NM Cyber Compliance

Cybersecurity Compliance Tracker

EO 2024-011 — NIST SP 800-53 Moderate-Impact Baseline

ALERT: Conduent Breach (Oct 2024 - Jan 2025)

25M+ records compromised including NM MMIS/Medicaid data. SafePay ransomware. Notifications ongoing through April 2026.

Annual Certification Deadline

November 1, 2026

227

days remaining

47%Compliant

Agencies Certified

5

of 20 total

Exempt w/ Plan

6

remediation plans filed

Non-Compliant

7

immediate action required

In Progress

2

assessment underway

Agency Compliance Status

Sorted by risk level (highest first)

20 of 20 agencies
AgencyStatusScoreRisk
Human Services DepartmentNon-Compliant
31%
High
Public Education DepartmentNon-Compliant
28%
High
Children, Youth and Families DeptNon-Compliant
35%
High
Corrections DepartmentNon-Compliant
38%
High
Workforce Solutions DepartmentNon-Compliant
41%
High
Indian Affairs DepartmentNon-Compliant
23%
High
Department of HealthExempt w/ Plan
58%
Medium
Environment DepartmentExempt w/ Plan
52%
Medium
Department of TransportationExempt w/ Plan
55%
Medium
General Services DepartmentExempt w/ Plan
62%
Medium
Motor Vehicle DivisionExempt w/ Plan
49%
Medium
Energy, Minerals and Natural ResourcesExempt w/ Plan
56%
Medium
New Mexico National GuardIn Progress
73%
Medium
Regulation and Licensing DepartmentNon-Compliant
43%
Medium
Department of Information TechnologyCertified
95%
Low
Taxation and Revenue DepartmentCertified
89%
Low
Department of Finance and AdministrationCertified
87%
Low
Economic Development DepartmentCertified
82%
Low
New Mexico State PoliceCertified
91%
Low
Department of Cultural AffairsIn Progress
67%
Low