SB 692 — Cybersecurity Standards and Liability
Last action — Died in Appropriations
-
1Introduced
-
2In Committee
-
3Passed Senate
-
4Passed House
-
5To Executive
-
6Enacted
This bill has been introduced in the Senate. Introduced December 02, 2025. It must pass committee before a floor vote.
Next likely step: a committee referral and hearing.
Prognosis
-
Introduced
Current position in the legislative process.
-
1 sponsor
1 primary, 0 co-sponsors signed on.
-
Single-party support
Sponsorship is currently within one party (1 R).
-
Cleared a recorded vote
Passed 3 recorded votes so far.
Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.
Summary
Cybersecurity Standards and Liability; Prohibiting local governments from imposing certain cybersecurity standards or processes on vendors; providing that a local government, a covered entity, or a third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident under certain circumstances; requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability, etc.
Bill Text
What changed in the latest version
176 added · 195 removed176 line(s) added, 195 removed.
Florida Senate - 2026 CS for SB 692 By Senatorthe LeekCommittee 7-00972-26on 2026692__Governmental AOversight bill to be entitled An act relating to cybersecurity standards and liability;Accountability;
and Senator Leek 585-02205-26 2026692c1 A bill to be entitled An act relating to cybersecurity standards and liability;
authorizingprohibiting local governments tofrom onlyimposing adoptcertain specified cybersecurity standards;standards or processes on vendors;
prohibiting the Department of Management Services from delegating the authority to set such standards to local governments;
requiring vendors to comply with specified cybersecurity standards unless otherwise required by state or federal law or regulation;
providingprohibiting forlocal preemption;governments from adopting or enforcing certain cybersecurity standards or processes;
requiring covered entities and third-third-party party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability;
PageBe 1It Enacted by the Legislature of 7the CODING:State of Florida:
Page 1 of 6 CODING:
Florida Senate - 2026 CS for SB 692 7-00972-26585-02205-26 2026692__2026692c1 BeSection It1. Enacted by the Legislature of the State of Florida:
SectionParagraph 1.(a) of subsection (4) of section 282.3185, Florida Statutes, is amended to read:
Subsection (4) of section 282.3185, Florida Statutes, is amended to read:
A local government may only adopt cybersecurity standards that are Each local government shall adopt cybersecurity standards that safeguard its data, information technology, and information technology resources to ensure availability, confidentiality, and integrity.
The cybersecurity standards must be consistent with thegenerally standardsaccepted andbest processespractices establishedfor bycybersecurity, including the departmentNational throughInstitute theof FloridaStandards Digitaland ServiceTechnology pursuantCybersecurity toFramework. s.
282.318 generally accepted best practices for cybersecurity, including the National Institute of Standards and Technology Cybersecurity Framework.
The department may not delegate the authority to set cybersecurity standards to a local government.
UnlessA otherwiselocal requiredgovernment bymay statenot orimpose federalcybersecurity lawsstandards or regulations,processes on a vendor mustwhich complyexceed withthe cybersecurity standards thator areprocesses consistentestablished withunder thethis standardsparagraph, andexcept processesas establishednecessary byto thecomply Nationalwith Institutestate ofor Standardsfederal andlaws, Technologyor (NIST)with Cybersecurityindustry-specific Frameworkrequirements 2.0.applicable to regulated sectors.
For purposes of this subparagraph,paragraph, “vendor” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity.entity that contracts with a local government to provide information technology commodities or services.
(b)3. This subsection preempts any prior cybersecurity standards or processes adopted by a local government which are Page 2 of 7 CODING:
WordsA strickenlocal government may not adopt or enforce any cybersecurity standards or processes that are deletions;inconsistent with this paragraph for contracts entered into or amended on or after July 1, 2026.
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ inconsistent with this subsection Each county with a population of 75,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each county with a population of less than 75,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(c) Each municipality with a population of 25,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each municipality with a population of less than 25,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(d) Each local government shall notify the Florida Digital Service of its compliance with this subsection as soon as possible.
768.401 Limitation on liability for cybersecurity incidents.— (1)Page As2 usedof in6 thisCODING: section, the term:
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 (1) As used in this section, the term:
Page5. 3 of 7 CODING:
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ 5.
(f) “Third-party agent” means an entity that has been contracted to maintain, store, or process personal information onPage behalf3 of a6 coveredCODING: entity.
(2) A local government is not liable in connection with a cybersecurity incident if the local government has implemented one or more policies that substantially comply with cybersecurity standards or align with cybersecurity frameworks, disaster recovery plans for cybersecurity incidents, and multi- factor authentication.
