S0692 revises Florida law on cybersecurity requirements for local governments and creates a new liability framework for cybersecurity incidents. First, it amends section 282.3185, F.S., to bar local governments from imposing cybersecurity standards or processes on vendors that exceed the standards already required by the statute, except where needed to comply with state or federal law or industry-specific rules. It also defines “vendor” for this purpose and prohibits local governments from adopting or enforcing inconsistent cybersecurity requirements for certain contracts entered into or amended on or after July 1, 2026.
The bill also creates section 768.401, F.S., which provides liability protections for local governments, covered entities, and third-party agents that substantially comply with specified cybersecurity standards, frameworks, disaster recovery planning, and multifactor authentication requirements. For covered entities and third-party agents handling personal information, the bill creates a presumption against liability in class actions if they maintain a qualifying cybersecurity program, including compliance with certain state or federal regimes such as HIPAA, GLBA, FISMA, HITECH, and CJIS, or comparable frameworks like NIST, CIS, ISO/IEC, HITRUST, SOC 2, and others. The bill requires updated compliance within one year of revisions to relevant standards to retain protection, and it states that no private cause of action is created.
The bill’s impact on state law is twofold: it limits local government contracting authority over vendor cybersecurity requirements and establishes a statutory liability shield and evidentiary protections in civil actions involving cybersecurity incidents. It also places the burden on defendants to prove substantial compliance when invoking the protection, and it applies to putative class actions filed before, on, or after the effective date. In practical terms, the measure is intended to standardize cybersecurity expectations, reduce patchwork local requirements, and encourage adoption of recognized security frameworks while reducing exposure to negligence claims for entities that meet the statute’s standards.
The general sentiment reflected in the committee votes appears supportive overall, though not unanimous. The bill passed the Senate Governmental Oversight and Accountability Committee 5-4 and later the Senate Judiciary Committee 9-2, suggesting a mix of concern and approval but a stronger level of support in the later committee. The absence of transcript excerpts limits direct insight into debate, but the voting pattern indicates the bill was viewed favorably by a majority while still drawing meaningful opposition.
The main points of contention likely center on whether the bill unduly restricts local governments from setting stricter cybersecurity requirements for their vendors and whether the liability shield is too broad for entities handling sensitive personal information. Opponents may be concerned that the bill reduces local flexibility and makes it harder for plaintiffs to pursue negligence claims after a breach, while supporters likely view it as a needed uniform standard that aligns Florida law with widely used cybersecurity frameworks and rewards compliance with recognized best practices.
The bill amends s. 282.3185, F.S., to restrict local governments from imposing vendor cybersecurity standards that exceed state-prescribed requirements, and it creates s. 768.401, F.S., establishing liability protections, evidentiary limits, and a burden-of-proof rule for cybersecurity incident litigation. It affects local governments, vendors, covered entities, and third-party agents that store, process, or maintain personal information, especially those operating under recognized cybersecurity frameworks or regulated by state or federal security laws.
Committee votes suggest the bill had majority support but was not universally embraced. It passed the Senate Governmental Oversight and Accountability Committee by a narrow 5-4 margin and the Senate Judiciary Committee by a wider 9-2 margin. That pattern indicates general approval of the bill’s goals, alongside continued concern from some members about its scope and effects.
The likely controversy is between supporters who want uniform cybersecurity standards and liability protections, and critics who may believe the bill limits local control and weakens accountability after data breaches. Local governments may object to losing the ability to impose stricter vendor requirements, while consumer and plaintiff-side interests may object to the presumption against liability, the bar on using potential compliance as evidence of negligence, and the bill’s application to class actions. Supporters, by contrast, appear to favor the bill as a way to align requirements with established frameworks and reduce inconsistent or duplicative mandates.