HB 635 — Cybersecurity Standards and Liability
Last action — Died in State Affairs Committee
-
✓Introduced
-
2In Committee
-
3Passed House
-
4Passed Senate
-
5To Executive
-
6Enacted
This bill is in committee in the House. Introduced December 03, 2025. It must pass committee before a floor vote.
Next likely step: a committee vote, then a floor vote in the House.
Odds of enactment
Low chanceBased on the sponsor, cosponsors, and committee posture, this bill has a low chance of becoming law.
Upgrade to see the exact probability and what's driving it.
A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.
Prognosis
-
In Committee
Current position in the legislative process.
-
3 sponsors
1 primary, 2 co-sponsors signed on.
-
Single-party support
Sponsorship is currently within one party (2 R).
-
Cleared a recorded vote
Passed 2 recorded votes so far.
Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.
Summary
Cybersecurity Standards and Liability; Prohibits local governments from imposing certain cybersecurity standards or processes on vendors; defines "vendor"; prohibits local governments from adopting or enforcing certain cybersecurity standards or processes; provides that local government, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to implement revised frameworks, standards, laws, or regulations.
Bill Text
What changed in the latest version
168 added · 183 removed168 line(s) added, 183 removed.
F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HBCS/HB 635 2026 A bill to be entitled An act relating to cybersecurity standards and liability;
authorizingprohibiting local governments tofrom onlyimposing adoptcertain specified cybersecurity standards;standards or processes on vendors;
prohibitingproviding thean Departmentexception; of Management Services from delegating the authority to set such standards to local governments;
requiring vendors to comply with specified cybersecurity standards;
providingprohibiting forlocal preemption;governments from adopting or enforcing certain cybersecurity standards or processes;
requiring covered entities and third-third-party party agents to implement revised frameworks, standards, laws, or regulations within a specified time period;
providing applicability;
providing a directive to the Division of Law Revision;
providing an effective date.
hb635-00hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HBCS/HB 635 2026 providingBe applicability;It Enacted by the Legislature of the State of Florida:
providing a directive to the Division of Law Revision;
providing an effective date.
Be It Enacted by the Legislature of the State of Florida:
SubsectionParagraph (a) of subsection (4) of section 282.3185, Florida Statutes, is amended to read:
A local government may only adopt cybersecurity standards Each local government shall adopt cybersecurity standards that safeguard its data, information technology, and information technology resources to ensure availability, confidentiality, and integrity.
The cybersecurity standards must be consistent with thegenerally standardsaccepted andbest processespractices establishedfor bycybersecurity, including the departmentNational throughInstitute theof FloridaStandards Digitaland ServiceTechnology pursuantCybersecurity toFramework. s.
282.318 generally accepted best practices for cybersecurity, including the National Institute of Standards and Technology Cybersecurity Framework.
The department may not delegate the authority to set cybersecurity standards to a local government.
UnlessA otherwiselocal requiredgovernment bymay statenot orimpose federalcybersecurity lawsstandards or regulations,processes on a vendor shallthat complyexceed withthe cybersecurity standards consistentor withprocesses theestablished standardsunder andthis processesparagraph, establishedexcept byas Thenecessary Nationalto Institutecomply ofwith Standardsstate andor Technologyfederal (NIST)laws, Cybersecurityor Frameworkwith 2.0.industry-specific requirements applicable to regulated sectors.
For purposes of this subparagraph,paragraph, Pagethe 2term of"vendor" 7means CODING:a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that contracts with a local government to provide information technology commodities or services.
3.
A local government may not adopt or enforce any Page 2 of 7 CODING:
hb635-00hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HBCS/HB 635 2026 "vendor"cybersecurity meansstandards aor soleprocesses proprietorship,that partnership,are corporation,inconsistent trust,with estate,this cooperative,paragraph association,for contracts entered into or otheramended commercialon entity.or after July 1, 2026.
(b) This subsection preempts any prior cybersecurity standards or processes adopted by a local government that are inconsistent with this subsection Each county with a population of 75,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each county with a population of less than 75,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(c) Each municipality with a population of 25,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each municipality with a population of less than 25,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(d) Each local government shall notify the Florida Digital Service of its compliance with this subsection as soon as possible.
(a) "Covered entity" means a sole proprietorship, partnership, corporation, trust, estate, cooperative, Pageassociation, 3or ofother 7commercial CODING:entity.
Words stricken are deletions;
words underlined are additions.
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 association, or other commercial entity.
8.Page 3 of 7 CODING:
Words stricken are deletions;
words underlined are additions.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 8.
(f) "Third-party agent" means an entity that has been Pagecontracted 4to maintain, store, or process personal information on behalf of 7a CODING:covered entity.
Words stricken are deletions;
words underlined are additions.
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 contracted to maintain, store, or process personal information on behalf of a covered entity.
Show all 57 changed lines (17 more)
501.171(3)-(6), as applicable.Page 4 of 7 CODING:
Words stricken are deletions;
words underlined are additions.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 applicable.
If regulated by the state or Federal Government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, a cybersecurity program that substantially complies with the current version of such laws and Pageregulations, 5as ofapplicable: 7 CODING:
Words stricken are deletions;
words underlined are additions.
hb635-00 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HB 635 2026 regulations, as applicable:
(4) A covered entity's or third-party agent's cybersecurityPage program's5 compliance with paragraph (3)(b) may be demonstrated by providing documentation or other evidence of an7 assessment,CODING: conducted internally or by a third-party, reflecting that the covered entity's or third-party agent's cybersecurity program has implemented the requirements of that paragraph.
(5) Any covered entity or third-party agent must update its cybersecurity program to incorporate any revisions of relevant frameworks or standards or of applicable state or federal laws or regulations within 1 year after the latest publication date stated in any such revisions in order to retain Page 6 of 7 CODING:
hb635-00hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S HBCS/HB 635 2026 protectioncybersecurity fromprogram's liability.compliance with paragraph (3)(b) may be demonstrated by providing documentation or other evidence of an assessment, conducted internally or by a third-party, reflecting that the covered entity's or third-party agent's cybersecurity program has implemented the requirements of that paragraph.
(5) Any covered entity or third-party agent must update its cybersecurity program to incorporate any revisions of relevant frameworks or standards or of applicable state or federal laws or regulations within 1 year after the latest publication date stated in any such revisions in order to retain protection from liability.
(8) In a civil action relating to a cybersecurity incident, if the defendant is a local government covered by subsection (2) or a covered entity or third-party agent covered by subsection (3), the defendant has the burden of proof to establishPage substantial6 complianceof with7 thisCODING: section.
Words stricken are deletions;
words underlined are additions.
hb635-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB 635 2026 establish substantial compliance with this section.
hb635-00hb635-01-c1
Show all 57 changed rows (17 more)
View plain text versions (2)
- H 635 c1 View text Current pdf
- Introduced H 635 Filed pdf
Action History
-
Died in State Affairs Committee
-
Now in State Affairs Committee
-
Reported out of Civil Justice & Claims Subcommittee
-
Favorable by Civil Justice & Claims Subcommittee
-
Added to Civil Justice & Claims Subcommittee agenda
-
1st Reading (Committee Substitute 1)
-
Now in Civil Justice & Claims Subcommittee
-
Referred to State Affairs Committee
-
Referred to Civil Justice & Claims Subcommittee
-
CS Filed
-
Laid on Table under Rule 7.18(a)
-
Reported out of Information Technology Budget & Policy Subcommittee
-
Favorable with CS by Information Technology Budget & Policy Subcommittee
-
Added to Information Technology Budget & Policy Subcommittee agenda
-
1st Reading (Original Filed Version)
-
Now in Information Technology Budget & Policy Subcommittee
-
Referred to State Affairs Committee
-
Referred to Civil Justice & Claims Subcommittee
-
Referred to Information Technology Budget & Policy Subcommittee
-
Filed
Sponsors
- Information Technology Budget & Policy Subcommittee · Primary
- Omar Blanco · Cosponsor
- Mike Giallombardo · Cosponsor
Sponsorship breakdown
Export CSV (upgrade) →1 sponsors · 2 co-sponsors · 161 not signed on
Sponsors (1)
- Information Technology Budget & Policy Subcommittee
Co-sponsors (2)
- Blanco, Omar Republican
- Giallombardo, Mike Republican
Not signed on (161)
161 members have not signed on to this bill.
Show all 161 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Votes
Roll call published as PDF — view source.
Roll call published as PDF — view source.
Subjects
Frequently asked questions
- What does HB 635 do?
- Cybersecurity Standards and Liability; Prohibits local governments from imposing certain cybersecurity standards or processes on vendors; defines "vendor"; prohibits local governments from adopting or enforcing certain cybersecurity standards or processes; provides that local government, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to implement revised frameworks, standards, laws, or regulations.
- Who sponsors HB 635?
- HB 635 is sponsored by Information Technology Budget & Policy Subcommittee, Blanco, Omar (Republican), and Giallombardo, Mike (Republican).
- What is the current status of HB 635?
- This bill is in committee in the House. Introduced December 03, 2025. It must pass committee before a floor vote.
- Where can I track HB 635?
- Track HB 635 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HB 635
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HB 635
Last checked for changes 2 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →