ANNUAL
A certification, every year
State law requires covered agencies to certify program compliance to OIS annually, with a plan of action and milestones. It's a recurring obligation, not a one-time project.
SAM-5300 and the SIMM 5300 series are the rules every California state entity must certify to the Office of Information Security each year — and the controls flow down to the vendors who serve them. It's NIST 800-53, tailored for California. We build the program and the annual certification, on either side of the contract.
Book a SAM-5300 Strategy Call →// WHY SAM-5300, WHY NOW
ANNUAL
State law requires covered agencies to certify program compliance to OIS annually, with a plan of action and milestones. It's a recurring obligation, not a one-time project.
800-53
SIMM 5300 is built on the NIST 800-53 control catalog with California-specific parameters — and is now explicitly aligned to NIST CSF 2.0, including its Govern function.
FLOWS DOWN
Serve a state agency and the requirements follow the data to you — which is why the confidential control set is shared with vendors under NDA during procurement.
// "FEDERAL NIST" ISN'T CALIFORNIA
NIST 800-53 is the foundation, but California layers its own requirements on top: the confidential SIMM 5300-A tailoring, the public Foundational Framework, the SIMM 5300-C maturity assessment, the risk register and POA&M, and an annual certification to OIS backed by statute. A strong 800-53 program gets you most of the substance — but "fine for California" means mapping it into the SIMM structure and producing the evidence the OIS certification depends on. That last mile is where state contracts are won or lost.
// THE FOUR IMPLEMENTATION LAYERS
SAM policy flows down through the SIMM 5300 series into controls and standards — but everything converges on one recurring obligation: the annual program certification to the Office of Information Security.
Where it all comes due: the public Foundational Framework (SIMM 5300-B) sets the security objectives, and the SIMM 5330-B annual certification is the agency-head attestation to OIS — backed by statute, with a plan of action and milestones — that the program meets them. The three layers below are what you build and tailor; this is what you certify, every year.
// LAYER · SAM CH. 5300
SAM Policy Authority
The executive-branch policy setting security requirements for every CA state entity. The "why."
// LAYER · SIMM 5300-A
NIST 800-53 + CA Tailoring
The confidential California control set on the NIST 800-53 catalog. Vendor access under NDA in procurement.
// LAYER · SIMM 5340–5360
Operational Standards
The continually updated standards portfolio — incident response, zero trust, monitoring, and more.
Anchored in Gov. Code 11545–11549.4 · the OIS is the regulator.
// THE PATH
From naming your security leadership to certifying the program — then doing it again next year. The amber stages are where the Office of Information Security is the receiving party: the designation letter and the annual certification.
Designate
SIMM 5330-A Letter
WK 1–3
Framework
Foundational Framework
MO 1–2
Controls
800-53 + CA Tailoring
MO 2–6
Maturity
SIMM 5300-C Assessment
MO 6–8
Certify
SIMM 5330-B to OIS
ANNUAL
Continuous
Standards + Contractors
ONGOING
Amber stages are where the Office of Information Security receives your submission — the SIMM 5330-A designation letter naming your CISO/ISO, and the SIMM 5330-B annual certification. Between them, the program is built, tailored, and assessed for maturity.
// IS THIS YOU?
// 01 // STATE ENTITY
You're an agency, department, board, or commission with a 5330-B certification due to OIS — and a maturity gap between where your program is and what you'll attest to.
// 02 // STATE VENDOR
You hold or want California state contracts. The controls flow down to you, and proving you can meet SIMM 5300 is fast becoming table stakes to compete.
// 03 // NIST, NOT CALIFORNIA
You run NIST 800-53 or CSF but haven't mapped into the SIMM structure, run the 5300-C maturity assessment, or built the evidence the OIS certification needs.
// WHAT WE DO
// Phase 01 · Establish
We confirm applicability, stand up the SIMM 5330-A designation, and apply the Foundational Framework — including a fractional security-leadership role where you don't have the in-house bench.
