Cybersecurity Legislation Tracker

Security obligations are being written into statute, one sector at a time

A curated tracker for cybersecurity legislation that follows the duty rather than the industry, with a monthly issue you can forward.

426

Bills in Scope

51

Jurisdictions

187

Past Committee

Page one of the September 2026 issue of the Cybersecurity Legislation Tracker
Page one of the September 2026 issue. A generated document, not a mockup.

The Problem

There Is No Cybersecurity Code To Read

The obligations are scattered across utilities statutes, insurance codes, procurement rules, hospital licensing and state agency IT law, and each one arrives under a different committee.

Sector tracking returns everything and nothing

Follow "the electric grid" and you get rate cases. Follow "financial institutions" and you get consumer lending. The sector is not the subject. The duty is: report an incident inside seventy-two hours, maintain a written program, hold a vendor to a standard.

Reporting deadlines are what clients get wrong

They are short, they differ by state and by sector, and they change by amendment rather than by new statute. A client usually discovers the deadline moved at the moment they need to meet it.

The bill that matters is often one definition

Whether industrial control systems and SCADA fall inside a definition of covered infrastructure decides who has an obligation at all. That is one clause in a long bill, and it is never in the title.

What's In Scope

Defined in writing, measured against every bill

In scope is any bill imposing security duties on an identifiable party: incident notification to a regulator or an affected person, written information security programs and reasonable security standards, ransomware payment restrictions and disclosure, vendor and supply chain requirements, and the treatment of industrial control systems and supervisory control and data acquisition systems.

data breach notification duties
critical infrastructure and utility security
state and local government cyber resilience
ransomware and incident reporting
connected device and product security standards

What this tracker does not cover

State administrative codes, agency advisories and threat intelligence are out of scope. Federal rulemaking arrives through Regulatory Watch, which is the Federal Register only and permanently so.

Scope is defined by a written topic profile that every bill is measured against. The profiles are drafted by a model and validated by retrieval measurement against a judged set of bills, not reviewed by an attorney. LawSignals is a research tool and does not provide legal advice.

Live From The Tracker

What's at the top of the Cybersecurity Legislation feed

The real feed, ranked the way a subscriber sees it: how far a bill has moved first, then how recently. Nothing here is a sample.

