Florida 2026 Regular Session

Florida Senate Bill S0692

Introduced
12/2/25  
Refer
12/16/25  

Caption

Cybersecurity Standards and Liability

Summary

S0692 revises Florida law on cybersecurity requirements for local governments and creates a new liability framework for cybersecurity incidents. First, it amends section 282.3185, F.S., to bar local governments from imposing cybersecurity standards or processes on vendors that exceed the standards already required by the statute, except where needed to comply with state or federal law or industry-specific rules. It also defines “vendor” for this purpose and prohibits local governments from adopting or enforcing inconsistent cybersecurity requirements for certain contracts entered into or amended on or after July 1, 2026. The bill also creates section 768.401, F.S., which provides liability protections for local governments, covered entities, and third-party agents that substantially comply with specified cybersecurity standards, frameworks, disaster recovery planning, and multifactor authentication requirements. For covered entities and third-party agents handling personal information, the bill creates a presumption against liability in class actions if they maintain a qualifying cybersecurity program, including compliance with certain state or federal regimes such as HIPAA, GLBA, FISMA, HITECH, and CJIS, or comparable frameworks like NIST, CIS, ISO/IEC, HITRUST, SOC 2, and others. The bill requires updated compliance within one year of revisions to relevant standards to retain protection, and it states that no private cause of action is created. The bill’s impact on state law is twofold: it limits local government contracting authority over vendor cybersecurity requirements and establishes a statutory liability shield and evidentiary protections in civil actions involving cybersecurity incidents. It also places the burden on defendants to prove substantial compliance when invoking the protection, and it applies to putative class actions filed before, on, or after the effective date. In practical terms, the measure is intended to standardize cybersecurity expectations, reduce patchwork local requirements, and encourage adoption of recognized security frameworks while reducing exposure to negligence claims for entities that meet the statute’s standards. The general sentiment reflected in the committee votes appears supportive overall, though not unanimous. The bill passed the Senate Governmental Oversight and Accountability Committee 5-4 and later the Senate Judiciary Committee 9-2, suggesting a mix of concern and approval but a stronger level of support in the later committee. The absence of transcript excerpts limits direct insight into debate, but the voting pattern indicates the bill was viewed favorably by a majority while still drawing meaningful opposition. The main points of contention likely center on whether the bill unduly restricts local governments from setting stricter cybersecurity requirements for their vendors and whether the liability shield is too broad for entities handling sensitive personal information. Opponents may be concerned that the bill reduces local flexibility and makes it harder for plaintiffs to pursue negligence claims after a breach, while supporters likely view it as a needed uniform standard that aligns Florida law with widely used cybersecurity frameworks and rewards compliance with recognized best practices.

Impact

The bill amends s. 282.3185, F.S., to restrict local governments from imposing vendor cybersecurity standards that exceed state-prescribed requirements, and it creates s. 768.401, F.S., establishing liability protections, evidentiary limits, and a burden-of-proof rule for cybersecurity incident litigation. It affects local governments, vendors, covered entities, and third-party agents that store, process, or maintain personal information, especially those operating under recognized cybersecurity frameworks or regulated by state or federal security laws.

Sentiment

Committee votes suggest the bill had majority support but was not universally embraced. It passed the Senate Governmental Oversight and Accountability Committee by a narrow 5-4 margin and the Senate Judiciary Committee by a wider 9-2 margin. That pattern indicates general approval of the bill’s goals, alongside continued concern from some members about its scope and effects.

Contention

The likely controversy is between supporters who want uniform cybersecurity standards and liability protections, and critics who may believe the bill limits local control and weakens accountability after data breaches. Local governments may object to losing the ability to impose stricter vendor requirements, while consumer and plaintiff-side interests may object to the presumption against liability, the bar on using potential compliance as evidence of negligence, and the bill’s application to class actions. Supporters, by contrast, appear to favor the bill as a way to align requirements with established frameworks and reduce inconsistent or duplicative mandates.

Companion Bills

FL H0635

Same As Cybersecurity Standards and Liability

Previously Filed As

FL H1183

Cybersecurity Incident Liability

FL HB1183

Cybersecurity Incident Liability:

FL H1293

Cybersecurity

FL HB1293

Cybersecurity:

FL S7020

OGSR/Agency Cybersecurity Information

FL H7013

OGSR/Cybersecurity

FL SB1216

Cybersecurity of Mortgage Brokers and Lenders and Money Services Businesses:

FL HB7013

OGSR/Cybersecurity:

FL H0667

Liability for Defamatory Statements

FL H1379

Cybersecurity Risks from Unmanned Aircraft Systems

Similar Bills

MS SB2471

Cyber breach; limit liability for certain entities.

TX SB2610

Relating to a limitation on civil liability of business entities in connection with a breach of system security.

MS HB1380

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

CA AB2298

Pupil instruction: computer science: content standards and instructional materials.

MS SB2410

Cybersecurity; limit liability for governmental and certain commercial entities that substantially comply with standards.

MS HB1220

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

FL H0635

Cybersecurity Standards and Liability

FL H1183

Cybersecurity Incident Liability