Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.
What changed between versions
Added a rebuttable presumption against liability for commercial entities that substantially comply with recognized cybersecurity standards, shifting some burden of proof to plaintiffs in lawsuits.
Expanded the list of qualifying cybersecurity standards to include additional NIST publications, ISO/IEC 27000 series, and specific federal laws like FISMA and HITECH.
Added requirements for covered entities to update their cybersecurity programs within one year when two or more referenced standards are revised.
Added clear definitions for 'cyberattack' and 'ransomware' with specific dates for reporting requirements.
Changed the effective date to January 1, 2026, and set a repeal date of December 31, 2025, indicating the act is intended to be temporary.
Added provisions requiring state agencies to notify the Department of Information Technology Services of cyberattacks or ransomware demands within one business day.