(3) A covered entity or a third-party agent that acquires, maintains, stores, processes, or uses personal information has a presumption against liability in a class action resulting from a cybersecurity incident if the covered entity or the third-party agent has a cybersecurity program that does all of the Page 4 of 7 CODING:
Florida Senate - 2026 CS for SB 692 7-00972-26585-02205-26 2026692__2026692c1 following,on asbehalf applicable:of a covered entity.
(2) A local government is not liable in connection with a cybersecurity incident if the local government has implemented one or more policies that substantially comply with cybersecurity standards or align with cybersecurity frameworks, disaster recovery plans for cybersecurity incidents, and multi- factor authentication.
(3) A covered entity or a third-party agent that acquires, maintains, stores, processes, or uses personal information has a presumption against liability in a class action resulting from a cybersecurity incident if the covered entity or the third-party agent has a cybersecurity program that does all of the following, as applicable:
Show all 57 changed lines (17 more)
No.Page 4 of 6 CODING:
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 No.
(4) A covered entity’s or a third-party agent’s cybersecurity program’s compliance with paragraph (3)(b) may be demonstrated by providing documentation or other evidence of an Pageassessment, 5conducted internally or by a third-party, reflecting that the covered entity’s or third-party agent’s cybersecurity program has implemented the requirements of 7that CODING:paragraph.
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ assessment, conducted internally or by a third-party, reflecting that the covered entity’s or third-party agent’s cybersecurity program has implemented the requirements of that paragraph.
(7) If a civil action is filed against a local government, a covered entity, or a third-party agent that failed to implement a cybersecurity program in compliance with this section, the fact that such defendant could have obtained a liability shield or presumption against liability upon compliance is not admissible as evidence of negligence, does not constitutePage negligence5 per se, and may not be used as evidence of fault6 underCODING: any other theory of liability.
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 constitute negligence per se, and may not be used as evidence of fault under any other theory of liability.
PageSection 64. of 7 CODING:
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ Section 4.
Page 76 of 76 CODING:
Show all 57 changed rows (17 more)
View plain text versions (2)
- S 692 c1 View text Current pdf
- Introduced S 692 Filed pdf
Action History
-
Died in Appropriations
-
Now in Appropriations
-
Favorable by Judiciary; YEAS 9 NAYS 2
-
On Committee agenda-- Judiciary, 02/10/26, 12:00 pm, 110 Senate Building
-
CS by Governmental Oversight and Accountability read 1st time
-
Now in Judiciary
-
Pending reference review under Rule 4.7(2) - (Committee Substitute)
-
CS by Governmental Oversight and Accountability; YEAS 5 NAYS 4
-
On Committee agenda-- Governmental Oversight and Accountability, 01/26/26, 3:30 pm, 110 Senate Building
-
Introduced
-
Referred to Governmental Oversight and Accountability; Judiciary; Appropriations
-
Filed
Sponsors
- Thomas J. "Tom" Leek · Primary
Sponsorship breakdown
Export CSV (upgrade) →1 sponsors · 0 co-sponsors · 163 not signed on · 4 voted No
Sponsors (1)
- Leek, Thomas J. "Tom" Republican
Co-sponsors (0)
None.
Not signed on (163)
163 members have not signed on to this bill.
Show all 163 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Votes
Roll call published as PDF — view source.
Roll call published as PDF — view source.
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Republican | 5 | 1 | 0 | 0 |
| Democrat | 0 | 3 | 0 | 0 |
| Total | 5 | 4 | 0 | 0 |
| % of votes cast | 56% | 44% | 0% | 0% |
How each member voted (9)
| Member | Party | Vote |
|---|---|---|
| Arrington, Kristen Aston | Democrat | Nay |
| Bracy Davis, LaVon | Democrat | Nay |
| Polsky, Tina Scott | Democrat | Nay |
| Brodeur, Jason | Republican | Yea |
| DiCeglie, Nick | Republican | Yea |
| Grall, Erin | Republican | Nay |
| Mayfield, Debbie | Republican | Yea |
| McClain, Stan | Republican | Yea |
| Rodriguez, Ana Maria | Republican | Yea |
Subjects
Frequently asked questions
- What does SB 692 do?
- Cybersecurity Standards and Liability; Prohibiting local governments from imposing certain cybersecurity standards or processes on vendors; providing that a local government, a covered entity, or a third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident under certain circumstances; requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability, etc.
- Who sponsors SB 692?
- SB 692 is sponsored by Leek, Thomas J. "Tom" (Republican).
- What is the current status of SB 692?
- This bill has been introduced in the Senate. Introduced December 02, 2025. It must pass committee before a floor vote.
- Where can I track SB 692?
- Track SB 692 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on SB 692
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of SB 692
Last checked for changes 2 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →