Florida 2026 Session Status: Introduced 1 R cosponsors

SB 692 — Cybersecurity Standards and Liability

Last action — Died in Appropriations

  1. 1
    Introduced
  2. 2
    In Committee
  3. 3
    Passed Senate
  4. 4
    Passed House
  5. 5
    To Executive
  6. 6
    Enacted

This bill has been introduced in the Senate. Introduced December 02, 2025. It must pass committee before a floor vote.

Next likely step: a committee referral and hearing.

Prognosis

Stalled 28% · moderate confidence
  • Introduced

    Current position in the legislative process.

  • 1 sponsor

    1 primary, 0 co-sponsors signed on.

  • Single-party support

    Sponsorship is currently within one party (1 R).

  • Cleared a recorded vote

    Passed 3 recorded votes so far.

Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.

Summary

Cybersecurity Standards and Liability; Prohibiting local governments from imposing certain cybersecurity standards or processes on vendors; providing that a local government, a covered entity, or a third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident under certain circumstances; requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability, etc.

Bill Text

What changed in the latest version

176 added · 195 removed

176 line(s) added, 195 removed.

→
Previous
Latest
Florida Senate - 2026 SB 692 By Senator Leek 7-00972-26 2026692__ A bill to be entitled An act relating to cybersecurity standards and liability;
Florida Senate - 2026 CS for SB 692 By the Committee on Governmental Oversight and Accountability;
and Senator Leek 585-02205-26 2026692c1 A bill to be entitled An act relating to cybersecurity standards and liability;
authorizing local governments to only adopt specified cybersecurity standards;
prohibiting local governments from imposing certain cybersecurity standards or processes on vendors;
prohibiting the Department of Management Services from delegating the authority to set such standards to local governments;
requiring vendors to comply with specified cybersecurity standards unless otherwise required by state or federal law or regulation;
providing for preemption;
prohibiting local governments from adopting or enforcing certain cybersecurity standards or processes;
requiring covered entities and third- party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability;
requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability;
Page 1 of 7 CODING:
Be It Enacted by the Legislature of the State of Florida:
Page 1 of 6 CODING:
Florida Senate - 2026 SB 692 7-00972-26 2026692__ Be It Enacted by the Legislature of the State of Florida:
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 Section 1.
Section 1.
Paragraph (a) of subsection (4) of section 282.3185, Florida Statutes, is amended to read:
Subsection (4) of section 282.3185, Florida Statutes, is amended to read:
A local government may only adopt cybersecurity standards that are Each local government shall adopt cybersecurity standards that safeguard its data, information technology, and information technology resources to ensure availability, confidentiality, and integrity.
Each local government shall adopt cybersecurity standards that safeguard its data, information technology, and information technology resources to ensure availability, confidentiality, and integrity.
The cybersecurity standards must be consistent with the standards and processes established by the department through the Florida Digital Service pursuant to s.
The cybersecurity standards must be consistent with generally accepted best practices for cybersecurity, including the National Institute of Standards and Technology Cybersecurity Framework.
282.318 generally accepted best practices for cybersecurity, including the National Institute of Standards and Technology Cybersecurity Framework.
The department may not delegate the authority to set cybersecurity standards to a local government.
Unless otherwise required by state or federal laws or regulations, a vendor must comply with cybersecurity standards that are consistent with the standards and processes established by the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0.
A local government may not impose cybersecurity standards or processes on a vendor which exceed the standards or processes established under this paragraph, except as necessary to comply with state or federal laws, or with industry-specific requirements applicable to regulated sectors.
For purposes of this subparagraph, “vendor” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity.
For purposes of this paragraph, “vendor” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that contracts with a local government to provide information technology commodities or services.
(b) This subsection preempts any prior cybersecurity standards or processes adopted by a local government which are Page 2 of 7 CODING:
3.
Words stricken are deletions;
A local government may not adopt or enforce any cybersecurity standards or processes that are inconsistent with this paragraph for contracts entered into or amended on or after July 1, 2026.
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ inconsistent with this subsection Each county with a population of 75,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each county with a population of less than 75,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(c) Each municipality with a population of 25,000 or more must adopt the cybersecurity standards required by this subsection by January 1, 2024.
Each municipality with a population of less than 25,000 must adopt the cybersecurity standards required by this subsection by January 1, 2025.
(d) Each local government shall notify the Florida Digital Service of its compliance with this subsection as soon as possible.
768.401 Limitation on liability for cybersecurity incidents.— (1) As used in this section, the term:
768.401 Limitation on liability for cybersecurity incidents.— Page 2 of 6 CODING:
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 (1) As used in this section, the term:
Page 3 of 7 CODING:
5.
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ 5.
(f) “Third-party agent” means an entity that has been contracted to maintain, store, or process personal information on behalf of a covered entity.
(f) “Third-party agent” means an entity that has been contracted to maintain, store, or process personal information Page 3 of 6 CODING:
(2) A local government is not liable in connection with a cybersecurity incident if the local government has implemented one or more policies that substantially comply with cybersecurity standards or align with cybersecurity frameworks, disaster recovery plans for cybersecurity incidents, and multi- factor authentication.
(3) A covered entity or a third-party agent that acquires, maintains, stores, processes, or uses personal information has a presumption against liability in a class action resulting from a cybersecurity incident if the covered entity or the third-party agent has a cybersecurity program that does all of the Page 4 of 7 CODING:
Florida Senate - 2026 SB 692 7-00972-26 2026692__ following, as applicable:
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 on behalf of a covered entity.
(2) A local government is not liable in connection with a cybersecurity incident if the local government has implemented one or more policies that substantially comply with cybersecurity standards or align with cybersecurity frameworks, disaster recovery plans for cybersecurity incidents, and multi- factor authentication.
(3) A covered entity or a third-party agent that acquires, maintains, stores, processes, or uses personal information has a presumption against liability in a class action resulting from a cybersecurity incident if the covered entity or the third-party agent has a cybersecurity program that does all of the following, as applicable:
Show all 57 changed rows (17 more)
Previous
Latest
No.
Page 4 of 6 CODING:
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 No.
(4) A covered entity’s or a third-party agent’s cybersecurity program’s compliance with paragraph (3)(b) may be demonstrated by providing documentation or other evidence of an Page 5 of 7 CODING:
(4) A covered entity’s or a third-party agent’s cybersecurity program’s compliance with paragraph (3)(b) may be demonstrated by providing documentation or other evidence of an assessment, conducted internally or by a third-party, reflecting that the covered entity’s or third-party agent’s cybersecurity program has implemented the requirements of that paragraph.
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ assessment, conducted internally or by a third-party, reflecting that the covered entity’s or third-party agent’s cybersecurity program has implemented the requirements of that paragraph.
(7) If a civil action is filed against a local government, a covered entity, or a third-party agent that failed to implement a cybersecurity program in compliance with this section, the fact that such defendant could have obtained a liability shield or presumption against liability upon compliance is not admissible as evidence of negligence, does not constitute negligence per se, and may not be used as evidence of fault under any other theory of liability.
(7) If a civil action is filed against a local government, a covered entity, or a third-party agent that failed to implement a cybersecurity program in compliance with this section, the fact that such defendant could have obtained a liability shield or presumption against liability upon compliance is not admissible as evidence of negligence, does not Page 5 of 6 CODING:
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 CS for SB 692 585-02205-26 2026692c1 constitute negligence per se, and may not be used as evidence of fault under any other theory of liability.
Page 6 of 7 CODING:
Section 4.
Words stricken are deletions;
words underlined are additions.
Florida Senate - 2026 SB 692 7-00972-26 2026692__ Section 4.
Page 7 of 7 CODING:
Page 6 of 6 CODING:
View plain text versions (2)

Action History

  1. Died in Appropriations

  2. Now in Appropriations

  3. Favorable by Judiciary; YEAS 9 NAYS 2

  4. On Committee agenda-- Judiciary, 02/10/26, 12:00 pm, 110 Senate Building

  5. CS by Governmental Oversight and Accountability read 1st time

  6. Now in Judiciary

  7. Pending reference review under Rule 4.7(2) - (Committee Substitute)

  8. CS by Governmental Oversight and Accountability; YEAS 5 NAYS 4

  9. On Committee agenda-- Governmental Oversight and Accountability, 01/26/26, 3:30 pm, 110 Senate Building

  10. Introduced

  11. Referred to Governmental Oversight and Accountability; Judiciary; Appropriations

  12. Filed

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

1 sponsors · 0 co-sponsors · 163 not signed on · 4 voted No

Sponsors (1)

Co-sponsors (0)

None.

Not signed on (163)

163 members have not signed on to this bill.

Show all 163 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Votes

Passed 5 Yea · 4 Nay
Party YeaNayPresentNot Voting
Republican 5100
Democrat 0300
Total 5400
% of votes cast 56%44%0%0%
How each member voted (9)
Member Party Vote
Arrington, Kristen Aston Democrat Nay
Bracy Davis, LaVon Democrat Nay
Polsky, Tina Scott Democrat Nay
Brodeur, Jason Republican Yea
DiCeglie, Nick Republican Yea
Grall, Erin Republican Nay
Mayfield, Debbie Republican Yea
McClain, Stan Republican Yea
Rodriguez, Ana Maria Republican Yea

Official roll call →

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

What does SB 692 do?
Cybersecurity Standards and Liability; Prohibiting local governments from imposing certain cybersecurity standards or processes on vendors; providing that a local government, a covered entity, or a third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident under certain circumstances; requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability, etc.
Who sponsors SB 692?
SB 692 is sponsored by Leek, Thomas J. "Tom" (Republican).
What is the current status of SB 692?
This bill has been introduced in the Senate. Introduced December 02, 2025. It must pass committee before a floor vote.
Where can I track SB 692?
Track SB 692 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on SB 692

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of SB 692

Last checked for changes 2 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →