Florida 2026 Session Status: In Committee 2 R cosponsors

HB 635 — Cybersecurity Standards and Liability

Last action — Died in State Affairs Committee

  1. ✓
    Introduced
  2. 2
    In Committee
  3. 3
    Passed House
  4. 4
    Passed Senate
  5. 5
    To Executive
  6. 6
    Enacted

This bill is in committee in the House. Introduced December 03, 2025. It must pass committee before a floor vote.

Next likely step: a committee vote, then a floor vote in the House.

Odds of enactment

Low chance

Based on the sponsor, cosponsors, and committee posture, this bill has a low chance of becoming law.

Upgrade to see the exact probability and what's driving it.

A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.

Prognosis

Advancing 40% · moderate confidence
  • In Committee

    Current position in the legislative process.

  • 3 sponsors

    1 primary, 2 co-sponsors signed on.

  • Single-party support

    Sponsorship is currently within one party (2 R).

  • Cleared a recorded vote

    Passed 2 recorded votes so far.

Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.

Summary

Cybersecurity Standards and Liability; Prohibits local governments from imposing certain cybersecurity standards or processes on vendors; defines "vendor"; prohibits local governments from adopting or enforcing certain cybersecurity standards or processes; provides that local government, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to implement revised frameworks, standards, laws, or regulations.

Bill Text

What changed in the latest version

168 added · 183 removed

168 line(s) added, 183 removed.

→
Previous
Latest
F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 A bill to be entitled An act relating to cybersecurity standards and liability;
F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 A bill to be entitled An act relating to cybersecurity standards and liability;
authorizing local governments to only adopt specified cybersecurity standards;
prohibiting local governments from imposing certain cybersecurity standards or processes on vendors;
prohibiting the Department of Management Services from delegating the authority to set such standards to local governments;
providing an exception;
requiring vendors to comply with specified cybersecurity standards;
providing for preemption;
prohibiting local governments from adopting or enforcing certain cybersecurity standards or processes;
requiring covered entities and third- party agents to implement revised frameworks, standards, laws, or regulations within a specified time period;
requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified time period;
providing applicability;
providing a directive to the Division of Law Revision;
providing an effective date.
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 providing applicability;
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 Be It Enacted by the Legislature of the State of Florida:
providing a directive to the Division of Law Revision;
providing an effective date.
Be It Enacted by the Legislature of the State of Florida:
Subsection (4) of section 282.3185, Florida Statutes, is amended to read:
Paragraph (a) of subsection (4) of section 282.3185, Florida Statutes, is amended to read:
A local government may only adopt cybersecurity standards Each local government shall adopt cybersecurity standards that safeguard its data, information technology, and information technology resources to ensure availability, confidentiality, and integrity.
Each local government shall adopt cybersecurity standards that safeguard its data, information technology, and information technology resources to ensure availability, confidentiality, and integrity.
The cybersecurity standards must be consistent with the standards and processes established by the department through the Florida Digital Service pursuant to s.
The cybersecurity standards must be consistent with generally accepted best practices for cybersecurity, including the National Institute of Standards and Technology Cybersecurity Framework.
282.318 generally accepted best practices for cybersecurity, including the National Institute of Standards and Technology Cybersecurity Framework.
The department may not delegate the authority to set cybersecurity standards to a local government.
Unless otherwise required by state or federal laws or regulations, a vendor shall comply with cybersecurity standards consistent with the standards and processes established by The National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0.
A local government may not impose cybersecurity standards or processes on a vendor that exceed the standards or processes established under this paragraph, except as necessary to comply with state or federal laws, or with industry-specific requirements applicable to regulated sectors.
For purposes of this subparagraph, Page 2 of 7 CODING:
For purposes of this paragraph, the term "vendor" means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that contracts with a local government to provide information technology commodities or services.
3.
A local government may not adopt or enforce any Page 2 of 7 CODING:
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 "vendor" means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 cybersecurity standards or processes that are inconsistent with this paragraph for contracts entered into or amended on or after July 1, 2026.
(b) This subsection preempts any prior cybersecurity standards or processes adopted by a local government that are inconsistent with this subsection Each county with a population of 75,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each county with a population of less than 75,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(c) Each municipality with a population of 25,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each municipality with a population of less than 25,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(d) Each local government shall notify the Florida Digital Service of its compliance with this subsection as soon as possible.
(a) "Covered entity" means a sole proprietorship, partnership, corporation, trust, estate, cooperative, Page 3 of 7 CODING:
(a) "Covered entity" means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity.
Words stricken are deletions;
words underlined are additions.
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 association, or other commercial entity.
8.
Page 3 of 7 CODING:
Words stricken are deletions;
words underlined are additions.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 8.
(f) "Third-party agent" means an entity that has been Page 4 of 7 CODING:
(f) "Third-party agent" means an entity that has been contracted to maintain, store, or process personal information on behalf of a covered entity.
Words stricken are deletions;
words underlined are additions.
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 contracted to maintain, store, or process personal information on behalf of a covered entity.
Show all 57 changed rows (17 more)
Previous
Latest
501.171(3)-(6), as applicable.
501.171(3)-(6), as Page 4 of 7 CODING:
Words stricken are deletions;
words underlined are additions.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 applicable.
If regulated by the state or Federal Government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, a cybersecurity program that substantially complies with the current version of such laws and Page 5 of 7 CODING:
If regulated by the state or Federal Government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, a cybersecurity program that substantially complies with the current version of such laws and regulations, as applicable:
Words stricken are deletions;
words underlined are additions.
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 regulations, as applicable:
(4) A covered entity's or third-party agent's cybersecurity program's compliance with paragraph (3)(b) may be demonstrated by providing documentation or other evidence of an assessment, conducted internally or by a third-party, reflecting that the covered entity's or third-party agent's cybersecurity program has implemented the requirements of that paragraph.
(4) A covered entity's or third-party agent's Page 5 of 7 CODING:
(5) Any covered entity or third-party agent must update its cybersecurity program to incorporate any revisions of relevant frameworks or standards or of applicable state or federal laws or regulations within 1 year after the latest publication date stated in any such revisions in order to retain Page 6 of 7 CODING:
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 protection from liability.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 cybersecurity program's compliance with paragraph (3)(b) may be demonstrated by providing documentation or other evidence of an assessment, conducted internally or by a third-party, reflecting that the covered entity's or third-party agent's cybersecurity program has implemented the requirements of that paragraph.
(5) Any covered entity or third-party agent must update its cybersecurity program to incorporate any revisions of relevant frameworks or standards or of applicable state or federal laws or regulations within 1 year after the latest publication date stated in any such revisions in order to retain protection from liability.
(8) In a civil action relating to a cybersecurity incident, if the defendant is a local government covered by subsection (2) or a covered entity or third-party agent covered by subsection (3), the defendant has the burden of proof to establish substantial compliance with this section.
(8) In a civil action relating to a cybersecurity incident, if the defendant is a local government covered by subsection (2) or a covered entity or third-party agent covered by subsection (3), the defendant has the burden of proof to Page 6 of 7 CODING:
Words stricken are deletions;
words underlined are additions.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 establish substantial compliance with this section.
hb635-00
hb635-01-c1
View plain text versions (2)

