SB 2471 Mississippi Senate · 2025 Regular Session

Cyber breach; limit liability for certain entities.

SB 2471 limits liability for government entities (like counties and municipalities) and commercial businesses if they adopt cybersecurity programs aligned with nationally recognized standards, such as the NIST Cybersecurity Framework. It creates a "rebuttable presumption" against liability for compliant entities, meaning plaintiffs must prove non-compliance with these standards to override the protection. The law requires documentation of compliance and shifts the burden of proof to the plaintiff in lawsuits, though it does not create new private lawsuits for non-compliance. This bill applies to entities handling personal information and takes effect July 1, 2025.
Bill status died 3 of 5 stages cleared
Introduction
Feb 2025
Committee Review
Feb 2025
Senate Passage
Feb 2025
House Passage
Governor
Introduced Feb 17, 2025 Last action Mar 4, 2025
Maddy AI version diff · 1 comparison

What changed between versions

As Introduced Current version · 6 edits
MODERATE
The bill was amended to clarify liability protections for government entities and commercial organizations regarding cybersecurity incidents. The changes streamline compliance requirements by removing redundant legal citations and updating references to federal cybersecurity standards to their current versions. These modifications ensure the law remains current with evolving federal regulations while maintaining the core immunity provisions for entities that adopt recognized cybersecurity practices.
Scope change
The bill's scope remains focused on providing liability protections for government entities and commercial organizations that implement cybersecurity standards, with no fundamental change to who is covered or what protections apply.
REQUIREMENT

Removed specific federal law citations (like Public Law numbers) from the list of standards that entities must align with, simplifying the compliance requirements.

Updated references to NIST cybersecurity publications to emphasize 'current version' and 'most current update' rather than specific publication numbers, ensuring ongoing compliance with evolving standards.

Added a new provision stating that failure to implement cybersecurity programs is not considered evidence of negligence or negligence per se.

Added a choice of law provision ensuring the act applies to agreements designating Mississippi as governing law, regardless of where the lawsuit is filed.

ENFORCEMENT

Clarified burden of proof rules in lawsuits, specifying that plaintiffs must prove non-compliance with clear and convincing evidence for government entities, while defendants must prove compliance for commercial entities.

TECHNICAL

Removed page headers, footers, and session metadata from the text, cleaning up the document format.

Floor votes · Senate Feb 11, 2025

How they voted

455
Passed · 1 other
Total votes 51
Feb 11, 2025
D Democratic16
15 Yea 1
93% Yea
R Republican35
30 Yea 5 Nay
85% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
7
Key actions
3
Committee
3
Amendments
1
Feb 17, 2025
Committee
Referred To Judiciary A;Technology
lower
Feb 17, 2025
Introduced
Transmitted To House
upper
Feb 11, 2025
Upper · Passed
Passed As Amended
upper
Feb 11, 2025
Upper · Passed
Amended
upper
Feb 4, 2025
Upper · Passed
Title Suff Do Pass
upper
Jan 20, 2025
Committee
Referred To Judiciary, Division A
upper
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Bart Williams
Bart Williams
RRepublican
MS
15