HB 635 Florida House · 2026 Regular Session

Cybersecurity Standards and Liability

Summary
Cybersecurity Standards and Liability; Prohibits local governments from imposing certain cybersecurity standards or processes on vendors; defines "vendor"; prohibits local governments from adopting or enforcing certain cybersecurity standards or processes; provides that local government, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to implement revised frameworks, standards, laws, or regulations.
Bill status died 1 of 4 stages cleared
Introduction
Dec 2025
Committee Review
Floor Vote
Governor
Introduced Dec 3, 2025 Last action Mar 13, 2026
Maddy AI version diff · 1 comparison

What changed between versions

H 635 Filed H 635 c1 · 5 edits
MODERATE
The bill was revised to clarify that local governments cannot impose cybersecurity standards on vendors that exceed state-mandated requirements, with an exception for contracts signed after July 1, 2026. The text was also updated to remove references to delegating authority to local governments and to streamline the definition of 'vendor' and the list of acceptable cybersecurity frameworks.
Scope change
The bill's scope shifted from allowing local governments to adopt their own standards (with a ban on delegation) to explicitly prohibiting them from imposing stricter standards on vendors, except for specific future contracts.
REQUIREMENT

Changed the rule for local governments from being allowed to adopt standards to being prohibited from imposing standards on vendors that exceed state rules.

Added a specific exception allowing local governments to impose stricter standards only for contracts entered into or amended on or after July 1, 2026.

DEFINITION

Removed the phrase 'The department may not delegate the authority to set cybersecurity standards to a local government' from the text.

Revised the definition of 'vendor' to explicitly include 'trust, estate, cooperative, association, or other commercial entity'.

TECHNICAL

Added a detailed list of acceptable cybersecurity frameworks, including NIST SP 800-171, CIS Controls, and ISO/IEC 27000.

Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
20
Key actions
9
Committee
14
Feb 3, 2026
Lower · Passed
Now in State Affairs Committee
lower
Feb 3, 2026
Lower · Passed
Reported out of Civil Justice & Claims Subcommittee
lower
Feb 3, 2026
Lower · Passed
Favorable by Civil Justice & Claims Subcommittee
lower
Jan 30, 2026
Lower · Passed
Added to Civil Justice & Claims Subcommittee agenda
lower
Jan 22, 2026
Lower · Passed
Now in Civil Justice & Claims Subcommittee
lower
Jan 22, 2026
Committee
Referred to State Affairs Committee
lower
Jan 22, 2026
Committee
Referred to Civil Justice & Claims Subcommittee
lower
Jan 21, 2026
Lower · Passed
Reported out of Information Technology Budget & Policy Subcommittee
lower
Jan 20, 2026
Lower · Passed
Favorable with CS by Information Technology Budget & Policy Subcommittee
lower
Jan 15, 2026
Lower · Passed
Added to Information Technology Budget & Policy Subcommittee agenda
lower
Dec 12, 2025
Lower · Passed
Now in Information Technology Budget & Policy Subcommittee
lower
Dec 12, 2025
Committee
Referred to State Affairs Committee
lower
Dec 12, 2025
Committee
Referred to Civil Justice & Claims Subcommittee
lower
Dec 12, 2025
Committee
Referred to Information Technology Budget & Policy Subcommittee
lower
2 primary · 0 co-sponsors

Sponsors