Cybersecurity Legislation Tracker

Security obligations are being written into statute, one sector at a time

A curated tracker for cybersecurity legislation that follows the duty rather than the industry, with a monthly issue you can forward.

148

Bills in Scope

37

Jurisdictions

56

Past Committee

Page one of the June 2026 issue of the Cybersecurity Legislation Tracker
Page one of the June 2026 issue. A generated document, not a mockup.

The Problem

There Is No Cybersecurity Code To Read

The obligations are scattered across utilities statutes, insurance codes, procurement rules, hospital licensing and state agency IT law, and each one arrives under a different committee.

Sector tracking returns everything and nothing

Follow "the electric grid" and you get rate cases. Follow "financial institutions" and you get consumer lending. The sector is not the subject. The duty is: report an incident inside seventy-two hours, maintain a written program, hold a vendor to a standard.

Reporting deadlines are what clients get wrong

They are short, they differ by state and by sector, and they change by amendment rather than by new statute. A client usually discovers the deadline moved at the moment they need to meet it.

The bill that matters is often one definition

Whether industrial control systems and SCADA fall inside a definition of covered infrastructure decides who has an obligation at all. That is one clause in a long bill, and it is never in the title.

What's In Scope

Defined in writing, measured against every bill

In scope is any bill imposing security duties on an identifiable party: incident notification to a regulator or an affected person, written information security programs and reasonable security standards, ransomware payment restrictions and disclosure, vendor and supply chain requirements, and the treatment of industrial control systems and supervisory control and data acquisition systems.

data breach notification duties
critical infrastructure and utility security
state and local government cyber resilience
ransomware and incident reporting
connected device and product security standards

What this tracker does not cover

State administrative codes, agency advisories and threat intelligence are out of scope. Federal rulemaking arrives through Regulatory Watch, which is the Federal Register only and permanently so.

Scope is defined by a written topic profile that every bill is measured against. The profiles are drafted by a model and validated by retrieval measurement against a judged set of bills, not reviewed by an attorney. LawSignals is a research tool and does not provide legal advice.

Live From The Tracker

What's at the top of the Cybersecurity Legislation feed

The real feed, ranked the way a subscriber sees it: how far a bill has moved first, then how recently. Nothing here is a sample.

Matched through 12 August 2026

27Enacted

2Cleared both chambers

27Past committee

92Introduced or inactive

148 bills in scope

Enacted

25 of 27 shown

ILHB 4966DCFS-SECURE ACTEnactedWVHB 5638Relating to the requirements of the state’s cyber security program and responsibilities and authority of the state chief information security officerEnactedFLHB 1081Cybersecurity Experiential LearningEnactedFLHB 1085Local Government Cyber SecurityEnactedMDHB 593Criminal Law - Interference With Critical Infrastructure or a Public Safety Answering PointEnactedMDSB 482Criminal Law - Interference With Critical Infrastructure or a Public Safety Answering PointEnactedMELD 2092An Act To Update Certain Terms And References Regarding Information Technology And CybersecurityEnactedMDHB 957Cybersecurity - Standards and Compliance - AlterationsEnactedMELD 2103An Act Requiring Hospitals To Adopt Cybersecurity PlansEnactedWASB 6231Removing a tax exemption for the replacement of equipment for data centers.EnactedRISB 2341AN ACT RELATING TO ELECTIONS -- MAIL BALLOTSEnactedMSSB 2096MDITS and SOS; require to establish minimum cybersecurity standards for SEMS.EnactedNYS 7672Relates to municipal cybersecurity incidents or ransomware attacksEnactedTXHB 3112Relating to the application of the open meetings law and public information law to government information related to certain cybersecurity measures.EnactedTXSB 2610Relating to a limitation on civil liability of business entities in connection with a breach of system security.EnactedTXHB 150Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.EnactedFLSB 7020OGSR/Agency Cybersecurity InformationEnactedMDSB 294Maryland Cybersecurity Council - AlterationsEnactedWASB 5014Concerning election security.EnactedMDSB 871Department of the Environment - Community Water and Sewerage Systems - Cybersecurity Planning and AssessmentsEnactedINSB 459Environmental matters.EnactedINSB 472Cybersecurity.EnactedMDHB 209State Finance and Procurement - Local Cybersecurity Preparedness and Response Plan and Assessment - RepealEnactedMDHB 235State Government - Information Technology - Cybersecurity RevisionsEnactedMDSB 244State Government - Information Technology - Cybersecurity RevisionsEnacted

Showing the 25 furthest along of 148. Sign up to see the full list →

The Monthly Issue

The document you forward to a client

Read a full issue before you decide anything. It was generated from the corpus, so every bill in it is real and you can check one.

Read the June 2026 issue

A real generated document, not a mockup.

Read past issues in the archive →

The month in one paragraph

What actually happened, written rather than counted.

What moved

Every bill that advanced, grouped by how far, one line each.

Enacted

What became law, and the effective date where the text states one.

Regulatory Watch

Federal rulemaking on the same subject, led by comment deadlines.

Track Cybersecurity Legislation in your dashboard

One tracker is the entry plan. Every plan starts with a free trial, and the trial includes a real issue rather than a sample of one.

Frequently Asked Questions

What counts as a cybersecurity bill here?

Any bill imposing a security duty on an identifiable party: incident notification, written information security programs, reasonable security standards, ransomware payment rules, vendor requirements, and the treatment of industrial control and SCADA systems.

Why not track by sector?

Because the sector is not the subject. A utilities bill is usually a rate case and a financial institutions bill is usually consumer lending. This tracker is scoped to the obligation, so a hospital licensing bill and a procurement bill arrive together when both impose the same duty.

Does it cover federal cybersecurity rulemaking?

Through Regulatory Watch, which reads the Federal Register and leads with open comment deadlines. State administrative codes are outside the product permanently.

Who decides what is relevant?

A written topic profile, drafted by a model and validated by retrieval measurement against a judged set of bills. It is not reviewed by an attorney.

LawSignals is a research tool. It does not provide legal advice. Always consult qualified legal counsel.