Matched through 5 October 2026

89Enacted

5Cleared both chambers

93Past committee

12Active in committee

227Introduced or inactive

426 bills in scope

Enacted

25 of 89 shown

CAAB 2281Office of Elections Cybersecurity.EnactedCAAB 2298Pupil instruction: computer science: content standards.EnactedDEHB 381AN ACT TO AMEND TITLE 6 OF THE DELAWARE CODE RELATING TO COMPUTER SECURITY BREACHES.EnactedMOSB 890SS/SCS/SB 890 - This act requires each state department with oversight of an administrative entity to submit an annual report to the General Assembly detailing any administrative entity that has not convened a public meeting or conducted public business during the three year period ending on August 28th of such year. The act further repeals and reassigns duties for a number of administrative entities. The Division of Workforce Development within the Department of Economic Development is renamed and moved to the Office of Workforce Development within the Department of Higher Education and Workforce Development. The Board for Certification of Interpreters is repealed and its duties assigned to the Missouri Commission for the Deaf and Hard of Hearing. The Life Sciences Research Board is repealed and its duties assigned the Department of Economic Development. The act repeals the Missouri Quality Home Care Council is repealed as well as all duties of the Council. The act repeals the following entities: the Career Readiness Course Task Force; the Infection Control Advisory Panel; the Missouri Arthritis Advisory Board and the Arthritis Program Review Committee; the AgriMissouri Advisory Commission for Marketing Missouri Agricultural Products; the Coordinating Board for Early Childhood; the Minority Environmental Literacy Advisory Committee; the Missouri Cybersecurity Commission; the Small Business Compliance Advisory Committee; and the Commission on the Special Health, Psychological and Social Needs of Minority Older Individuals. This act is similar to SB 729 (2025). JIM ERTLEEnactedMOSB 999SS#2/SB 999 - This act modifies several provisions relating to vulnerable persons. ASSISTANCE FROM THE ATTORNEY GENERAL (Section 27.117) Under this act, a prosecuting attorney may request assistance from the Attorney General for the prosecution of the certain sexual offenses. This provision is identical to a provision in CCS/SS/SCS/HCS/HBs 2637 & 3155 (2026) and substantially similar to a provision in the truly agreed to and finally passed SS/SCS/HCS/HBs 2273 et al (2026). "BORN-ALIVE ABORTION SURVIVORS PROTECTION ACT (Section 188.035) This act creates the "Born-Alive Abortion Survivors Protection Act". Under this act, a child born alive during or after an abortion or attempted abortion shall have the same rights, privileges, and immunities as any other person, citizen, and resident of Missouri, including any other live-born child. Any licensed, registered, or certified health care provider present in the provider's professional capacity at the time a child is born alive during or after an abortion or attempted abortion shall exercise the same degree of professional skill, care, and diligence to preserve the life, health, and comfort of the child as a reasonably diligent and conscientious provider would render to any other child born alive at the same gestational age. Any person who knowingly performs or attempts to perform an overt act that kills a child born alive shall be guilty of first-degree murder. A person shall have the right to bring a cause of action for wrongful death or improper health care, as described in this act. This provision is similar to HCS/HBs 195 & 1119 (2025), SB 702 (2025), SCS/SB 753 (2022), provisions in SCS/HCS/HB 2012 (2022), HCS/HBs 1593 & 1959 (2022), SB 168 (2021), SB 665 (2020), and SB 388 (2019). PREGNANCY-ASSOCIATED MORTALITY REVIEW BOARD (Section 192.990) This act modifies the "Pregnancy-Associated Mortality Review Board" within the Department of Health and Senior Services. Under this act, board membership shall include at least one member from each congressional district with demographically diverse membership. Board members are increased from no more than 18 members to no more than 22 members. Additionally, the board shall, in its study and review of maternal deaths, consider the level and timing of prenatal and postnatal care, the presence or absence of maternity care deserts, approaches taken in this state and other states to reduce or eliminate racial inequities in maternal deaths, and the adequacy of data collected by the board. Data reported by the board shall be disaggregated by race, ethnicity, language, nationality, age, zip code, and level and timing of prenatal and postnatal care. This provision is identical to a provision in the truly agreed to and finally passed SS/SCS/HCS/HB 2372 (2026) and substantially similar to SCS/SB 871 (2026), SB 39 (2025), SCS/SBs 1357 & 888 (2024), and SCS/SBs 579 & 595 (2023). RELEASE FROM JAIL (Section 544.667) Currently, a person can be released from jail upon recognizance or bond. This act provides that a person that has been released under such circumstances that fails to comply with the conditions of such release that imposes no contact with the victim shall be guilty of a class A misdemeanor and shall forfeit any security that was pledged for their release. This provision is identical to a provision in CCS/SS/SCS/HCS/HBs 2637 & 3155 (2026) and SCS/SB 928 (2026). CRIMINAL OFFENSES (Sections 455.050, 565.002, 565.050-565.056, 565.072-565.074, 565.090-565.091, 565.225-565.227, 565.400-565.405, 573.570, 573.575, and Section C) This act modifies the offenses of assault in the first, second, third, and fourth degrees and the offenses of domestic violence in the first, second, third, and fourth degrees by removing the defined terms of "serious physical injury" and "physical injury" and providing for the following harms: • Great bodily harm: Bodily injury which creates a high probability of death, or which causes serious permanent or protracted loss or impairment of function of any bodily member or organ, or other serious bodily harm; • Substantial bodily harm: Bodily harm which involves a temporary but substantial disfigurement, or which causes temporary but substantial loss or impairment of the function of any bodily member or organ, or which causes a fracture of any bodily member; and • Bodily harm: Physical pain or injury, illness, or any impairment of physical condition. Under current law, the first offense of harassment in the first degree is a class E felony. This act provides that a second or subsequent conviction of harassment in the first degree shall be a class D felony where the individual has previously been found guilty of harassment in the first or second degree. Currently, a first offense of harassment in the second degree is a class A misdemeanor. Under this act, provisions relating to a second or subsequent conviction of harassment in the second degree are modified to include a conviction of harassment in the first degree as a previous conviction in which case it is a class E felony. This act modifies the offense of stalking in the first degree by repealing the elements of such offense and providing that a person commits the offense of stalking in the first degree when the person knowingly, through a course of conduct that is directed at another person or through technological abuse, as defined in the act, engages in conduct that would cause a reasonable person under similar circumstances to: • Fear death or bodily injury, as defined in this act; • Fear that an offense will be committed against a member of the person's family, household members, or an individual with whom the person has a dating relationship; • Fear that an offense will be committed against the person's property; or • Feel harassed, terrified, or intimidated. This act modifies the offense of stalking in the second degree by repealing the elements of such offense and providing that a person commits the offense of stalking in the second degree when the person knowingly, through a course of conduct that is directed at another person or through technological abuse, as defined in the act, engages in conduct that would cause a reasonable person under similar circumstances to feel harassed, terrified, or intimidated. This act creates the offense of cyberharassment. A person commits this offense if he or she purposely or knowingly engages in a threatening, aggressive, or otherwise fear-inducing, course of conduct by using digital technology, internet service providers, electronic service providers or other electronic communications and devices cause reasonable fear, alarm, anxiety, undo stress, or terror to others by repeated contact with no legitimate purpose. This offense shall be a class B misdemeanor upon a first offense and a class A misdemeanor for second or subsequent offenses. A person commits the offense of cyberstalking if such person purposely or knowingly engages in a threatening, aggressive, or otherwise fear-inducing, course of conduct by using digital technology, internet service providers, electronic service providers or other electronic communications and devices to enhance the ability to intimidate, track, follow or cause reasonable fear, alarm, anxiety, undo stress, or terror to another person. A first offense shall be a class A misdemeanor and a second or subsequent offense shall be a class E felony. These provisions are identical to provisions in CCS/SS/SCS/HCS/HBs 2637 & 3155 (2026) and SCS/SB 928 (2026). This act creates the offense of disclosure of an intimate digital depiction. A person shall be guilty of such offense if he or she discloses or threatens to disclose an intimate digital depiction with the intent to harass or threaten another person. A violation of such offense is a class D felony if the person discloses an intimate digital depiction and a class E felony if the person threatens to disclose an intimate digital depiction. Any second or subsequent violation of such offense is a class C felony. Additionally, it shall be a class C felony if the disclosure interferes with a government proceeding or causes violence. This act creates the offense of sadistic online exploitation. A person commits this offense where he or she uses the internet to coerce a victim into committing certain acts. This offense shall be a class E felony. These provisions are identical to provision in the truly agreed to and finally passed SS/SCS/HCS/HBs 2273 et al (2026), CCS/SS/SCS/HCS/HBs 2637 & 3155 (2026), and SCS/SB 928 (2026). Provisions of this act have an effective date of July 1, 2027. This act has a non-severability provision for the act. SARAH HASKINSEnactedWVHB 5638Relating to the requirements of the state’s cyber security program and responsibilities and authority of the state chief information security officerEnactedFLHB 1081Cybersecurity Experiential LearningEnactedNHSB 589relative to port electrification, microgrid development, and cybersecurity standards for energy and water systems.EnactedFLSB 7024OGSR/Cybersecurity, Information Technology, and Operational Technology InformationEnactedCOHB 1252Updates to State Emergency Response Departments & DivisionsEnactedCOSB 185Enhance Security of Office of Information TechnologyEnactedMDHB 1335Department of Information Technology - Information Technology Staffing and Capability Assessment - Independent StudyEnactedOKSB 1859Oklahoma State Bureau of Investigation; creating the Cyber Crime Fraud Unit; revolving fund. Effective date. Emergency.EnactedFLHB 1085Local Government Cyber SecurityEnactedLAHB 1033CRIME: Provides relative to the definition of "critical infrastructure"EnactedLASB 75INFORMATION TECHNOLOGY: Provides for reimbursement to the state for cyber reinforcement support provided to noncompliant recipients. (8/1/26) (EN SEE FISC NOTE SG RV)EnactedMDHB 1239Public Safety - Critical Infrastructure ProtectionEnactedMDHB 593Criminal Law - Interference With Critical Infrastructure or a Public Safety Answering PointEnactedMDHB 861Department of Information Technology - Statewide Information Technology Master Plan - ReportingEnactedMDSB 482Criminal Law - Interference With Critical Infrastructure or a Public Safety Answering PointEnactedMDSB 581Department of Information Technology - Statewide Information Technology Master Plan - ReportingEnactedNELB 937Adopt the Prior Learning Act and the K-12 Education Cybersecurity Act and change provisions relating to student transfers, school absences, option enrollment, extracurricular activities, reports, school employment, the improvement grant program, monitoring or providing instruction, deadlines, the Nebraska Teacher Apprenticeship Program, the Nebraska Teacher Recruitment and Retention Act, and the College Pathway Program ActEnactedMELD 2092An Act To Update Certain Terms And References Regarding Information Technology And CybersecurityEnactedMDHB 957Cybersecurity - Standards and Compliance - AlterationsEnactedMELD 2103An Act Requiring Hospitals To Adopt Cybersecurity PlansEnacted

Showing the 25 furthest along of 426. Sign up to see the full list →

The Monthly Issue

The document you forward to a client

Read a full issue before you decide anything. It was generated from the corpus, so every bill in it is real and you can check one.

Read the August 2026 issue

A real generated document, not a mockup.

Read past issues in the archive →

The month in one paragraph

What actually happened, written rather than counted.

What moved

Every bill that advanced, grouped by how far, one line each.

Enacted

What became law, and the effective date where the text states one.

Regulatory Watch

Federal rulemaking on the same subject, led by comment deadlines.

Track Cybersecurity Legislation in your dashboard

One tracker is the entry plan. Every plan starts with a free trial, and the trial includes a real issue rather than a sample of one.

Frequently Asked Questions

What counts as a cybersecurity bill here?

Any bill imposing a security duty on an identifiable party: incident notification, written information security programs, reasonable security standards, ransomware payment rules, vendor requirements, and the treatment of industrial control and SCADA systems.

Why not track by sector?

Because the sector is not the subject. A utilities bill is usually a rate case and a financial institutions bill is usually consumer lending. This tracker is scoped to the obligation, so a hospital licensing bill and a procurement bill arrive together when both impose the same duty.

Does it cover federal cybersecurity rulemaking?

Through Regulatory Watch, which reads the Federal Register and leads with open comment deadlines. State administrative codes are outside the product permanently.

Who decides what is relevant?

A written topic profile, drafted by a model and validated by retrieval measurement against a judged set of bills. It is not reviewed by an attorney.

LawSignals is a research tool. It does not provide legal advice. Always consult qualified legal counsel.