FY 26-27 Certification Standards

Texas DIR Cybersecurity Awareness Training

Built for Texas state and local government employees, officials, and contractors. Covers every mandatory topic in the DIR FY 26-27 Training Program Certification Standards under Texas Government Code Section 2063.102, plus foreign adversary interaction restrictions under Section 572.070.

At a Glance

  •  4 mandatory modules mapped 1:1 to the DIR standards, plus an optional IT roles track
  •  About 60 minutes to complete, including the final assessment
  •  Final assessment with 10 randomized questions, 80% to pass, retakes allowed
  •  Certificate of completion with QR-code verification
  •  Annual completion tracking by fiscal year

Statutory Basis

Tex. Gov't Code Sec. 2063.102

Sets the criteria for certifying a cybersecurity training program in Texas. Requires programs to teach the habits and procedures that protect information resources, and to teach how to detect, assess, report, and address threats - including foreign adversary influence operations.

Tex. Gov't Code Sec. 572.070

Prohibits state employees and volunteers from accepting transportation, lodging, gifts, or anything of value funded by or located in a foreign adversary country. Requires reporting interactions with foreign-adversary representatives to the Texas Ethics Commission within 30 days.

Course Modules

Required 14 min · 7 pages

Module 1: Principles and Safeguarding Information

Information security fundamentals, the CIA triad, types and forms of information, security controls, multi-factor authentication, secure storage and disposal, working remotely, and using generative AI safely.

DIR Standard: Mandatory Topic 1: Information security habits and procedures that protect information resources

Required 16 min · 8 pages

Module 2: Threats, Attacks, and Reporting

Common threats and threat actors, risk management, social engineering, phishing variants, quishing, business email compromise, ransomware and malware, and how to recognize and report suspicious activity.

DIR Standard: Mandatory Topic 2: Detecting, assessing, reporting, and addressing information security threats

Required 10 min · 5 pages

Module 3: Foreign Adversary Influence Operations

Definitions, threats from foreign adversaries and the United Front Work Department of the Chinese Communist Party, tactics used against Texas state and local government, authoritative resources, and how to report to the Texas Ethics Commission and law enforcement.

DIR Standard: Mandatory Topic 3: Foreign adversary influence operations (Tex. Gov. Code Sec. 2063.102)

Required 6 min · 3 pages

Module 4: Foreign Adversary Interaction Restrictions

Prohibited acceptance of transportation, lodging, gifts, and items of value from foreign adversary sources; the 30-day reporting requirement to the Texas Ethics Commission; and felony-level consequences for knowing violations.

DIR Standard: Mandatory Topic 4: Foreign adversary interaction restrictions (Tex. Gov. Code Sec. 572.070)

Optional 20 min · 6 pages

Module 5: IT Roles Track (Optional)

Additional content recommended by DIR for IT administrators and management: cyber hygiene, backups, Traffic Light Protocol, AI attacks and mitigation, third-party operational risk management with BCDR, and protection of privileged accounts.

DIR Standard: Strongly Recommended for IT Roles (Optional - not required for certification)

Ready to start?

Enrollment is $19.95 per employee for the FY 26-27 cycle, or $39.95 bundled with the DIR-certified AI Awareness course. Sign in (or create an account) and you will get immediate access to all four mandatory modules and the optional IT track.