// Phase 02 · Build
We implement the NIST 800-53 controls with California's SIMM 5300-A parameters, build the risk register and POA&M, and run the SIMM 5300-C maturity assessment that drives the certification.
// Phase 03 · Certify
We produce the evidence behind the SIMM 5330-B certification to OIS, then keep the program current against the evolving standards portfolio — so next year's certification is maintenance, not a rebuild.
// THE CERTIFICATION COMES DUE EVERY YEAR
// FREQUENTLY ASKED
They're two layers of the same requirement. SAM Chapter 5300 is the policy: the executive-branch State Administrative Manual section establishing the information security and privacy requirements every California state entity must meet. The SIMM 5300 series is the implementation — the Statewide Information Management Manual, owned by the California Department of Technology's Office of Information Security (OIS), translating that policy into specific controls based on NIST 800-53 with California-specific parameters.
In practice you comply with SAM by implementing SIMM. The series includes a confidential California control set (SIMM 5300-A, available to designated personnel and to vendors under NDA in procurement), a public Foundational Framework (SIMM 5300-B), maturity assessments (SIMM 5300-C), and the reporting and certification instruments in the SIMM 5330 series. The whole structure is anchored in Government Code sections 11545 through 11549.4.
If you provide IT or data services to California state agencies, the requirements effectively flow down to you, even though the certification obligation sits with the agency. The framework binds the state entity, but agencies are responsible for the security of the data they entrust to vendors, so procurement and contract terms push the relevant controls onto contractors that handle state information. That's also why the confidential control set, SIMM 5300-A, is shared with vendors under NDA during procurement — the state expects you to meet it.
For a vendor, demonstrating you can operate to the SIMM 5300 baseline is increasingly a prerequisite to winning and keeping state work, and a real differentiator on vehicles like CMAS. WatchUr6 holds CMAS #3-25-06-1018 and has prior performance with the State of California and the California DMV, so we help both state entities and their contractors meet the standard from either side.
SIMM 5330-B is the Information Security and Privacy Program Compliance Certification each California state entity submits to OIS every year. Government Code section 11549.3 requires covered agencies to certify annually that they comply with adopted state security policies, standards, and procedures — and that certification must include a plan of action and milestones for any gaps. It's submitted on the schedule in SIMM 5330-C, due to OIS by the last business day of the entity's scheduled reporting month.
It's paired with the SIMM 5330-A designation letter, through which the entity head formally names the agency's CIO, Information Security Officer, Technology Recovery Coordinator, and Privacy Officer to OIS, with updates required when those roles change. Because it's signed at the agency-head level and backed by statute, it isn't a formality — it's a personal attestation of the program's state, which is exactly why the maturity assessment and evidence behind it matter.
SAM-5300 is built on NIST. The underlying control catalog for SIMM 5300 is NIST 800-53 (with its 800-53B baselines), which California tailors with state-specific parameters in the confidential SIMM 5300-A, referencing FIPS 199 and FIPS 200 for categorization. California has also explicitly aligned its program with NIST CSF 2.0, including the Govern function that sits above identify, protect, detect, respond, and recover.
So an organization with a mature 800-53 or CSF program already shares most of the substance — the work is usually less about building controls from scratch and more about tailoring to California's parameters, mapping into the SIMM structure, running the SIMM 5300-C maturity assessment, and producing the evidence the annual OIS certification depends on. One caution: the SIMM series is updated frequently, with new and revised standards issued by CDT on an ongoing basis, so staying compliant means keeping pace with the current standards rather than treating the framework as static.
// THE NEXT MOVE
Book a 30-minute SAM-5300 strategy call with a WatchUr6 advisor. Bring whether you're a state entity or a vendor serving one, your current NIST footing, and your reporting month if you know it. You'll walk away with a clear read on your SIMM 5300 gaps, a path to the annual certification, and an honest assessment of your maturity — whether you hire us or not.
Book a SAM-5300 Strategy Call →CA STATE & DMV PAST PERFORMANCE · CMAS #3-25-06-1018 · SDVOSB · DVBE · VETERAN-LED