Texas SB 2610, passed by the 89th Texas Legislature and effective September 1, 2025, gives businesses with fewer than 250 employees a legal tool to limit their exposure in a data breach lawsuit. If a qualifying cybersecurity program was in place when a breach occurred, the business can assert an affirmative defense against exemplary damages. The specific program required depends on how many employees the business has, and the program must exist before the breach happens.

SB 2610 creates an affirmative defense in civil litigation. When a plaintiff sues a business over a breach of system security, the business can invoke the defense to block an award of exemplary damages if it can show it had a qualifying cybersecurity program in place at the time of the breach. The law does not prevent lawsuits from being filed, and it does not eliminate liability for actual damages. It addresses only the punitive layer of a damages award.
The bill also requires that a qualifying program be updated after a relevant framework revision. A program frozen at an outdated version of a framework does not satisfy the law’s requirements going forward.

The safe harbor is narrow and specific. It is an affirmative defense to exemplary damages only. Exemplary damages, sometimes called punitive damages, are awarded on top of actual damages to punish particularly egregious conduct. SB 2610 does not shield a business from claims of negligence, breach of contract, or statutory violations. It does not prevent a court from awarding actual damages, and it does not create immunity from regulatory enforcement.
This distinction matters. A business that suffers a breach can still face significant liability for direct losses, notification costs, and other compensatory claims. The law reduces one category of financial exposure, not all of it. Understanding Texas data breach laws in full context is essential before treating SB 2610 as a complete risk management solution.
This page is not legal advice. Consult qualified legal counsel to evaluate how SB 2610 applies to your business.

The law applies to businesses with fewer than 250 employees. That threshold covers a wide range of Texas companies, from sole proprietors to mid-sized firms. The employee count determines which tier of requirements applies, so getting the headcount right matters before selecting a framework or building a program.
The law does not define “employees” further in the evidence available here. [ADD: statutory definition or clarification of how SB 2610 counts employees, e.g., full-time equivalents, part-time, contractors] Businesses near a tier boundary should confirm their classification with legal counsel before deciding which requirements to follow.
The smallest tier covers businesses with fewer than 20 employees. SB 2610 requires two things from these businesses: reasonable password requirements and employee cybersecurity training. The law does not prescribe a specific password standard or mandate a particular training curriculum, but the program must be implemented and maintained, not simply documented and forgotten.
In practice, reasonable password requirements typically include minimum length, complexity rules, and controls against reuse. Employee training should cover phishing recognition, safe handling of sensitive data, and incident reporting procedures. These are baseline controls, but they must be active and enforced when a breach occurs for the defense to apply.
Businesses in this tier should document their password policy and keep records of training completion. Documentation is what makes the defense usable in court. Our data security and compliance services can help small businesses build and maintain these records systematically.
Businesses in the 20-to-99 employee range must implement and maintain a cybersecurity program that meets CIS Controls Implementation Group 1 (IG1). CIS IG1 is the foundational tier of the CIS Controls framework, designed specifically for smaller organizations with limited IT resources. It covers 56 safeguards across 18 control categories, addressing areas such as asset inventory, data protection, secure configuration, account management, and basic incident response.
IG1 is not a light lift for a business without dedicated IT staff, but it is structured and well-documented. The Center for Internet Security publishes the full control set with implementation guidance. The key obligation under SB 2610 is that the program must be in place and maintained, and it must be updated when the CIS Controls framework is revised.
Businesses at this tier should map their existing controls to IG1, identify gaps, and close them before a breach occurs. Working with a Dallas IT services provider familiar with CIS Controls can accelerate that process for Texas-based companies.

The largest tier under SB 2610 covers businesses with 100 to 249 employees. These businesses must substantially comply with a recognized cybersecurity framework or an applicable regulatory standard. The bill identifies several options:
The standard is substantial compliance, not perfect compliance. That said, substantial compliance still requires a documented, functioning program. Selecting a framework and doing nothing with it does not qualify. Businesses in this tier should choose the framework most aligned with their industry and existing controls, then build toward it systematically. Our NIST compliance framework guidance covers how to structure that process for businesses using NIST CSF or SP 800-171.
| Employee Count | What the Law Requires | Example Controls | Documentation to Keep |
|---|---|---|---|
| Fewer than 20 | Reasonable password requirements and employee cybersecurity training | Password policy with minimum length and complexity; annual phishing and security awareness training | Written password policy; training completion records with dates and employee names |
| 20 to 99 | CIS Controls Implementation Group 1 | Hardware and software asset inventory; data protection controls; secure configuration baselines; multi-factor authentication; basic incident response plan | IG1 gap assessment; control implementation records; evidence of framework updates applied after CIS revisions |
| 100 to 249 | Substantial compliance with a recognized framework (NIST CSF, NIST SP 800-171, ISO/IEC 27000 series, CIS Controls) or applicable regulation (HIPAA, GLBA, PCI DSS) | Risk assessment; access control policy; vulnerability management program; incident response and recovery plan; vendor risk management | Framework selection rationale; risk assessment reports; policy documents; audit or assessment results; evidence of updates after framework revisions |
For businesses already subject to HIPAA, GLBA, or PCI DSS, SB 2610 creates an alignment opportunity. If a business in the 100-to-249 employee tier is already maintaining a HIPAA Security Rule compliance program, that program can serve as the qualifying cybersecurity program under SB 2610, provided it is implemented and maintained as the law requires. The same logic applies to PCI DSS for payment card processors and GLBA for financial services firms.
The Texas Data Privacy and Security Act (TDPSA) operates separately from SB 2610. TDPSA imposes data processing and privacy obligations on businesses that meet its applicability thresholds. SB 2610 addresses breach litigation exposure. The two laws can overlap in practice: a breach that triggers TDPSA obligations may also be the event that tests whether a business qualifies for the SB 2610 affirmative defense. Reviewing the Texas breach notification law requirements alongside SB 2610 gives a more complete picture of what a breach response involves.
Businesses subject to multiple frameworks should map their existing compliance work to SB 2610’s tier requirements and identify whether any gaps remain. Our compliance services team works with businesses navigating overlapping regulatory obligations.

The affirmative defense requires a business to show it implemented and maintained a qualifying program when the breach occurred. That showing happens in litigation, which means documentation is the evidence. Verbal policies and informal practices do not hold up in court.
Every tier requires written documentation. For the smallest tier, that means a written password policy and training records. For IG1, it means a gap assessment, control implementation records, and evidence that the program was updated when the CIS Controls framework was revised. For the top tier, it means a formal risk assessment, written policies aligned to the chosen framework, and periodic review records.
Key documentation practices include:

Start by confirming your employee count and identifying which tier applies to your business. Then assess your current controls against that tier’s requirements. For businesses with fewer than 20 employees, the gap analysis is straightforward: do you have a written password policy and documented training? For businesses in the 20-to-99 range, map your existing controls to CIS IG1 and identify what is missing. For businesses with 100 to 249 employees, select the framework most relevant to your industry and conduct a formal risk assessment against it.
Build the program before a breach occurs. The law requires the program to be in place at the time of the breach. Retroactive compliance does not qualify for the affirmative defense. Set a review schedule so the program stays current as frameworks are updated, and assign clear internal ownership so the program does not lapse between reviews.
Legal counsel should review your program design and documentation approach to confirm it meets the law’s requirements. SB 2610 is new, and how courts interpret “reasonable password requirements,” “substantial compliance,” and related terms will develop over time.
Texas SB 2610 is a 2025 state law, effective September 1, 2025, that creates an affirmative defense to exemplary (punitive) damages for businesses with fewer than 250 employees that are sued over a breach of system security. To qualify for the defense, the business must have implemented and maintained a cybersecurity program meeting the requirements for its employee-count tier at the time the breach occurred.
No, SB 2610 compliance is not mandatory. The law establishes a voluntary affirmative defense, meaning a business chooses whether to build a qualifying cybersecurity program. A business that does not meet the requirements simply loses access to that specific defense if it faces a lawsuit involving exemplary damages related to a breach of system security.
Under SB 2610, a business with fewer than 20 employees must implement reasonable password requirements and provide employee cybersecurity training to qualify for the affirmative defense. The program must also be updated following any revision to the applicable framework or requirements. Consulting legal counsel is advisable to confirm your program meets the statutory standard before relying on this defense.
No, SB 2610 does not protect a business from all breach-related lawsuits. The affirmative defense applies only to exemplary (punitive) damages; it does not limit liability for actual damages or shield a business from regulatory enforcement actions. A qualifying cybersecurity program reduces one category of financial exposure, not overall legal or regulatory risk from a breach.
For businesses in the 100–249 employee tier, SB 2610 lists compliance with applicable regulations, including HIPAA and PCI DSS, as a qualifying path to the affirmative defense. Whether your existing compliance program satisfies the statutory requirements depends on the specific bill language; verify the enrolled text at capitol.texas.gov and have legal counsel review your situation before drawing conclusions.
Start by counting your employees to determine which SB 2610 tier applies to your business: fewer than 20, 20–99, or 100–249. Once you know your tier, document your current security controls and compare them against the corresponding requirements. Identify any gaps between your existing program and the statutory standard, and have legal counsel review your findings before the September 1, 2025 effective date.
See the power of IT GOAT.
The world’s most advanced cybersecurity platform catered specifically to your business’ needs.
Keep up to date with our digest of trends & articles.
By subscribing, I agree to the use of my personal data in accordance with IT GOAT Privacy Policy. IT GOAT will not sell, trade, lease, or rent your personal data to third parties.
Mitigate All Types of Cyber Threats
Experience the full capabilities of our advanced cybersecurity platform through a scheduled demonstration. Discover how it can effectively protect your organization from cyber threats.
IT GOAT: Threat Intel & Cyber Analysis
We are experts in the field of cybersecurity, specializing in the identification and mitigation of advanced persistent threats, malware, and exploit development across all platforms.
Protect Your Business & Operations
Exceptional performance in the latest evaluations, achieving 100% prevention rate and providing comprehensive analytic coverage, unmatched visibility, and near-instant detection of threats.
We use cookies to enhance site performance and user experience. Your data stays private — we don’t sell your information or share it with unrelated third parties. To find out more about the cookies we use, view our Privacy Policy.