Requires municipalities, counties, and school districts to report cybersecurity incidents.
This bill requires municipalities, counties, and school districts in New Jersey to report cybersecurity incidents that compromise billing systems, communications, data management, or critical infrastructure (like industrial control systems). Designated employees must submit incidents via an online form developed by the Attorney General and NJ Cybersecurity Integration Cell within a prompt timeframe. Within 30 days of receiving a report, the NJCCIC must contract an independent cybersecurity firm to audit the entity’s security program and response, identifying threats, vulnerabilities, and improvement strategies. All incident reports and audit details are exempt from public disclosure under New Jersey’s open records law. The Department of Law and Public Safety covers audit costs and allows reimbursement for related expenses incurred by affected entities.
Bill status
in committee
1 of 4 stages cleared
Introduction
Feb 2024
Committee Review
Floor Vote
Governor
Introduced Feb 27, 2024
Last action Nov 14, 2024
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
3
Key actions
0
Committee
2
Nov 14, 2024
Committee
Reported and Referred to Assembly Appropriations Committee
lower
Jun 6, 2024
Committee
Reported out of Assembly Committee with Amendments and Referred to Assembly State and Local Government Committee
lower
Feb 27, 2024
Introduced
Introduced in the Assembly, Referred to Assembly Science, Innovation and Technology Committee
lower
3 primary · 2 co-sponsors
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about A 3897
Scope: NJ
Hi! I can help you understand A 3897. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline