Cybersecurity Legislation Tracker
Security obligations are being written into statute, one sector at a time
A curated tracker for cybersecurity legislation that follows the duty rather than the industry, with a monthly issue you can forward.
Bills in Scope
Jurisdictions
Past Committee

The Problem
There Is No Cybersecurity Code To Read
The obligations are scattered across utilities statutes, insurance codes, procurement rules, hospital licensing and state agency IT law, and each one arrives under a different committee.
Sector tracking returns everything and nothing
Follow "the electric grid" and you get rate cases. Follow "financial institutions" and you get consumer lending. The sector is not the subject. The duty is: report an incident inside seventy-two hours, maintain a written program, hold a vendor to a standard.
Reporting deadlines are what clients get wrong
They are short, they differ by state and by sector, and they change by amendment rather than by new statute. A client usually discovers the deadline moved at the moment they need to meet it.
The bill that matters is often one definition
Whether industrial control systems and SCADA fall inside a definition of covered infrastructure decides who has an obligation at all. That is one clause in a long bill, and it is never in the title.
What's In Scope
Defined in writing, measured against every bill
In scope is any bill imposing security duties on an identifiable party: incident notification to a regulator or an affected person, written information security programs and reasonable security standards, ransomware payment restrictions and disclosure, vendor and supply chain requirements, and the treatment of industrial control systems and supervisory control and data acquisition systems.
What this tracker does not cover
State administrative codes, agency advisories and threat intelligence are out of scope. Federal rulemaking arrives through Regulatory Watch, which is the Federal Register only and permanently so.
Scope is defined by a written topic profile that every bill is measured against. The profiles are drafted by a model and validated by retrieval measurement against a judged set of bills, not reviewed by an attorney. LawSignals is a research tool and does not provide legal advice.
Live From The Tracker
What's at the top of the Cybersecurity Legislation feed
The real feed, ranked the way a subscriber sees it: how far a bill has moved first, then how recently. Nothing here is a sample.
Matched through 12 August 2026
27Enacted
2Cleared both chambers
27Past committee
92Introduced or inactive
148 bills in scope
Enacted
25 of 27 shown
Showing the 25 furthest along of 148. Sign up to see the full list →
The Monthly Issue
The document you forward to a client
Read a full issue before you decide anything. It was generated from the corpus, so every bill in it is real and you can check one.
Read the June 2026 issueA real generated document, not a mockup.
The month in one paragraph
What actually happened, written rather than counted.
What moved
Every bill that advanced, grouped by how far, one line each.
Enacted
What became law, and the effective date where the text states one.
Regulatory Watch
Federal rulemaking on the same subject, led by comment deadlines.
By Jurisdiction
Cybersecurity Legislation legislation, state by state
37 jurisdictions currently hold bills in this tracker
- New Jersey20
- Maryland15
- New York14
- Texas10
- Florida9
- Minnesota8
- Massachusetts7
- Michigan6
- Illinois5
- Oklahoma5
- Rhode Island5
- Connecticut4
- Pennsylvania4
- Nebraska3
- Arizona2
- California2
- Indiana2
- Maine2
- Mississippi2
- Ohio2
- Oregon2
- South Carolina2
- Tennessee2
- Washington2
- Alaska1
- Delaware1
- Iowa1
- Idaho1
- Kentucky1
- Montana1
- New Hampshire1
- New Mexico1
- Congress1
- Utah1
- Virginia1
- Vermont1
- West Virginia1
Track Cybersecurity Legislation in your dashboard
One tracker is the entry plan. Every plan starts with a free trial, and the trial includes a real issue rather than a sample of one.
Frequently Asked Questions
What counts as a cybersecurity bill here?
Any bill imposing a security duty on an identifiable party: incident notification, written information security programs, reasonable security standards, ransomware payment rules, vendor requirements, and the treatment of industrial control and SCADA systems.
Why not track by sector?
Because the sector is not the subject. A utilities bill is usually a rate case and a financial institutions bill is usually consumer lending. This tracker is scoped to the obligation, so a hospital licensing bill and a procurement bill arrive together when both impose the same duty.
Does it cover federal cybersecurity rulemaking?
Through Regulatory Watch, which reads the Federal Register and leads with open comment deadlines. State administrative codes are outside the product permanently.
Who decides what is relevant?
A written topic profile, drafted by a model and validated by retrieval measurement against a judged set of bills. It is not reviewed by an attorney.
LawSignals is a research tool. It does not provide legal advice. Always consult qualified legal counsel.