What Does Texas SB 2610 Require for the Cybersecurity Safe Harbor?
What Texas SB 2610 Requires For The Cybersecurity Safe Harbor – The Three Tiers In Texas SB 2610 Explained
The 3 tiers in the law, what the protection covers and leaves open, and the records a Houston business needs to show it qualified.
The Texas SB 2610 safe harbor protects a business with fewer than 250 employees from exemplary damages in a data breach lawsuit, provided the business can show it had a conforming cybersecurity program in place when the breach happened. What counts as conforming depends on headcount.
The question usually arrives sideways. An insurance broker mentions a Texas safe harbor at renewal, or an attorney raises it while reviewing a client contract, and a Houston owner wants to know what the business has to have in place. The law took effect September 1, 2025 as Chapter 542 of the Texas Business and Commerce Code. It passed the Texas Senate 31 to 0 and the House 109 to 27.
CinchOps builds and documents SB 2610 cybersecurity programs specifically for small and mid-sized businesses in the Houston metro, mapped to the tier for each headcount: fewer than 20, 20 to 99, or 100 to 249 employees.
What Does Texas SB 2610 Require at Each Business Size?
The law sets 3 tiers. Headcount decides which one applies.
Texas SB 2610 requires password policies and employee cybersecurity training for a business with fewer than 20 employees, the CIS Controls Implementation Group 1 for a business with 20 to 99 employees, and conformance to a recognized framework such as NIST or ISO/IEC 27000 for a business with 100 to 249 employees.
The table compares the 3 SB 2610 tiers by employee count, the wording in Section 542.004 of the law, and the records CinchOps recommends a business in that tier keep on file.
| Employees | What Section 542.004 says | Records to keep on file (CinchOps recommendation) |
|---|---|---|
| Fewer than 20 | "Simplified requirements, including password policies and appropriate employee cybersecurity training" | A written password policy, proof it is enforced, and dated training records for each employee |
| 20 to 99 | "Moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1" | A dated assessment against each Implementation Group 1 safeguard, with the gaps found and the date each was closed |
| 100 to 249 | Conformance to an industry-recognized cybersecurity framework named in the law | The framework name and version, a dated assessment against it, and a plan for the open items |
A 12-person CPA practice in Katy and a 60-person engineering firm in The Woodlands sit in different tiers and owe different amounts of work. Both tiers use the word "including," which sets a floor and stops short of a complete list. Every tier also has to meet the base test in the law: administrative, technical and physical safeguards that protect personal identifying information and sensitive personal information.
The frameworks SB 2610 names include the NIST Cybersecurity Framework, NIST Special Publications 800-171 and 800-53, the CIS Critical Security Controls, the ISO/IEC 27000 series, HITRUST, SOC 2 and FedRAMP, plus "other similar frameworks." A business already subject to HIPAA, the Gramm-Leach-Bliley Act or PCI DSS has to conform to the current version of those as well. CinchOps explains two of the options in CIS Controls for Houston businesses and the NIST Cybersecurity Framework for small and mid-size businesses.
The law covers a business entity in Texas that has fewer than 250 employees and owns or licenses computerized data that includes sensitive personal information. Texas defines that as an unencrypted name combined with a Social Security number, a driver's license or government ID number, or an account or card number with its access code, along with identifying health information. The bill text does not say how to count part-time staff or contractors, so a business near 20, 100 or 250 should ask an attorney which side of the line it is on.
What Does the SB 2610 Safe Harbor Protect, and What Does It Leave Open?
The protection is narrower than the name suggests.
The SB 2610 safe harbor removes one thing: exemplary damages in a lawsuit arising from a breach of system security. The lawsuit can still be filed, compensatory damages are still available, and Section 542.005 says the law does not change any common law or statutory duty a business already has.
Exemplary damages are defined in Texas law as "any damages awarded as a penalty or by way of punishment but not for compensatory purposes," and the definition includes punitive damages. They are the part of a verdict meant to punish. Compensatory damages, the part that repays what people lost, are outside the safe harbor.
Existing duties stay in force. A Texas business that suffers a breach of system security still has to notify affected individuals no later than the 60th day after it determines the breach occurred, and has to notify the Texas Attorney General no later than the 30th day when at least 250 Texas residents are involved. CinchOps walks through that sequence in the data breach reporting checklist for Texas small businesses.
Two limits in the text catch owners out. The protection applies only to a cause of action that accrues on or after September 1, 2025. And the business has to demonstrate that the program was implemented and maintained "at the time of the breach," so the burden sits with the business and the program cannot be built afterward.
How Does a Houston Business Prove It Qualified for the SB 2610 Safe Harbor?
The law says "demonstrates." In practice that means paper with dates on it.
A Houston business proves it qualified for the SB 2610 safe harbor with dated records created before the breach. The law requires the business to demonstrate that it implemented and maintained the program, so it needs a named framework, a dated assessment against it, training records and a log showing the program was kept up.
In 35+ years doing this, the gap I see most often is missing dates. The firewall is configured, the staff sat through training and the backups run, and nobody can show when any of it was last checked. A program that exists only in people's heads is hard to demonstrate to anyone.
The local numbers suggest how much work is ahead. The CinchOps Houston Area Security Index scored 4,393 Houston-area businesses on external security signals, and 49.6% earned a D or an F. An outside score does not decide whether a business qualifies under SB 2610, because the Index cannot see internal policies or training. It does show that about half the businesses measured would have visible problems to fix before they could make the case.
Frameworks change, and the law allows for it. When a named standard is updated, a program keeps qualifying if the business updates it by the later of 2 dates: the implementation date published in the new standard, or the first anniversary of its publication. A dated network security audit each year is the simplest way to show the program kept pace.
The safe harbor is the one part of a breach lawsuit a business gets to prepare for in advance. If you were going to secure the company anyway, the extra cost is writing it down and keeping the dates.
Find Out Which SB 2610 Tier You Are In and What Is Missing
For a business with 20 to 99 employees, the law points to CIS Controls Implementation Group 1. CinchOps assesses Houston businesses against it through its CIS Controls service.
See CIS Controls for Houston businesses →How Can CinchOps Help a Houston Business Meet the SB 2610 Requirements?
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
- The CIS Controls service assesses a business against Implementation Group 1 and records each gap and the date it was closed.
- An IT security audit produces the dated, written assessment the evidence file is built around.
- Through cybersecurity services, CinchOps closes the gaps an assessment finds and runs 24/7 threat monitoring between reviews.
- Under managed IT support, help desk requests are answered in under 15 minutes.
- CinchOps works with businesses across the Houston area, including CPA firms, law firms and engineering firms.
SB 2610 pays the business that did the work before anything went wrong and can show when it did it. The Houston businesses CinchOps assesses usually have part of a program in place and little of the paperwork. Find your tier, get the assessment dated, and talk to CinchOps if you want it built and kept current.
Frequently Asked Questions
What is the Texas SB 2610 safe harbor?
The Texas SB 2610 safe harbor is a protection in Chapter 542 of the Texas Business and Commerce Code. It bars exemplary damages in a data breach lawsuit against a business with fewer than 250 employees that had a conforming cybersecurity program in place at the time of the breach.
Does Texas SB 2610 require my business to do anything?
No. SB 2610 is voluntary. It creates no new duty and no new right to sue, and a business that ignores it breaks no rule. What the business gives up is the protection from exemplary damages, which is available only to one that built and maintained a conforming program before a breach.
What does SB 2610 require for a business with 20 to 99 employees?
A business with at least 20 and fewer than 100 employees must meet what the law calls moderate requirements, including the Center for Internet Security Controls Implementation Group 1. The practical step is a dated assessment that lists each Implementation Group 1 safeguard, whether the business meets it, and when any gap was closed.
Can a business qualify for the SB 2610 safe harbor after a breach?
No. The law protects a business that demonstrates it implemented and maintained the program at the time of the breach. A program assembled after the incident does not meet that test, which is why the dated records created beforehand matter more than the security tools themselves.
What does an SB 2610 cybersecurity program cost in Houston?
CinchOps prices managed IT and security at a flat monthly rate of $100 to $250 per user per month, with no long-term contracts, no hidden fees and no cancellation penalties. The tier sets the amount of work, so a 15-person office needs far less than a 150-person one. Ask for a written scope.
Discover More
Sources
- Texas Legislature, SB 2610, enrolled text (89th Regular Session), adding Chapter 542 to the Business and Commerce Code
- Texas Business and Commerce Code, Chapter 521, Sections 521.002 and 521.053 (definitions and breach notification)
- Texas Civil Practice and Remedies Code, Section 41.001 (definition of exemplary damages)
- Spencer Fane, Texas Cybersecurity Safe Harbor for Small and Mid-Sized Businesses, October 29, 2025
- CinchOps, Houston Area Security Index 2026