Texas businesses under 250 employees
Since September 1, 2025, Texas businesses that maintain a recognized cybersecurity program have an affirmative defense against punitive damages in a breach lawsuit. But the defense only holds if the program is real, documented, and in place before the incident. Most businesses find out which side of that line they’re on at the worst possible moment.
10 questions · instant score · no sales call to see your results.
Texas SB 2610, explained — and how to turn it into a real safe harbor.
Senate Bill 2610 creates an affirmative defense — not immunity. If your business has fewer than 250 employees and you are sued over a data breach, you can assert that you adopted and maintained a cybersecurity program that reasonably conforms to a recognized industry framework, and on that basis be shielded from punitive (exemplary) damages.
Three things follow from that, and they are the three things most businesses get wrong. The defense is something you raise and prove, so the burden is yours. It covers punitive damages only — ordinary compensatory damages, breach-notification costs, and regulatory exposure are untouched. And it is judged on the state of your program before the breach, which means the work has to be done in advance and evidenced with dated artifacts.
In plain terms: the statute rewards businesses that can produce paperwork proving they were already doing the right things. That is a documentation problem at least as much as a security problem.
SB 2610 scales its expectations by headcount. We build a program — anchored on NIST CSF 2.0 — that matches the tier you fall into.
Fewer than 20 employees
A streamlined set of safeguards sized to a very small team.
The statute asks for a program that reasonably conforms to a recognized framework, scaled to your size. In practice: documented policies, MFA everywhere, managed endpoint protection, tested backups, offboarding that actually revokes access, and annual security awareness training — written down, with evidence you followed it.
20–99 employees
A mid-tier program aligned to a recognized framework.
Everything above, plus formal risk assessments, vendor/third-party review, logging and alerting you can produce after an incident, an incident-response plan that has been exercised, and named ownership for each control.
100–249 employees
A NIST CSF 2.0–based program for larger small businesses.
A full NIST CSF 2.0 program across all six functions (Govern, Identify, Protect, Detect, Respond, Recover), with continuous control monitoring, documented governance, and an audit trail that shows the program was operating *before* any incident — which is the part that carries the defense.
“The law protects me automatically.”
It does not. SB 2610 is an affirmative defense you have to raise and prove. If you cannot show the program existed and was maintained before the breach, there is nothing to assert.
“We have good IT, so we’re covered.”
Working IT and a documented compliance program are different things. The defense turns on evidence — policies, records, dated artifacts — not on whether your network was well run. Most businesses that are genuinely secure still cannot produce the paperwork.
“We’re too small to be sued.”
The safe harbor exists precisely because businesses under 250 employees were being hit with punitive-damages claims after breaches. Small is who this law is written for.
“We’ll do it after we get breached.”
The program must predate the incident. A compliance program built after a breach protects you from the *next* one — it does nothing for the claim in front of you.
Answer 10 questions about how your business actually operates and get a 0–100 readiness score, your biggest gaps, and what to fix first. It takes about two minutes and you see the score immediately.
1. Baseline assessment (~2 weeks)
We measure you against NIST CSF 2.0 at your headcount tier and produce a written gap report — what exists, what doesn’t, and what a court or carrier would actually accept as evidence today. It includes a full NIST SP 800-30 risk assessment: your risks identified, rated for likelihood and impact, and prioritized, with the reasoning recorded for each one.
2. Remediation sprint (45–90 days)
We close the gaps and write the program: policies, risk assessment, incident-response plan, and the control evidence behind each one. Your existing IT team or provider keeps running IT — we work alongside them.
3. Continuous compliance (ongoing)
The defense depends on the program being maintained, not just built once. We keep the evidence current and dated, so on any given day you can show what was true — including the day before an incident.
SB 2610 protects businesses that implement and maintain a recognized framework. The hard question isn’t whether you bought a framework — it’s whether you can show you made reasoned decisions about your own risk. A generic checklist, identical to every other company’s, is weak evidence of that. A risk assessment that names your threats, rates them against evidence from your systems, records why each rating was chosen, and shows what you decided to do about it is a much harder thing to argue with.
It’s also the evidence behind the NIST CSF 2.0 subcategories a reviewer is most likely to ask about — GV.RM-01 and ID.RA-01 through ID.RA-05 — and the same document answers the risk questions on a cyber-insurance application and a customer security questionnaire. One piece of work, three audiences.
We reassess annually, and sooner if something material changes — an incident, a new critical system, a merger, a new AI tool touching customer data, or an insurance renewal. An assessment that is two years stale doesn’t describe the company you are now.
SB 2610
Texas’s cybersecurity safe-harbor law — an affirmative defense, in effect since September 1, 2025, for businesses that adopt a recognized security program.
TDPSA
The Texas Data Privacy & Security Act — data-handling and consumer-rights obligations, enforced aggressively by the Texas Attorney General.
TRAIGA
The Texas Responsible AI Governance Act — new AI obligations in effect January 1, 2026.
Texas Senate Bill 2610 is a cybersecurity safe-harbor law effective September 1, 2025. It gives a business with fewer than 250 employees an affirmative defense against punitive (exemplary) damages in a lawsuit arising from a data breach, provided the business adopted and maintained a cybersecurity program that reasonably conforms to a recognized industry framework.
No. It does not prevent a lawsuit and it does not bar ordinary compensatory damages. It is a shield against punitive damages specifically, and only if you can prove the qualifying program was in place before the incident.
Businesses operating in Texas with fewer than 250 employees. The law scales what it expects by headcount: fewer than 20 employees, 20–99 employees, and 100–249 employees each face a different bar.
Recognized frameworks including NIST Cybersecurity Framework (CSF) 2.0, NIST SP 800-171, CIS Critical Security Controls, ISO/IEC 27001, and sector frameworks such as HIPAA Security Rule or PCI DSS where they apply. We anchor most Texas SMB programs on NIST CSF 2.0 because it scales cleanly across all three headcount tiers.
Evidence, dated before the incident: written policies, a documented risk assessment, records showing the controls were operating (MFA enforcement, patching, backup tests, access reviews, training completion), and an incident-response plan. A framework you bought but never operated will not carry the defense.
For most Texas businesses under 250 employees, a baseline assessment takes about two weeks, and closing the gaps it finds typically runs 45–90 days depending on tier and starting posture. The documentation and evidence trail then has to be maintained continuously — that is the part that keeps the defense alive.
No. Compliance is a standalone service. We work alongside your in-house IT team or your existing provider — we build, document, and maintain the compliance program; they keep running your IT. Nothing about your current arrangement has to change.
They ask for substantially the same controls. The evidence you assemble for the safe harbor is the same evidence your carrier wants on the renewal questionnaire — MFA, EDR, tested backups, access management, training. Doing it once serves both, and it is a common reason businesses start.
Start with a baseline assessment. We’ll show you exactly where you stand against a recognized framework — and what it takes to make SB 2610 work for you.
Free 30-minute call · no obligation · no sales pressure — or call (281) 941-4028
We ask before we track you.
Nothing from Google, Microsoft, or Meta loads on this site unless you say yes. We keep basic, cookieless visit counts on our own server either way. Details in our Privacy Policy.
Essential site function and first-party, cookieless visit counts run either way and can't be switched off here.