Texas Cybersecurity Safe Harbor (SB 2610): A Plain-Language Guide

By May 28, 2025September 30th, 2026Business4 min read

Last reviewed: September 30, 2026

Texas Senate Bill 2610 gives smaller Texas businesses a clear reason to invest in cybersecurity. If your organization has fewer than 250 employees and maintains a cybersecurity program that meets the law’s requirements, a person suing you over a data breach cannot recover exemplary (punitive) damages.

What the law is

SB 2610 added Chapter 542, “Cybersecurity Program,” to the Texas Business and Commerce Code. The governor signed it on June 20, 2025, and it took effect on September 1, 2025. It applies to lawsuits over breaches where the cause of action arose on or after that date.

The law is voluntary. It creates no new penalties, filings or deadlines. It offers a legal defense to businesses that can show they had implemented and maintained a qualifying cybersecurity program at the time of the breach.

Who it affects

The safe harbor is available to a business entity in Texas that:

  • has fewer than 250 employees, and
  • owns or licenses computerized data that includes sensitive personal information.

Under Texas law, sensitive personal information includes a person’s name combined with a Social Security number, driver’s license or government ID number, or financial account or card number with its access code, when that data is not encrypted. It also includes information that identifies a person and relates to their health, health care or payment for health care. If you keep employee, patient or customer records, you likely hold it.

What a qualifying program looks like

Every qualifying program needs administrative, technical and physical safeguards for personal information, and it must conform to an industry-recognized cybersecurity framework. The requirements scale with your size:

  • Fewer than 20 employees: simplified requirements, including password policies and appropriate employee cybersecurity training.
  • 20 to 99 employees: moderate requirements, including the Center for Internet Security (CIS) Controls Implementation Group 1.
  • 100 to 249 employees: conformity with one or more of the frameworks named in the law.

The frameworks named in the law are the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53 and 800-53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000 series, the HITRUST Common Security Framework, the Secure Controls Framework, SOC 2, and other similar industry frameworks.

If your organization is subject to HIPAA, the Gramm-Leach-Bliley Act (Title V), FISMA or the HITECH Act, your program must also conform to the current version of those laws. If PCI DSS applies to you, your program must conform to it as well.

Keeping current: when a named framework is updated, you have until the later of the implementation date published in the new version or one year after it is published to update your program.

What it means in practice

The safe harbor is narrow and specific:

  • It limits exemplary damages only. Damages meant to compensate people for harm are not affected.
  • It creates no new lawsuits. The law states that it does not create a private cause of action.
  • It changes no existing duties. Your obligations under Texas breach notification law stay the same. For example, you must still notify affected individuals within 60 days of determining a breach occurred, and notify the Texas Attorney General within 30 days if 250 or more Texans are involved.
  • It depends on proof. You need to show the program was in place and maintained when the breach happened. Documentation matters.

The practical takeaway: pick a framework that fits your size and industry, put the controls in place, keep records that prove they work, and review them when the framework changes.

How ALCON DTS helps

ALCON DTS helps Texas organizations build, operate and document a cybersecurity program aligned to the framework that fits them, from password policies and security awareness training to endpoint detection and response, email security, monitoring, and tested backup and recovery. You keep the legal decisions. We run the controls and keep the evidence organized for your attorney, insurer or auditor.

For the full breakdown, including framework details, how our services map to each requirement and related Texas laws, see our Texas SB 2610 Cybersecurity Safe Harbor page.

Ready to see where you stand? Email info@alcondts.com or call 512-892-6900.

Sources: Texas Business and Commerce Code, Chapter 542; SB 2610 enrolled text; SB 2610 bill history; Texas Business and Commerce Code, Chapter 521.

This article is general information, not legal advice. Talk with your attorney about how SB 2610 applies to your organization.