{"data":{"id":"us-tx/tex.-business-commerce-code-542.004","jurisdiction":"us-tx","citation":"Tex. Business \u0026 Commerce Code § 542.004","heading":"CYBERSECURITY PROGRAM.","body":"(a) For purposes of Section 542.003, a cybersecurity program must:\n(1) contain administrative, technical, and physical safeguards for the protection of personal identifying information and sensitive personal information;\n(2) conform to an industry-recognized cybersecurity framework as described by Subsection (b);\n(3) be designed to:\n(A) protect the security of personal identifying information and sensitive personal information;\n(B) protect against any threat or hazard to the integrity of personal identifying information and sensitive personal information; and\n(C) protect against unauthorized access to or acquisition of personal identifying information and sensitive personal information that would result in a material risk of identity theft or other fraud to the individual to whom the information relates; and\n(4) with regard to the scale and scope, meet the following requirements:\n(A) for a business entity with fewer than 20 employees, simplified requirements, including password policies and appropriate employee cybersecurity training;\n(B) for a business entity with at least 20 employees but fewer than 100 employees, moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1; and\n(C) for a business entity with at least 100 employees but fewer than 250 employees, compliance with the requirements of Subsection (b).\n(b) A cybersecurity program under this section conforms to an industry-recognized cybersecurity framework for purposes of this section if the program conforms to:\n(1) a current version of or any combination of current versions of the following:\n(A) the Framework for Improving Critical Infrastructure Cybersecurity published by the National Institute of Standards and Technology (NIST);\n(B) the NIST's special publication 800-171;\n(C) the NIST's special publications 800-53 and 800-53a;\n(D) the Federal Risk and Authorization Management Program's FedRAMP Security Assessment Framework;\n(E) the Center for Internet Security Critical Security Controls for Effective Cyber Defense;\n(F) the ISO/IEC 27000-series information security standards published by the International Organization for Standardization and the International Electrotechnical Commission;\n(G) the Health Information Trust Alliance's Common Security Framework;\n(H) the Secure Controls Framework;\n(I) the Service Organization Control Type 2 Framework; or\n(J) other similar frameworks or standards of the cybersecurity industry;\n(2) if the business entity is subject to its requirements, the current version of the following:\n(A) the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.);\n(B) Title V, Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.);\n(C) the Federal Information Security Modernization Act of 2014 (Pub. L. No. 113-283); or\n(D) the Health Information Technology for Economic and Clinical Health Act (Division A, Title XIII, and Division B, Title IV, Pub. L. No. 111-5); and\n(3) if applicable to the business entity, a current version of the Payment Card Industry Data Security Standard.\n(c) If any standard described by Subsection (b)(1) is published and updated, a business entity's cybersecurity program continues to meet the requirements of a program under this section if the entity updates the program to meet the updated standard not later than the later of:\n(1) the implementation date published in the updated standard; or\n(2) the first anniversary of the date on which the updated standard is published.\nAdded by Acts 2025, 89th Leg., R.S., Ch. 1029 (S.B. 2610), Sec. 1, eff. September 1, 2025.","path":["BUSINESS AND COMMERCE CODE","TITLE 11. PERSONAL IDENTITY INFORMATION","SUBTITLE C. CONSUMER DATA PROTECTION","CHAPTER 542. CYBERSECURITY PROGRAM"],"source_url":"https://statutes.capitol.texas.gov/Docs/BC/htm/BC.542.htm#542.004","current_through":"89th 2nd Called Legislative Session, 2025","vintage":"","retrieved_at":"2026-08-27T01:46:56Z","sha256":"5aac2b93b72494f6f9ce696d8813b5d7ea56560a040f8127e89e6e053c97fdb9","source_id":"us-tx","stale":false,"prev":"us-tx/tex.-business-commerce-code-542.003","next":"us-tx/tex.-business-commerce-code-542.005"},"notice":"GroundRules: Original legal text. Not legal advice."}
