Does Texas SB 2610 protect your business after a data breach — and what cybersecurity requirements do you need to meet to qualify?
SB 2610 has been in effect since September 1, 2025. There’s no grace
period and no phase-in. The protection only applies if your cybersecurity
program already met the requirements at the moment a breach happened —
which means the time to qualify is before something goes wrong, not after.
Here’s what Texas business owners need to know and how to qualify for this protection.
Who Does This Law Apply To?
SB 2610 applies to businesses in Texas that:
- Have fewer than 250 employees
- Own or license computerized data that contains sensitive personal information (like Social Security numbers, government IDs, or health records).
If your business collects, stores, or manages data tied to individuals, especially customers, patients, or employees, this law likely applies to you. This applies whether your business directly owns the data or has permission to use/manage it as part of your operations.
What Protections Does SB 2610 Offer?
If your business experiences a breach of system security and you can demonstrate that a compliant cybersecurity program was in place at the time, SB 2610 protects you from punitive damages in related lawsuits.
However, the law does not protect you from:
- Compensatory damages (e.g., covering real losses)
- Court orders (injunctive relief)
- Investigations or penalties from the Texas Attorney General, FTC, or other agencies
- Breach notification requirements under Texas Business & Commerce Code §521.053
- Class action lawsuits (this law does not affect certification of a class)
What Does a “Compliant Cybersecurity Program” Look Like?
To qualify for safe harbor, your cybersecurity program must:
- Include administrative, technical, and physical safeguards for protecting sensitive information
- Be designed to detect, prevent, and respond to risks like identity theft and fraud
- Be scaled appropriately based on the size and complexity of your business
- Conform to industry-recognized cybersecurity frameworks
Requirements Based on Company Size
Each tier comes with its own expectations — and only businesses that meet the controls appropriate to their size will be eligible for SB 2610’s safe harbor protection. Smaller businesses aren’t off the hook; even the simplest tier requires documented safeguards and active cybersecurity training.

Would your business qualify today?
A quick gut-check:
- Your administrative, technical, and physical safeguards are documented, not just switched on
- MFA is enforced for every user, not left optional
- Your controls map to a recognized framework like NIST CSF, CIS Controls, or ISO 27000
- Cybersecurity training is required and tracked
- Your program is scaled to your employee-count tier
Hesitated on any of these? You may not be covered when it counts.
Approved Cybersecurity Frameworks
For businesses with 100–249 employees (or any business opting for full compliance), accepted frameworks include:
- NIST Cybersecurity Framework
- NIST SP 800-171, 800-53, and 800-53a
- ISO/IEC 27000-series
- Center for Internet Security Critical Security Controls
- FedRAMP
- HITRUST CSF
- Secure Controls Framework
- SOC 2 Framework
- HIPAA, GLBA, FISMA, HITECH, PCI DSS (if applicable)
If a framework is updated, businesses must update their program by the published implementation date or within 1 year — whichever comes later.
What Counts as “Sensitive Personal Information”?
!Per Texas law, this includes unencrypted digital data that combines a person’s name with:
- Social Security number
- Driver’s license or ID number
- Financial account numbers with access credentials
- Health information, diagnoses, care received, or payment data
Public records and information legally made public are not covered under this definition.
In Texas breach investigations, regulators routinely examine whether security controls were enforced at the time of the incident — not just available. Failures like optional MFA, inconsistent identity controls, and missing documentation are often what determine liability.
That’s the part most small businesses get wrong: qualifying isn’t about owning security tools, it’s about proving they were enforced and documented when a breach occurred.
For businesses already on Microsoft 365, most of the required controls — enforced MFA, threat protection, documented data handling — can be delivered and proven through licenses you may already have. The gap is almost always configuration and documentation, not missing software.
What This Means for Your Business
Whether you’re a 10-person startup or a growing business with 200 employees, SB 2610 incentivizes cybersecurity preparedness. If you’re not actively maintaining and updating a framework-based program, a breach could leave you fully exposed, not just to reputational damage, but also financial liability.
For current GCS clients, many of these protections may already be partially in place through Secure Cloud. However, eligibility still depends on whether required cybersecurity training is enforced, and whether your controls align with your size category.
Don’t Wait Until It’s Too Late
Not sure your current setup would actually qualify? That’s the part most businesses get wrong — and the part that only matters after it’s too late. We’ll review your cybersecurity program against the SB 2610 requirements and show you exactly where you stand. Request an SB 2610 readiness check.
Disclaimer: This post is for informational purposes only and does not constitute legal advice. GCS Technologies is not a law firm, and we do not provide legal services.
FAQ: Texas SB 2610 Cybersecurity Safe Harbor Law
Who qualifies for protection under Texas SB 2610?
Texas businesses with fewer than 250 employees that own or manage sensitive personal information and have a compliant cybersecurity program in place at the time of a breach.
What protection does SB 2610 actually provide?
SB 2610 offers safe harbor from punitive damages in certain lawsuits following a data breach. It does not eliminate breach notifications, regulatory investigations, compensatory damages, or class actions.
What counts as a “compliant cybersecurity program” under SB 2610?
A program that includes administrative, technical, and physical safeguards, is scaled to your business size, and aligns with an approved cybersecurity framework such as NIST, CIS Controls, ISO 27001, or SOC 2.
Does SB 2610 require small businesses to follow enterprise-level frameworks?
No. Requirements scale by company size, but even small businesses must document controls, train employees, and actively manage cybersecurity risks to qualify.
When does SB 2610 go into effect, and when must businesses be compliant?
The law takes effect on September 1, 2025, and protections apply only if your cybersecurity program is compliant before a breach occurs.



