THE BILL ITSELF
CS/HB 635
Cybersecurity Standards and Liability
1
A bill to be entitled
2
An act relating to cybersecurity standards and
3
liability; amending s. 282.3185, F.S.; prohibiting
4
local governments from imposing certain cybersecurity
5
standards or processes on vendors; providing an
6
exception; defining the term "vendor"; prohibiting
7
local governments from adopting or enforcing certain
8
cybersecurity standards or processes; creating s.
9
768.401, F.S.; providing definitions; providing that a
10
local government, a covered entity, or a third-party
11
agent that complies with certain requirements is not
12
liable in connection with a cybersecurity incident
13
under certain circumstances; requiring covered
14
entities and third-party agents to implement revised
15
frameworks, standards, laws, or regulations within a
16
specified time period; providing that a private cause
17
of action is not established; providing that the fact
18
that a specified defendant could have obtained a
19
liability shield or a presumption against liability is
20
not admissible as evidence of negligence, does not
21
constitute negligence per se, and may not be used as
22
evidence of fault; specifying that the defendant in
23
certain actions has a certain burden of proof;
24
providing applicability; providing a directive to the
25
Division of Law Revision; providing an effective date.
27
Be It Enacted by the Legislature of the State of Florida:
29
Section 1. Paragraph (a) of subsection (4) of section 282.3185, Florida Statutes, is amended to read:
31
282.3185 Local government cybersecurity.—
32
(4) CYBERSECURITY STANDARDS.—
33
(a)1. Each local government shall adopt cybersecurity
34
standards that safeguard its data, information technology, and
35
information technology resources to ensure availability,
36
confidentiality, and integrity. The cybersecurity standards must
37
be consistent with generally accepted best practices for
38
cybersecurity, including the National Institute of Standards and
39
Technology Cybersecurity Framework.
40
2. A local government may not impose cybersecurity
41
standards or processes on a vendor that exceed the standards or
42
processes established under this paragraph, except as necessary
43
to comply with state or federal laws, or with industry-specific
44
requirements applicable to regulated sectors. For purposes of
45
this paragraph, the term "vendor" means a sole proprietorship,
46
partnership, corporation, trust, estate, cooperative,
47
association, or other commercial entity that contracts with a
48
local government to provide information technology commodities
49
or services.
50
3. A local government may not adopt or enforce any
51
cybersecurity standards or processes that are inconsistent with
52
this paragraph for contracts entered into or amended on or after
53
July 1, 2026.
54
Section 2. Section 768.401, Florida Statutes, is created to read:
56
768.401 Limitation on liability for cybersecurity
57
incidents.—
58
(1) As used in this section, the term:
59
(a) "Covered entity" means a sole proprietorship,
60
partnership, corporation, trust, estate, cooperative,
61
association, or other commercial entity.
62
(b) "Cybersecurity standards or frameworks" means one or
63
more of the following:
64
1. The National Institute of Standards and Technology
65
(NIST) Cybersecurity Framework 2.0;
66
2. NIST special publication 800-171;
67
3. NIST special publications 800-53 and 800-53A;
68
4. The Federal Risk and Authorization Management Program
69
security assessment framework;
70
5. The Center for Internet Security (CIS) Critical
71
Security Controls;
72
6. The International Organization for
73
Standardization/International Electrotechnical Commission 27000
74
series (ISO/IEC 27000) family of standards;
75
7. HITRUST Common Security Framework (CSF);
76
8. Service Organization Control Type 2 Framework (SOC 2);
77
9. Secure Controls Framework; or
78
10. Other similar industry frameworks or standards.
79
(c) "Disaster recovery" has the same meaning as in s.
80
282.0041.
81
(d) "Local government" means a county, municipality, or
82
other political subdivision of this state.
83
(e) "Personal information" has the same meaning as in s.
84
501.171(1).
85
(f) "Third-party agent" means an entity that has been
86
contracted to maintain, store, or process personal information
87
on behalf of a covered entity.
88
(2) A local government is not liable in connection with a
89
cybersecurity incident if the local government has implemented
90
one or more policies that substantially comply with
91
cybersecurity standards or align with cybersecurity frameworks,
92
disaster recovery plans for cybersecurity incidents, and multi-
93
factor authentication.
94
(3) A covered entity or third-party agent that acquires,
95
maintains, stores, processes, or uses personal information has a
96
presumption against liability in a class action resulting from a
97
cybersecurity incident if the covered entity or third-party
98
agent has a cybersecurity program that does all of the
99
following, as applicable:
100
(a) Substantially complies with s. 501.171(3)-(6), as
101
applicable.
102
(b) Has implemented:
103
1. One or more policies that substantially comply with
104
cybersecurity standards or align with cybersecurity frameworks,
105
a disaster recovery plan for cybersecurity incidents, and multi-
106
factor authentication; or
107
2. If regulated by the state or Federal Government, or
108
both, or if otherwise subject to the requirements of any of the
109
following laws and regulations, a cybersecurity program that
110
substantially complies with the current version of such laws and
111
regulations, as applicable:
112
a. The Health Insurance Portability and Accountability Act
113
of 1996 security requirements in 45 C.F.R. part 160 and part 164
114
subparts A and C.
115
b. Title V of the Gramm-Leach-Bliley Act of 1999, Pub. L.
116
No. 106-102, as amended, and its implementing regulations.
117
c. The Federal Information Security Modernization Act of
118
2014, Pub. L. No. 113-283.
119
d. The Health Information Technology for Economic and
120
Clinical Health Act requirements in 45 C.F.R. parts 160 and 164.
121
e. The Criminal Justice Information Services (CJIS)
122
Security Policy.
123
f. Other similar requirements mandated by state or federal
124
laws or regulations.
125
(4) A covered entity's or third-party agent's
126
cybersecurity program's compliance with paragraph (3)(b) may be
127
demonstrated by providing documentation or other evidence of an
128
assessment, conducted internally or by a third-party, reflecting
129
that the covered entity's or third-party agent's cybersecurity
130
program has implemented the requirements of that paragraph.
131
(5) Any covered entity or third-party agent must update
132
its cybersecurity program to incorporate any revisions of
133
relevant frameworks or standards or of applicable state or
134
federal laws or regulations within 1 year after the latest
135
publication date stated in any such revisions in order to retain
136
protection from liability.
137
(6) This section does not establish a private cause of
138
action.
139
(7) If a civil action is filed against a local government,
140
covered entity, or third-party agent that failed to implement a
141
cybersecurity program in compliance with this section, the fact
142
that such defendant could have obtained a liability shield or
143
presumption against liability upon compliance is not admissible
144
as evidence of negligence, does not constitute negligence per
145
se, and may not be used as evidence of fault under any other
146
theory of liability.
147
(8) In a civil action relating to a cybersecurity
148
incident, if the defendant is a local government covered by
149
subsection (2) or a covered entity or third-party agent covered
150
by subsection (3), the defendant has the burden of proof to
151
establish substantial compliance with this section.
152
(9) This section applies to any putative class action
153
filed before, on, or after the effective date of this act.
154
Section 3. The Division of Law Revision is directed to
155
replace the phrase "the effective date of this act" wherever it
156
occurs in this act with the date this act becomes a law.
157
Section 4. This act shall take effect upon becoming a law.