2026 Top 10 Trends and Priorities for Government - State

Tailored Industry Research to Empower IT Leadership

Preview Another Industry

Industry-Centric Innovation and Transformation

View Our Research and Analyst Services
01

Fortify whole-of-state cyber resilience

The Challenge

Defend against a relentless threat landscape.

Cybersecurity held the top spot on NASCIO's State CIO priorities for 12 consecutive years, and although AI overtook it for 2026, the threat environment has only intensified. The 2024 Change Healthcare breach disrupted Medicaid payment systems nationwide and exposed how deeply third-party dependencies run through state operations. Ransomware, expanding cloud footprints, and remote work keep widening the attack surface around the tax, benefits, and licensing data that residents trust states to protect.

Why It Matters

A single breach can erode public trust that took decades to build.

State governments hold some of the most sensitive citizen records in the public sector, so a compromise carries regulatory, financial, and reputational damage well beyond the incident itself. With AI now ranked the number one state CIO priority, and with cybersecurity a close second, the agencies that pair modern controls with disciplined third-party risk management will keep services running and confidence intact ("State CIO Top Ten Policy and Technology Priorities for 2026," NASCIO, 2026).

The Solution

Build a risk-based security strategy.

Map threats, vulnerabilities, and consequences across agencies so control investments match actual risk rather than spreading evenly.

Make the risk posture visible to decision-makers.

Work with executives, IT leaders, and legislators to communicate the state's cyber posture and exposure in business terms, so funding follows the highest risks.

Operationalize zero trust and continuous monitoring.

Adopt zero-trust access, multifactor authentication, and continuous monitoring backed by regular training, so defenses keep pace with evolving threats.

Back to Top
02

Harness responsible AI across agencies

The Challenge

Meet rising expectations for digital services that must now be accessible to every resident by law.

Constituents increasingly expect to transact with government the way they do with banks and retailers, but states must deliver seamless, secure experiences while satisfying privacy, equity, and accessibility requirements. The 2024 Department of Justice rule under Title II of the Americans with Disabilities Act (ADA) makes web and mobile accessibility a legal obligation, raising the bar for every digital service a state offers.

Why It Matters

Accessible, trusted digital services are now both a citizen expectation and a compliance obligation.

Under the ADA Title II rule, state and local governments must bring web content and mobile apps to WCAG 2.1, Level AA, with compliance dates for larger entities extended to April 2027 ("Fact Sheet: New Rule on the Accessibility of Web Content," Department of Justice, 2024). States that design with accessibility and strong authentication in mind from the start will reduce legal exposure and better serve residents who depend on digital channels for benefits, licensing, and democratic participation.

The Solution

Prioritize high-value services with human-centered design.

Use personas and journey mapping to target the services residents use most, then build accessible, mobile-first interfaces around them.

Design for accessibility and security from the start.

Build to WCAG 2.1, Level AA, and embed authentication, privacy, and security by design so compliance is built-in rather than retrofitted.

Scale through a digital reference architecture.

Align data collection, sharing, and storage to a common digital government architecture so services scale across agencies without recreating risk.

Back to Top
03

Streamline resident-first digital services

The Challenge

Capture AI's operational value while meeting governance demands that are now written into law.

AI has moved from pilots into production across state agencies, powering eligibility automation, document processing, fraud detection, and constituent chatbots. At the same time, more than 20 states have enacted or advanced AI governance legislation, so the question is no longer whether to deploy AI but how to govern it on a foundation of clean, well-managed data.

Why It Matters

AI is now the defining priority for state technology leaders.

NASCIO ranked AI the number one state CIO priority for 2026, the first time in over a decade that cybersecurity did not hold the top spot ("State CIO Top Ten Policy and Technology Priorities for 2026," NASCIO, 2026). States that invest early in responsible AI guardrails, data governance, and workforce reskilling will scale automation with public trust intact, while those that skip governance risk bias, liability, and stalled deployments.

The Solution

Set an AI strategy and responsible-use policy.

Fold AI into the broader IT roadmap and adopt responsible AI principles that define acceptable use, transparency, and accountability for both traditional and generative AI.

Prioritize high-value, low-risk use cases.

Use capability maps to target uses such as service automation, fraud detection, and document processing, starting where value is clear and risk is manageable.

Ground AI in data and workforce readiness.

Ensure tools draw on reliable, governed data and build reskilling programs for staff whose roles shift as automation scales.

Back to Top
04

Retire legacy, accelerate modernization

The Challenge

Replace aging systems that drain budgets and block both service delivery and AI adoption.

Legacy platforms are expensive to run, hard to secure, and rarely produce the clean, machine-readable data that modern analytics and AI require. The Government Accountability Office (GAO) found that the federal government spends over $100 billion a year on IT, roughly 80% of it just operating and maintaining existing systems, a pattern mirrored across state government ("Information Technology: Agencies Need to Plan for Modernizing," GAO, 2025).

Why It Matters

Modernization is the prerequisite for nearly every other priority.

Of the ten critical legacy systems GAO flagged in 2019, only three were modernized by early 2025, and most still ran on outdated languages with known security vulnerabilities (GAO, 2025). States that tie modernization to clear business outcomes, rather than treating it as a technical refresh, free up budget and unlock the data foundation that AI and digital services depend on.

The Solution

Anchor modernization in business value.

Prioritize applications against digital business goals so investment targets the services and capabilities that matter most to residents and staff.

Match the approach to risk tolerance.

Assess technical complexity and change tolerance, then choose the right path for each system, whether rehosting, refactoring, or replacing.

Sequence the work with a clear roadmap.

Lay out milestones, dependencies, and disposition plans for retired systems so modernization proceeds predictably and avoids cost overruns.

Back to Top
05

Win the public-sector tech talent race

The Challenge

Close a widening public sector talent gap that now includes scarce AI skills.

Traditional draws like pensions and job security carry less weight with today's candidates, and highly structured, seniority-based civil service models slow the rise of skilled new hires. As agencies deploy AI, they also need people who can govern models, validate outputs, and manage data pipelines, skills that are expensive and in short supply.

Why It Matters

Workforce capacity sets the ceiling on everything else a state CIO wants to accomplish.

NASCIO's 2025 State CIO Survey reports median CIO tenure of just over two years and names change leadership the most important CIO trait, underscoring how much delivery now depends on people, not just technology ("The 2025 State CIO Survey: Leading Change Through Uncertain Times," NASCIO, 2025). States that offer flexible work, meaningful projects, and accelerated paths for high performers will out-compete neighbors for the talent that modernization and AI demand.

The Solution

Track workforce trends and capability gaps.

Monitor IT labor trends and map them to the capabilities the agency needs, so gaps are addressed before they become bottlenecks.

Invest in growth and meaningful work.

Offer continuous training, leadership development, and challenging projects that keep skilled professionals engaged and progressing.

Modernize hiring and advancement.

Adopt flexible and remote work, broaden talent pools, and promote on skills and impact rather than tenure alone.

Back to Top
06

Unlock data as a strategic asset

The Challenge

Turn fragmented data into a governed asset that powers analytics, AI, and policy.

Poorly managed data leads to weak decisions, missed service opportunities, and avoidable security risk, and it is the single biggest barrier to reliable AI because models are only as good as the data behind them. Federal interoperability requirements tied to programs like SNAP and Medicaid add further urgency to clean, shareable, cross-agency data.

Why It Matters

Data management has been a top-ten state CIO priority every year since 2016.

Strong data governance lets states move from reactive reporting to evidence-based policy, while weak governance quietly undermines AI, analytics, and public trust. The states that treat data as shared infrastructure will get the most from every other technology investment. ("The 2025 State CIO Survey: Leading Change Through Uncertain Times," NASCIO, 2025).

The Solution

Align data work with agency strategy.

Tie data management plans to agency missions and strategic goals so data initiatives support real outcomes rather than standalone projects.

Govern data as a shared asset.

Build a collaborative, scalable plan across IT and the business, with clear governance, ownership, and quality standards.

Close gaps with a data roadmap.

Assess current data services, identify gaps, and sequence corrective actions that improve integration, literacy, and analytics.

Back to Top
07

Secure trusted, seamless digital identity

The Challenge

Manage rising complexity in identity as mobile credentials and modern authentication go mainstream.

Identity and security are now inseparable, requiring continuous control over access, transactions, and fraud across cloud and AI-driven services. Mobile driver's licenses (mDLs) are bercoming more common under American Association of Motor Vehicle Administrators (AAMVA) guidance, passkey authentication is replacing passwords, and REAL ID continues to drive state IT investment.

Why It Matters

Digital identity is becoming core public infrastructure.

By mid-2025, around 18 states were issuing standards-compliant mDLs and more than 250 airports accepted them at TSA checkpoints, signaling that mobile credentials have moved from pilot to mainstream ("Adoption Now and Ahead: mDL Day ‘Voices of the Future’ panel," OpenID, 2025). States that adopt interoperable standards such as ISO/IEC 18013-5 and AAMVA's Digital Trust Service will give residents secure, portable identity while reducing fraud and friction.

The Solution

Centralize identity with role-based access.

Stand up a centralized identity and access management (IAM) capability with a role-based access control (RBAC) model to regain control and simplify auditing.

Adopt interoperable mDL and authentication standards.

Align mDL issuance and verification to ISO/IEC 18013-5 and AAMVA's Digital Trust Service, and move toward passkeys and multifactor authentication.

Procure and integrate deliberately.

Select IAM vendors using clear requirements, minimize entitlement sprawl, and integrate cleanly across cloud services.

Back to Top
08

Rationalize the application portfolio

The Challenge

Bring discipline to sprawling application portfolios before aging systems fail.

Many states still rely on complex, unstable legacy applications that are increasingly exposed to outages and cyberattacks, yet lack a clear, ongoing process to rationalize them. GAO found that most of the federal legacy systems most in need of modernization still run on outdated languages and carry known security vulnerabilities, a risk profile common in state portfolios as well ("Information Technology: Agencies Need to Plan for Modernizing," GAO, 2025).

Why It Matters

Continuous portfolio management is what keeps modernization from becoming a one-time event.

With roughly 80% of IT budgets consumed by operations and maintenance, every unmanaged legacy application crowds out investment in new services (GAO, 2025). States that manage applications by business capability, not just technical health, can retire redundancy, target spend, and make a credible case for modernization funding.

The Solution

Rationalize the portfolio continuously.

Make portfolio review an ongoing discipline, shifting the lens from technical issues to the value applications deliver to programs and services.

Empower portfolio leads to act.

Give application owners the data and authority to flag issues early and make the case for investment to decision-makers.

View applications by business capability.

Organize the portfolio around programs and services first, so modernization decisions align with mission priorities.

Back to Top
09

Scale Agile, product-centric delivery

The Challenge

Make Agile and product-centric delivery work within public sector constraints.

Most state organizations struggle to adopt Agile, DevOps, and product-centric delivery because textbook practice collides with procurement rules, annual funding, and federated governance. Without an approach tailored to government, transformations stall and revert to slow, document-heavy delivery.

Why It Matters

Adaptive delivery is how states ship digital services before requirements go stale.

In its January 2025 IT high-risk update, GAO reported that federal IT projects too often run over budget, slip schedules, and deliver far fewer improvements than promised, with 463 of the 1,881 IT-management recommendations it has made since 2010 still unimplemented ("High-Risk Series: Critical Actions Needed," GAO, 2025). States that build Agile guardrails fit for public sector funding and oversight will deliver working software faster and adjust as needs change.

The Solution

Coach teams with real-time guidance.

Pair teams with experienced Agile mentors who can troubleshoot delivery challenges in the moment and tailor practices to a government context.

Assess and strengthen delivery practices.

Evaluate Agile, DevOps, and product skills, then set guardrails grounded in GAO Agile best practices for adoption, execution, and control.

Fit Agile to public sector rules.

Adapt Agile to procurement, funding, and project management standards so iterative delivery works within, not against, government constraints.

Back to Top
10

Reinvent the CIO as enterprise orchestrator

The Challenge

Lead across a fragmented technology landscape as the CIO's role expands and splinters.

State service delivery spans many agencies, systems, and limited budgets, creating constant coordination demands. The role itself is changing fast as states add Chief Data Officers and Chief AI Officers, requiring the CIO to redefine scope and lead through influence across new peers.

Why It Matters

The modern state CIO succeeds as an orchestrator, not just an operator.

NASCIO's 2025 State CIO Survey named change leadership the single most important CIO trait, ahead of communication and strategy, reflecting how much the job now centers on leading transformation ("The 2025 State CIO Survey: Leading Change Through Uncertain Times," NASCIO, 2025). CIOs who broker services across vendors, shared services, and agency partners will be most effective in a federated environment where no single team controls the whole stack.

The Solution

Align IT and manage the vendor ecosystem.

Keep IT initiatives tied to agency objectives and govern vendor relationships for compliance, performance, and value.

Broker collaboration across agencies.

Connect and integrate services from multiple providers and agencies into coherent solutions that promote interoperability.

Balance risk management with innovation.

Manage cyber and privacy risk while adopting emerging technologies, so the CIO drives both stability and progress.

Back to Top

Comprehensive Government - State Industry Coverage

Filters

Testimonials

“Info-Tech demonstrated the difference between a vendor and a partner. Info-Tech brought in the right resources, experts in the field, and our own Account Executive and Executive Partner, who were there for us to deliver on any request, as extensions of our own team.”

Timothy Galluzi, Executive Director & State Chief Information Officer, State of Nevada

View Full Case Study

"In just five years, we flipped our previous ratio of digital to paper processes on its head: more than 80% of journeys are now completed online and only 20% on paper.”

Dave King, CIO, Arizona State Retirement System

View Full Case Study
More Case Studies

Our People

Tom Hawley headshot

Tom Hawley

Managing Partner, US State & Local Government

View Full Bio
Mike Higginbotham headshot

Mike Higginbotham

Senior Executive Counselor

View Full Bio
Hillory Courtney headshot

Hillory Courtney

Executive Counselor

View Full Bio
Patrick Dennis headshot

Patrick Dennis

Executive Counselor

View Full Bio
Eric Frohlick headshot

Eric Frohlick

Executive Counselor

View Full Bio
Alia Mendonsa headshot

Alia Mendonsa

Executive Counselor

View Full Bio
Titus Moore headshot

Titus Moore

Executive Counselor

View Full Bio
Katy Piatanesi headshot

Katy Piatanesi

Executive Counselor

View Full Bio