Most Texas appraisal districts handle their annual cybersecurity training compliance assuming a 25% computer-use threshold determines who needs the training. That threshold is real, but it belongs to state agencies under §2054.5192. CADs fall under §2054.5191, which covers a wider group of people, and that difference is the most common audit miss we see in the field.
If you're a Chief Appraiser or CAD Director reading this between ARB hearings and a CAMA vendor call, the short version is this: the August 31 compliance deadline is real, the training itself is offered free at freecybersecurityawarenesstraining.com, and the work is in the documentation and tracking around it. What follows is who is covered by §2054.5191 (more people than most CADs assume), what missing the deadline costs you in practice, what to do if this year's August 31 has already passed, and how to automate the compliance cycle so your office isn't the one chasing certificates in late August.
Understanding Texas Gov Code 2054.5191
HB 3834, passed in 2019, was the Legislature's answer to a run of ransomware attacks on local government IT in Texas. It added two parallel sections to the Government Code (§2054.5191 for local government entities, CADs included, and §2054.5192 for state agencies), both requiring annual cybersecurity awareness training from a state-certified provider.
Under §2054.5191, the training has to be completed annually and the program has to come from a state-certified training provider. The reasoning is simple. Most local government breaches in Texas have started with one staff member clicking the wrong link. Training won't catch every phishing or social engineering attempt, but it measurably cuts how often they succeed.
Who needs the training under §2054.5191: This is where most CADs get the rule slightly wrong. §2054.5192 (state agencies) and §2054.5191 (local government) read almost the same but cover different staff. For local government, which is what CADs fall under, the requirement applies to:
- CAD employees with access to district systems: Yes. The local government rule doesn't use the 25% computer-use threshold that applies to state agencies under §2054.5192. If a staff member has access to the CAD's computer systems or databases at all (administrators, appraisers, customer service, IT), they're in scope. That's a bigger group than many CADs realize, and it's the most common audit miss.
- Board of Directors: Yes. Elected or appointed officials who have access to the district's information resources are required to complete the training. Whether they log in regularly or not, if they have credentials, they're in scope.
- Field staff with no system access: Possibly exempt, but the exception is narrow. If a field appraiser genuinely has no access to CAD systems (no login, no shared file access, no district email account), they're outside the requirement. In practice, most field staff have at least an email account, which puts them back in scope. The cleaner approach for most districts is to train everyone. The cost difference is small and it removes the gray area an auditor would ask about.
The real cost of missing the August 31 deadline
Districts certify compliance to the state by August 31 each year. Missing the certification has both compliance and audit consequences. Non-certification can trigger administrative review from the state and can affect grant eligibility: the cybersecurity-related grant programs CADs sometimes draw from carry compliance prerequisites tied to §2054.5191 certification. Trading grant access for a forgotten training video is the kind of trade no Chief Appraiser wants to explain to the board.
Beyond compliance, there's the operational side. CADs hold taxpayer PII, exemption records, and county financial data, exactly the kind of records ransomware groups have learned to target in local government. A CAD going offline disrupts more than your office. It slows certification of the tax rolls that fund the whole county.
This isn't hypothetical for Texas CADs. Three districts have been hit between 2022 and 2024: Dallas CAD (Royal ransomware, with the district paying about $170K), Travis CAD (also Royal), and Tarrant Appraisal District (a $700K demand TAD refused to pay). Recovery costs ran well into six figures in each case, on top of weeks of operational disruption. Awareness training won't guarantee you avoid any of that, but it's the cheapest thing you can do about the most common way in: an employee clicking the wrong link.
If your district already missed this year's certification
It happens, usually in a year where the Chief Appraiser changed or the person who kept the tracker left in July. There is no formal cure period written into §2054.5191, so the practical answer is to close the gap now rather than wait for the next cycle.
- Run the training now, not next spring. Enroll every covered person, board members included, and get completions logged with real dates. A completion dated in October is a far better record than a blank one.
- Keep the dated certificates. Completion dates are what an auditor or a grant administrator asks for. Save the individual certificates, not just a spreadsheet row.
- Submit the certification as soon as the completions are in. Do not hold it until next August. A late record with dates on it beats a missing one.
- Take it to the board and minute it. A documented decision to remediate reads very differently from silence when the gap surfaces later.
- Fix the process, not just the year. The gap almost always traces back to manual tracking, which is the next section.
If a cybersecurity grant application is in flight, check that program's compliance prerequisites before you submit. Some tie eligibility to §2054.5191 certification, and a late certification on file is a stronger position than none at all.
The hidden time-tax of manual tracking
Knowing the rule is the easy part. Enforcing it across staff, board members, and seasonal new hires is where the time goes, and most CADs are absorbing 20-40 hours of leadership and HR time on it every year. Manual compliance usually looks like this:
- Verify the training program is on the current state-certified list. The list changes year to year, so last year's choice isn't automatically valid this year.
- Announce the requirement to staff and board members and push them toward a deadline most won't hit on the first reminder.
- Run a tracker (usually a spreadsheet) logging who has completed and who hasn't.
- Follow up with the last 20% of staff who didn't act on the first three emails. This part usually happens in the final two weeks of August.
- Collect individual completion certificates, organize them as supporting evidence, and submit the compliance attestation to the state.
None of this is a good use of a Chief Appraiser's time, and the workload doesn't shrink in a busy year. It just gets crammed into fewer days.
Automating the compliance cycle
The full compliance cycle (training delivery, enrollment, reminders, tracking, certificate collection, attestation) is something a managed IT partner that works with CADs can handle as part of standard service. Here's what the automated version looks like in practice:
- Always-current state-certified curriculum. The training platform stays on the state-certified list, and the content gets updated as new threat patterns show up: phishing, credential theft, social engineering, business email compromise.
- Automated enrollment and reminders. Staff and board members are enrolled by the platform, and reminder emails go out on a schedule the system manages. Your office isn't the one doing the chasing.
- New hires assigned automatically. When a new appraiser or admin starts, the training assignment is part of IT onboarding, so HR doesn't have a separate step to remember.
- Phishing simulations between training cycles. Awareness training once a year is the floor. Periodic simulated phishing emails through the year show you which staff might need a refresher before a real attacker tests them.
- Attestation-ready reporting. On August 31, you have a single report showing completion status for every covered employee and board member, ready to submit to the state.
Beyond training: securing the whole district
Training is one piece of the security picture. A staff member who recognizes a phishing email and doesn't click is your last layer of defense. The earlier layers (the ones that keep the phishing email from landing in the inbox, or from succeeding if it does) matter at least as much.
For CADs that's a defense-in-depth setup: 24/7 endpoint detection and response on workstations, modern email security that filters phishing before it lands, multi-factor authentication enforced across CAMA and Microsoft 365, and immutable cloud backups of CAMA databases and GIS files. When a staff member does click something they shouldn't have (it'll happen eventually), the goal is for the next layer to catch it before it spreads across the network.
The IT side also needs to own CAMA performance instead of bouncing the ticket back to TrueAutomation, Tyler, or Spatialest when something's slow. That coordination is half the job for a CAD's IT partner. We hold a 15-minute response window for appraiser-blocking issues during business hours.
Let's make the next cycle easy
If the compliance spreadsheet is a recurring summer headache, you can hand this part of the work off. safemode IT handles cybersecurity training compliance (state-certified curriculum, enrollment, reminders, completion tracking, and the August 31 attestation report) as part of our managed IT service for Texas appraisal districts.
If you want to talk through how this would work for your district, reach out to safemode IT. We work with Texas CADs specifically, so the conversation doesn't start with explaining what a CAMA system is.
Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.
Book a 10-Minute Discovery Call →Frequently asked questions
Does the 25% computer-use threshold apply to Texas appraisal districts?
No. That threshold comes from §2054.5192, which covers state agencies. Appraisal districts are local government entities under §2054.5191, and that section applies to anyone with access to the district's computer systems or databases, whether or not they spend 25% of their time on a computer.
Do CAD board members have to complete the cybersecurity training?
Yes. Elected or appointed officials with access to the district's information resources are covered. If a board member has credentials, they are in scope even if they rarely log in.
When is the Texas CAD cybersecurity training deadline?
Districts certify compliance to the state by August 31 each year. Missing the certification can trigger administrative review and can affect eligibility for cybersecurity-related grant programs that require §2054.5191 compliance.
Is the required cybersecurity awareness training free?
Yes. The training itself is offered free at freecybersecurityawarenesstraining.com. The cost to the district is the time it takes to verify the provider is on the current state-certified list, track completions, collect certificates, and submit the attestation.
What if our district already missed the August 31 deadline?
Close the gap now rather than waiting for the next cycle. Enroll everyone who is covered, board members included, keep the dated completion certificates, and submit the certification as soon as the completions are in. There is no formal cure period in §2054.5191, so a late certification with real dates on it is a much stronger position than a missing one. If a cybersecurity grant application is in flight, check that program's compliance prerequisites before submitting.
Can safemode IT handle our CAD's cybersecurity training compliance?
Yes. We handle the state-certified curriculum, enrollment, reminders, completion tracking, and the August 31 attestation report as part of our managed IT services for Texas appraisal districts. Reach out and we can walk through how it would work for your district.
Last updated: September 18, 2026


