Cybersecurity Program Safe Harbor (S.B. 2610)

Texas Cybersecurity Safe Harbor
active

Gives small and mid-sized Texas businesses a defense against exemplary (punitive) damages in data breach lawsuits if, at the time of the breach, they maintained a cybersecurity program scaled to their size and conforming to a recognized framework such as NIST, CIS Controls, ISO 27000, SOC 2, or applicable HIPAA, GLBA, or PCI DSS requirements.

Jurisdiction

Texas

Jurisdiction Type

state

Country

United States

Effective Date

9/1/2025

Enforcing Authority

None (liability defense only)

Fines Under This Regulation

0

Total Fine Amount (USD)

--