Action History

  1. Died in State Affairs Committee

  2. Now in State Affairs Committee

  3. Reported out of Civil Justice & Claims Subcommittee

  4. Favorable by Civil Justice & Claims Subcommittee

  5. Added to Civil Justice & Claims Subcommittee agenda

  6. 1st Reading (Committee Substitute 1)

  7. Now in Civil Justice & Claims Subcommittee

  8. Referred to State Affairs Committee

  9. Referred to Civil Justice & Claims Subcommittee

  10. CS Filed

  11. Laid on Table under Rule 7.18(a)

  12. Reported out of Information Technology Budget & Policy Subcommittee

  13. Favorable with CS by Information Technology Budget & Policy Subcommittee

  14. Added to Information Technology Budget & Policy Subcommittee agenda

  15. 1st Reading (Original Filed Version)

  16. Now in Information Technology Budget & Policy Subcommittee

  17. Referred to State Affairs Committee

  18. Referred to Civil Justice & Claims Subcommittee

  19. Referred to Information Technology Budget & Policy Subcommittee

  20. Filed

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

1 sponsors · 2 co-sponsors · 161 not signed on

Sponsors (1)

  • Information Technology Budget & Policy Subcommittee

Co-sponsors (2)

Not signed on (161)

161 members have not signed on to this bill.

Show all 161 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Votes

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

What does HB 635 do?
Cybersecurity Standards and Liability; Prohibits local governments from imposing certain cybersecurity standards or processes on vendors; defines "vendor"; prohibits local governments from adopting or enforcing certain cybersecurity standards or processes; provides that local government, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to implement revised frameworks, standards, laws, or regulations.
Who sponsors HB 635?
HB 635 is sponsored by Information Technology Budget & Policy Subcommittee, Blanco, Omar (Republican), and Giallombardo, Mike (Republican).
What is the current status of HB 635?
This bill is in committee in the House. Introduced December 03, 2025. It must pass committee before a floor vote.
Where can I track HB 635?
Track HB 635 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HB 635

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HB 635

Last checked for changes 2 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →