SB 254 New Mexico Senate · 2025 Regular Session

CYBERSECURITY ACT & OFFICE CHANGES

SB 254 proposes renaming New Mexico's "Cybersecurity Office" to the "Office of Cybersecurity" and places it under the Department of Information Technology, managed by a Security Officer. The bill requires this office to establish minimum security standards for all state agencies, develop centralized incident response plans for major breaches (affecting over 10,000 residents or involving nation-state actors), and create a unified data breach reporting process. It also revises the Cybersecurity Advisory Committee's membership to include specific representation from counties, municipalities, tribal governments, healthcare, education, and private cybersecurity experts. These changes directly affect state agencies, local governments, and tribal entities by standardizing cybersecurity practices and reporting requirements across New Mexico's public sector.
Bill status passed 3 of 5 stages cleared
Introduction
Feb 2025
Committee Review
Mar 2025
Senate Passage
Mar 2025
House Passage
Governor
Introduced Feb 3, 2025 Last action Jun 3, 2025
Maddy AI version diff · 1 comparison

What changed between versions

introduced version RU substitute · 6 edits
MODERATE
This bill amends New Mexico's Cybersecurity Act to update definitions, reorganize the Office of Cybersecurity duties, and revise the Cybersecurity Advisory Committee's membership and reporting requirements. The changes clarify terminology, expand the office's responsibilities to include service catalogs and centralized breach reporting, and adjust committee composition to better reflect state and local representation.
Scope change
The bill expands the scope of the Office of Cybersecurity by adding new duties such as developing a service catalog, establishing data classification policies, and creating a centralized breach reporting process. It also broadens the definition of 'information technology' to include modern cloud and communication systems.
DEFINITION

Updated definitions to include modern technology like cloud systems, voice/video communications, and user credentials, ensuring the law covers current digital infrastructure.

REQUIREMENT

Added new duties for the Office of Cybersecurity including developing a service catalog, establishing data classification policies, and creating a centralized breach reporting process.

Reordered the Cybersecurity Advisory Committee's duties to prioritize statewide planning and best practice guidelines before incident response coordination.

ELIGIBILITY

Adjusted committee membership numbers and representation requirements, reducing some positions from three to two members and clarifying representation for counties and municipalities.

TIMELINE

Changed reporting deadlines from 2023 to 2024 and subsequent years, aligning with the new legislative session timeline.

ENFORCEMENT

Clarified that the security officer can issue compliance orders for executive agencies but that compliance by non-executive and local governments remains voluntary.

Floor votes · Senate Mar 17, 2025

How they voted

360
Passed · 4 other
Total votes 40
Mar 17, 2025
D Democratic24
22 Yea 2
91% Yea
R Republican16
14 Yea 2
87% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
6
Key actions
3
Committee
2
Mar 18, 2025
Introduced
Sent to House Judiciary Committee
lower
Mar 17, 2025
Upper · Passed
passed Senate
upper
Mar 15, 2025
Upper · Passed
DO PASS committee report adopted
upper
Feb 21, 2025
Upper · Passed
DO NOT PASS, replaced with committee substitute
upper
Feb 3, 2025
Introduced
Sent to Senate Rules Committee & Senate Health and Public Affairs Committee
upper
2 primary · 0 co-sponsors

Sponsors