Texas SB 2610 Cybersecurity Safe Harbor: What It Means for Your Organization

If your organization operates in Texas, has fewer than 250 employees and owns or licenses computerized data that includes sensitive personal information, SB 2610 gives you a reason to formalize your cybersecurity program. If you meet the program requirements at the time of a data breach, a person suing you over that breach cannot recover exemplary (punitive) damages. The law is voluntary, and ALCON DTS helps you build, run and document the program it describes.

Book a readiness reviewSee what the law requires

At a glance

  • Law: Texas Senate Bill 2610, 89th Legislature, Regular Session (Acts 2025, Ch. 1029)
  • Passed by: the Texas Legislature. Signed by the governor on June 20, 2025.
  • Code citation: Texas Business and Commerce Code, Chapter 542 (Cybersecurity Program), Sections 542.001 to 542.005
  • Effective: September 1, 2025. Applies only to a cause of action that accrues on or after that date.
  • Type: Voluntary safe harbor. No new mandate, no penalties, no filing or registration. No state agency enforces Chapter 542; it is a defense you raise in court.
  • Who can use it: Business entities in Texas with fewer than 250 employees that own or license computerized sensitive personal information
  • What it protects against: Exemplary damages in a lawsuit arising from a breach of system security
  • Official text: Texas Business and Commerce Code, Chapter 542
  • Last reviewed: September 30, 2026

What is SB 2610?

SB 2610 is a Texas law passed by the Texas Legislature in its 89th Regular Session. It added Chapter 542, “Cybersecurity Program,” to the Texas Business and Commerce Code, effective September 1, 2025.

What changed: SB 2610 created a specific defense tied to your cybersecurity program. If you qualify and you can show that, at the time of the breach, you had implemented and maintained a program that meets Sec. 542.004, a person harmed by the breach may not recover exemplary damages from you (Sec. 542.003).

SB 2610 does not order you to do anything. There is no regulator, no registration and no penalty under Chapter 542. It sets out what your cybersecurity program must look like if you want the protection, and it works as a defense in a lawsuit.

What does the safe harbor cover, and what doesn’t it?

It covers: exemplary damages. In a lawsuit arising from a breach of system security, a person harmed by the breach may not recover exemplary damages from a qualifying business (Sec. 542.003). Texas law defines exemplary damages as damages awarded as a penalty or punishment, not as compensation, and the term includes punitive damages (Civil Practice and Remedies Code Sec. 41.001).

It does not:

  • Limit compensatory damages. The law addresses exemplary damages only.
  • Create a private cause of action (Sec. 542.005).
  • Change any existing common law or statutory duty (Sec. 542.005). Your breach notification duties and your duty to protect sensitive personal information stay the same.
  • Apply automatically. You must demonstrate that your program was in place and maintained at the time of the breach.

Does SB 2610 apply to you?

Chapter 542 applies only to a business entity in Texas that meets both tests (Sec. 542.002):

  1. It has fewer than 250 employees.
  2. It owns or licenses computerized data that includes sensitive personal information.

“Sensitive personal information” uses the Texas definition in Business and Commerce Code Sec. 521.002. In plain terms, it covers:

  • A person’s first name or first initial and last name, combined with a Social Security number, a driver’s license or government ID number, or a financial account or card number with the code needed to access it, when that data is not encrypted.
  • Information that identifies a person and relates to their physical or mental health, the health care they receive, or payment for that care.

If you keep employee records, patient information or customer payment details in computerized form, you very likely own or license sensitive personal information.

Quick check: is SB 2610 relevant to you?

  • You operate in Texas.
  • You have fewer than 250 employees.
  • You own or license computerized data that includes sensitive personal information (employee, patient, client or customer data).

If all three are true, the safe harbor is available to you, provided your cybersecurity program meets Sec. 542.004. Chapter 542 does not say how employees are counted. Talk with your attorney about how it applies to your staffing.

What do you need to have in place?

Every qualifying program must

  • Contain administrative, technical and physical safeguards for personal identifying information and sensitive personal information.
  • Conform to an industry-recognized cybersecurity framework (see the list below).
  • Be designed to protect the security of that information, protect against threats or hazards to its integrity, and protect against unauthorized access or acquisition that would create a material risk of identity theft or other fraud.

What scales with your size? (Sec. 542.004(a)(4))

Program requirements by employee count, Texas Business and Commerce Code Sec. 542.004(a)(4). Example starting points are general illustrations, not requirements of the law.
Employees What the law expects Example starting point
Fewer than 20 Simplified requirements, including password policies and appropriate employee cybersecurity training A written password policy with multifactor authentication, plus security awareness training for every employee with completion records
20 to 99 Moderate requirements, including the Center for Internet Security (CIS) Controls Implementation Group 1 A gap assessment against CIS Controls Implementation Group 1, then a documented plan to close each gap
100 to 249 Compliance with the requirements of Sec. 542.004(b): conformity with a current version of one or more listed frameworks, plus the current version of HIPAA, GLBA Title V, FISMA or HITECH if you are subject to them, and PCI DSS if it applies to you Choose a named framework that fits your industry, add any of those laws or PCI DSS that apply to you, assess against them and keep an evidence file that shows conformity

If you have close to 100 employees, you may be near the line between the second and third tiers. If you are growing past 100 employees, plan your framework now so your program keeps pace.

Which frameworks does the law name? (Sec. 542.004(b))

Your program conforms to an industry-recognized framework if it conforms to a current version of one, or any combination, of these:

  • NIST Framework for Improving Critical Infrastructure Cybersecurity (NIST Cybersecurity Framework)
  • NIST Special Publication 800-171
  • NIST Special Publications 800-53 and 800-53A
  • FedRAMP Security Assessment Framework
  • CIS Critical Security Controls for Effective Cyber Defense
  • ISO/IEC 27000-series information security standards
  • HITRUST Common Security Framework
  • Secure Controls Framework
  • SOC 2 (Service Organization Control Type 2 Framework)
  • Other similar frameworks or standards of the cybersecurity industry

Your program must also conform to the current version of these laws if your organization is subject to them:

  • HIPAA
  • Gramm-Leach-Bliley Act, Title V
  • Federal Information Security Modernization Act of 2014 (FISMA)
  • HITECH Act

And, if it applies to you, the current version of the Payment Card Industry Data Security Standard (PCI DSS).

How do you keep the program current? (Sec. 542.004(c))

Frameworks change. When a listed framework is updated, your program still qualifies as long as you update it to the new version by the later of:

  1. the implementation date published in the updated standard, or
  2. one year after the updated standard is published.

That means a steady review cycle matters. A program that met the framework two versions ago may not qualify later.

How can ALCON DTS help you?

You keep the compliance decisions. We can run the controls. We can keep them current and document how they work, so you have a clear record of your program when your attorney, insurer or auditor asks. Our services help you build and maintain a program aligned to the framework you choose. Whether the safe harbor applies to a specific claim is a legal question decided on the facts.

SB 2610 element What ALCON DTS provides
Framework conformity and documentation (542.004(a)(2), (b)) Compliance tracking against your chosen framework, with documented policies, procedures and an organized evidence file
Password policies (under 20 tier) Identity and access management, including multifactor authentication, enforced password policies and secure credential storage
Employee cybersecurity training (under 20 tier) Security awareness training with completion records
Technical safeguards: malware and endpoint defense Endpoint detection and response, application control and managed administrator rights
Technical safeguards: email threats Email security and filtering, plus email domain authentication (SPF, DKIM and DMARC)
Monitoring and detection Centralized logging, security monitoring and alerting across devices and cloud apps
Asset inventory and secure configuration (CIS IG1) Device management, managed patching and updates, and automated documentation of systems and configurations
Network safeguards Managed firewalls, switching and secure Wi-Fi
Integrity and recovery Tested backup and recovery
Staying current (542.004(c)) Regular, documented program reviews against the current framework version, with changes recorded in your evidence file

The exact controls in your environment depend on your ALCON DTS plan and any project work. We will show you which are in place today and which would close a gap.

Why work with ALCON DTS?

When you build a program you may one day need to show your attorney or insurer, you want a team that has done this work for years and documents it as it goes. Here is what you get with ALCON DTS.

  • More than two decades in Texas. ALCON DTS has served Central Texas organizations since 2001, from our headquarters in Austin.
  • A certified, specialized team. Our team holds a range of industry certifications, including certifications in implementing compliance frameworks, and works every day in cybersecurity, managed IT and regulatory compliance.
  • Experience in regulated work. We support healthcare organizations and clinics that protect patient information, manufacturers and engineering firms, and law and professional services firms.
  • Firsthand knowledge of the law. Eduardo Contreras led the effort to pass SB 2610, so we know the intent behind the law as well as its text.

ALCON DTS has earned awards and recognition from business and community organizations, a reflection of how we operate: plain answers, documented work and long-term relationships.

Ready to see where your program stands? We will compare your current controls with the SB 2610 tier that fits your headcount and show you what would close the gaps.

Book a readiness review

How does SB 2610 fit with other Texas and federal rules?

  • Texas breach notification law (Bus. and Com. Code Sec. 521.053). SB 2610 does not change breach notification. If a breach involves sensitive personal information, you must notify affected individuals without unreasonable delay and no later than 60 days after determining the breach occurred. If at least 250 Texas residents are involved, you must also notify the Texas Attorney General no later than 30 days after that determination. If you notify more than 10,000 people at one time, consumer reporting agencies must also be notified. The Texas Attorney General enforces Chapter 521 and may bring an action for civil penalties for violations of it (Sec. 521.151).
  • Texas duty to protect sensitive personal information (Sec. 521.052). Businesses must implement and maintain reasonable procedures to protect sensitive personal information and must securely destroy records they no longer keep. SB 2610 leaves this duty in place, and a framework-based program is a practical way to show reasonable procedures.
  • HIPAA and HITECH. If your organization is subject to HIPAA or HITECH, SB 2610 requires your program to conform to the current version of those laws as well. For healthcare and imaging organizations, the HIPAA Security Rule work you already do becomes part of your SB 2610 program.
  • Texas Data Privacy and Security Act (TDPSA, Bus. and Com. Code Ch. 541). TDPSA requires reasonable data security practices from businesses it covers. It does not apply to businesses that are small businesses under the U.S. Small Business Administration definition (with one exception for selling sensitive data), HIPAA covered entities and business associates, or nonprofit organizations (Sec. 541.002). If TDPSA does apply to you, a framework-based program supports both laws.
  • PCI DSS. If you accept payment cards and PCI DSS applies to you, SB 2610 expects your program to conform to its current version.

Frequently asked questions

No. It creates no new duty and no penalties. It offers a defense against exemplary damages to qualifying businesses that choose to maintain a conforming cybersecurity program.

No agency does. Chapter 542 is a defense a qualifying business can raise in a lawsuit arising from a breach. It creates no private cause of action and changes no existing duty (Sec. 542.005).

September 1, 2025. The governor signed it on June 20, 2025. The protection applies only to causes of action that accrue on or after September 1, 2025.

No. It bars exemplary (punitive) damages only. Compensatory damages, breach notification duties and regulatory enforcement under other laws are not changed by SB 2610.

The law names the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53 and 800-53A, FedRAMP, the CIS Critical Security Controls, ISO/IEC 27000-series, HITRUST CSF, the Secure Controls Framework and SOC 2, plus other similar industry frameworks. Businesses with 20 to 99 employees must include CIS Controls Implementation Group 1.

By the later of the implementation date published in the updated standard or one year after the updated standard is published.

Chapter 542 does not say how employees are counted. Talk with your attorney about how it applies to your staffing.

Chapter 542 applies only to businesses with fewer than 250 employees. A strong framework-based program is still good practice and supports your duties under other laws.

No one can promise that in advance. Whether the defense applies is decided on the facts of a specific case. We help you build, operate and document a program aligned to the law’s framework requirements so you have a clear record to show your attorney.

Sources

Last reviewed: September 30, 2026

This page is general information about Texas law, not legal advice for your situation.

Talk with ALCON DTS about your SB 2610 program

Want to know where your organization stands? We will review your current controls against the SB 2610 tier that fits your headcount, show you what is already in place, and give you a clear plan for the gaps.

Email: info@alcondts.com ยท Phone: 512-892-6900

Schedule my SB 2610 review