific requirements support a separate approach.

Certain Council of State offices, including the departments led by the Labor Commissioner, State Treasurer, and State Auditor, also receive authority to exempt themselves from aspects of normal state purchasing and contracting oversight.

As a result, procurement responsibility will vary by agency and office. A vendor may need NCDIT approval for one opportunity while working more directly with an independent agency or elected department on another. The relevant approval path may not be clear from the eventual solicitation alone.

What Technology Vendors Should Monitor

The clearest opportunities fall into three categories.

The first includes enterprise and shared services administered through NCDIT, such as cybersecurity, data storage, identity management, and health information exchange.

The second includes agency-specific public-safety systems, including SBI infrastructure, criminal information platforms, emergency management technology, and corrections modernization.

The third includes phased programs such as OPUS, SEIMS, and the community college business systems project. These initiatives have substantial authorizations and active funding, but later phases remain subject to future legislative decisions.

Companies pursuing this work should identify the responsible agency, the role of NCDIT, applicable identity and security standards, the amount currently appropriated, and the funding still expected in later years.

North Carolina’s FY2027 budget treats technology as essential infrastructure for public safety, cybersecurity, and citizen services. It also establishes different funding and oversight models depending on the project and agency involved.

The individual appropriations show what the state plans to modernize. The surrounding provisions show how those systems will be funded, governed, and procured.

Related Vertex Capabilities: