WATCHUR6 // CALIFORNIA SAM-5300 // AUDIT READINESS

California's security standard.
And every state contract inherits it.

SAM-5300 and the SIMM 5300 series are the rules every California state entity must certify to the Office of Information Security each year — and the controls flow down to the vendors who serve them. It's NIST 800-53, tailored for California. We build the program and the annual certification, on either side of the contract.

Book a SAM-5300 Strategy Call
SAM CH. 5300 + SIMM 5300 NIST 800-53, CA-TAILORED ANNUAL OIS CERTIFICATION CA PAST PERFORMANCE

// WHY SAM-5300, WHY NOW

In California state work, the standard isn't optional. It's certified every year.

ANNUAL

A certification, every year

State law requires covered agencies to certify program compliance to OIS annually, with a plan of action and milestones. It's a recurring obligation, not a one-time project.

800-53

NIST, tailored for California

SIMM 5300 is built on the NIST 800-53 control catalog with California-specific parameters — and is now explicitly aligned to NIST CSF 2.0, including its Govern function.

FLOWS DOWN

Contractors inherit it

Serve a state agency and the requirements follow the data to you — which is why the confidential control set is shared with vendors under NDA during procurement.

// "FEDERAL NIST" ISN'T CALIFORNIA

We already do NIST 800-53, so we're fine for California.
SAM-5300 is 800-53 plus California's parameters, structure, and annual certification.

NIST 800-53 is the foundation, but California layers its own requirements on top: the confidential SIMM 5300-A tailoring, the public Foundational Framework, the SIMM 5300-C maturity assessment, the risk register and POA&M, and an annual certification to OIS backed by statute. A strong 800-53 program gets you most of the substance — but "fine for California" means mapping it into the SIMM structure and producing the evidence the OIS certification depends on. That last mile is where state contracts are won or lost.

// THE FOUR IMPLEMENTATION LAYERS

Policy. Controls. Standards. One annual certification it all funnels into.

SAM policy flows down through the SIMM 5300 series into controls and standards — but everything converges on one recurring obligation: the annual program certification to the Office of Information Security.

Foundational Framework + Annual Certification SIMM 5300-B + 5330-B · the structural center

Where it all comes due: the public Foundational Framework (SIMM 5300-B) sets the security objectives, and the SIMM 5330-B annual certification is the agency-head attestation to OIS — backed by statute, with a plan of action and milestones — that the program meets them. The three layers below are what you build and tailor; this is what you certify, every year.

// LAYER · SAM CH. 5300

SAM Policy Authority

The executive-branch policy setting security requirements for every CA state entity. The "why."

// LAYER · SIMM 5300-A

NIST 800-53 + CA Tailoring

The confidential California control set on the NIST 800-53 catalog. Vendor access under NDA in procurement.

// LAYER · SIMM 5340–5360

Operational Standards

The continually updated standards portfolio — incident response, zero trust, monitoring, and more.

Anchored in Gov. Code 11545–11549.4 · the OIS is the regulator.

SAM 5300 · POLICY · SIMM 5300 · IMPLEMENTATION NIST 800-53 · CSF 2.0 GOVERN ALIGNED SIMM 5330-B · CERTIFY ANNUALLY TO OIS

// THE PATH

Six stages, an annual cycle.

From naming your security leadership to certifying the program — then doing it again next year. The amber stages are where the Office of Information Security is the receiving party: the designation letter and the annual certification.

Designate

SIMM 5330-A Letter

WK 1–3

Framework

Foundational Framework

MO 1–2

Controls

800-53 + CA Tailoring

MO 2–6

Maturity

SIMM 5300-C Assessment

MO 6–8

Certify

SIMM 5330-B to OIS

ANNUAL

Continuous

Standards + Contractors

ONGOING

Amber stages are where the Office of Information Security receives your submission — the SIMM 5330-A designation letter naming your CISO/ISO, and the SIMM 5330-B annual certification. Between them, the program is built, tailored, and assessed for maturity.

// IS THIS YOU?

Three signs SAM-5300 is on your desk.

// 01 // STATE ENTITY

You're a California state entity

You're an agency, department, board, or commission with a 5330-B certification due to OIS — and a maturity gap between where your program is and what you'll attest to.

// 02 // STATE VENDOR

You serve state agencies

You hold or want California state contracts. The controls flow down to you, and proving you can meet SIMM 5300 is fast becoming table stakes to compete.

// 03 // NIST, NOT CALIFORNIA

You have NIST but not the CA layer

You run NIST 800-53 or CSF but haven't mapped into the SIMM structure, run the 5300-C maturity assessment, or built the evidence the OIS certification needs.

// WHAT WE DO

The designation, the program, and the annual certification.

// Phase 01 · Establish

Designation & Framework

We confirm applicability, stand up the SIMM 5330-A designation, and apply the Foundational Framework — including a fractional security-leadership role where you don't have the in-house bench.

  • Applicability and scope analysis
  • SIMM 5330-A designation (CIO / ISO / TRC / Privacy)
  • Foundational Framework (SIMM 5300-B) application

// Phase 02 · Build

Controls, Tailoring & Maturity

We implement the NIST 800-53 controls with California's SIMM 5300-A parameters, build the risk register and POA&M, and run the SIMM 5300-C maturity assessment that drives the certification.

  • NIST 800-53 controls + SIMM 5300-A CA tailoring
  • Risk register and POA&M (SIMM 5305)
  • SIMM 5300-C maturity assessment

// Phase 03 · Certify

Certification & Continuous Compliance

We produce the evidence behind the SIMM 5330-B certification to OIS, then keep the program current against the evolving standards portfolio — so next year's certification is maintenance, not a rebuild.

  • SIMM 5330-B annual certification readiness
  • Operational standards currency (IR, zero trust, monitoring)
  • Contractor inheritance and procurement support

// THE CERTIFICATION COMES DUE EVERY YEAR

An agency head signs the SIMM 5330-B. The evidence behind it had better be real.

Book a SAM-5300 Strategy Call

// FREQUENTLY ASKED

The SAM-5300 questions teams keep asking.

What's the difference between SAM 5300 and SIMM 5300?

They're two layers of the same requirement. SAM Chapter 5300 is the policy: the executive-branch State Administrative Manual section establishing the information security and privacy requirements every California state entity must meet. The SIMM 5300 series is the implementation — the Statewide Information Management Manual, owned by the California Department of Technology's Office of Information Security (OIS), translating that policy into specific controls based on NIST 800-53 with California-specific parameters.

In practice you comply with SAM by implementing SIMM. The series includes a confidential California control set (SIMM 5300-A, available to designated personnel and to vendors under NDA in procurement), a public Foundational Framework (SIMM 5300-B), maturity assessments (SIMM 5300-C), and the reporting and certification instruments in the SIMM 5330 series. The whole structure is anchored in Government Code sections 11545 through 11549.4.

We're a contractor, not a state agency. Does SAM-5300 apply to us?

If you provide IT or data services to California state agencies, the requirements effectively flow down to you, even though the certification obligation sits with the agency. The framework binds the state entity, but agencies are responsible for the security of the data they entrust to vendors, so procurement and contract terms push the relevant controls onto contractors that handle state information. That's also why the confidential control set, SIMM 5300-A, is shared with vendors under NDA during procurement — the state expects you to meet it.

For a vendor, demonstrating you can operate to the SIMM 5300 baseline is increasingly a prerequisite to winning and keeping state work, and a real differentiator on vehicles like CMAS. WatchUr6 holds CMAS #3-25-06-1018 and has prior performance with the State of California and the California DMV, so we help both state entities and their contractors meet the standard from either side.

What is the SIMM 5330-B annual certification, and who signs it?

SIMM 5330-B is the Information Security and Privacy Program Compliance Certification each California state entity submits to OIS every year. Government Code section 11549.3 requires covered agencies to certify annually that they comply with adopted state security policies, standards, and procedures — and that certification must include a plan of action and milestones for any gaps. It's submitted on the schedule in SIMM 5330-C, due to OIS by the last business day of the entity's scheduled reporting month.

It's paired with the SIMM 5330-A designation letter, through which the entity head formally names the agency's CIO, Information Security Officer, Technology Recovery Coordinator, and Privacy Officer to OIS, with updates required when those roles change. Because it's signed at the agency-head level and backed by statute, it isn't a formality — it's a personal attestation of the program's state, which is exactly why the maturity assessment and evidence behind it matter.

How does SAM-5300 relate to NIST 800-53 and the NIST CSF?

SAM-5300 is built on NIST. The underlying control catalog for SIMM 5300 is NIST 800-53 (with its 800-53B baselines), which California tailors with state-specific parameters in the confidential SIMM 5300-A, referencing FIPS 199 and FIPS 200 for categorization. California has also explicitly aligned its program with NIST CSF 2.0, including the Govern function that sits above identify, protect, detect, respond, and recover.

So an organization with a mature 800-53 or CSF program already shares most of the substance — the work is usually less about building controls from scratch and more about tailoring to California's parameters, mapping into the SIMM structure, running the SIMM 5300-C maturity assessment, and producing the evidence the annual OIS certification depends on. One caution: the SIMM series is updated frequently, with new and revised standards issued by CDT on an ongoing basis, so staying compliant means keeping pace with the current standards rather than treating the framework as static.

// THE NEXT MOVE

Make next year's OIS certification the easy part.

Book a 30-minute SAM-5300 strategy call with a WatchUr6 advisor. Bring whether you're a state entity or a vendor serving one, your current NIST footing, and your reporting month if you know it. You'll walk away with a clear read on your SIMM 5300 gaps, a path to the annual certification, and an honest assessment of your maturity — whether you hire us or not.

Book a SAM-5300 Strategy Call

CA STATE & DMV PAST PERFORMANCE · CMAS #3-25-06-1018 · SDVOSB · DVBE · VETERAN-LED