Cybersecurity Standards and Liability
Summary
Cybersecurity Standards and Liability; Prohibits local governments from imposing certain cybersecurity standards or processes on vendors; defines "vendor"; prohibits local governments from adopting or enforcing certain cybersecurity standards or processes; provides that local government, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to implement revised frameworks, standards, laws, or regulations.
Bill status
died
1 of 4 stages cleared
Introduction
Dec 2025
Committee Review
Floor Vote
Governor
Introduced Dec 3, 2025
Last action Mar 13, 2026
Maddy AI version diff · 1 comparison
What changed between versions
H 635 Filed
→
H 635 c1
·
5 edits
MODERATE
The bill was revised to clarify that local governments cannot impose cybersecurity standards on vendors that exceed state-mandated requirements, with an exception for contracts signed after July 1, 2026. The text was also updated to remove references to delegating authority to local governments and to streamline the definition of 'vendor' and the list of acceptable cybersecurity frameworks.
Scope change
The bill's scope shifted from allowing local governments to adopt their own standards (with a ban on delegation) to explicitly prohibiting them from imposing stricter standards on vendors, except for specific future contracts.
REQUIREMENT
Changed the rule for local governments from being allowed to adopt standards to being prohibited from imposing standards on vendors that exceed state rules.
Added a specific exception allowing local governments to impose stricter standards only for contracts entered into or amended on or after July 1, 2026.
DEFINITION
Removed the phrase 'The department may not delegate the authority to set cybersecurity standards to a local government' from the text.
Revised the definition of 'vendor' to explicitly include 'trust, estate, cooperative, association, or other commercial entity'.
TECHNICAL
Added a detailed list of acceptable cybersecurity frameworks, including NIST SP 800-171, CIS Controls, and ISO/IEC 27000.
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
20
Key actions
9
Committee
14
Feb 3, 2026
Lower · Passed
Now in State Affairs Committee
lower
Feb 3, 2026
Lower · Passed
Reported out of Civil Justice & Claims Subcommittee
lower
Feb 3, 2026
Lower · Passed
Favorable by Civil Justice & Claims Subcommittee
lower
Jan 30, 2026
Lower · Passed
Added to Civil Justice & Claims Subcommittee agenda
lower
Jan 22, 2026
Lower · Passed
Now in Civil Justice & Claims Subcommittee
lower
Jan 22, 2026
Committee
Referred to State Affairs Committee
lower
Jan 22, 2026
Committee
Referred to Civil Justice & Claims Subcommittee
lower
Jan 21, 2026
Lower · Passed
Reported out of Information Technology Budget & Policy Subcommittee
lower
Jan 20, 2026
Lower · Passed
Favorable with CS by Information Technology Budget & Policy Subcommittee
lower
Jan 15, 2026
Lower · Passed
Added to Information Technology Budget & Policy Subcommittee agenda
lower
Dec 12, 2025
Lower · Passed
Now in Information Technology Budget & Policy Subcommittee
lower
Dec 12, 2025
Committee
Referred to State Affairs Committee
lower
Dec 12, 2025
Committee
Referred to Civil Justice & Claims Subcommittee
lower
Dec 12, 2025
Committee
Referred to Information Technology Budget & Policy Subcommittee
lower
2 primary · 0 co-sponsors
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about HB 635
Scope: FL
Hi! I can help you understand HB 635. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline