SB 2610 offers Texas businesses a legal "safe harbor" if they adopt and maintain a cybersecurity program aligned with an industry-recognized framework (like CIS or NIST).
To qualify, your program must match the scale and complexity of your business—and be updated within 12 months of any changes to the framework.
Password Policy
MFA
Employee Training
Antivirus
Firewall Protection
Written Cybersecurity Policies
All of the above plus
CIS Controls (IG1)
Asset Inventory
Incident Response
Email Filtering
Backups
All of the above plus
Full Framework Alignment (CIS, NIST, or ISO)
Encryption
IAM
SIEM/logging
vCSO support
Take our free 3-minute quiz to assess your cybersecurity readiness and find the right action plan for your business size.
Whether you're just starting or need a quick policy refresh, we’ll guide you step-by-step.
Take the Quiz. Download the Checklist. Book a Free Compliance Consult.
Disclaimer: This content is provided for general informational purposes only and does not constitute legal advice. While adopting and maintaining a cybersecurity program aligned with recognized frameworks may help your business potentially qualify for the safe-harbor protection under Texas SB 2610—effective September 1, 2025—HCS makes no guarantees of legal immunity. Requirements may change, and applicability depends on your specific facts and documentation. Please consult qualified counsel to tailor your cybersecurity measures and ensure full compliance.