A 3897 New Jersey General Assembly · 2024-2025 Regular Session

Requires municipalities, counties, and school districts to report cybersecurity incidents.

This bill requires municipalities, counties, and school districts in New Jersey to report cybersecurity incidents that compromise billing systems, communications, data management, or critical infrastructure (like industrial control systems). Designated employees must submit incidents via an online form developed by the Attorney General and NJ Cybersecurity Integration Cell within a prompt timeframe. Within 30 days of receiving a report, the NJCCIC must contract an independent cybersecurity firm to audit the entity’s security program and response, identifying threats, vulnerabilities, and improvement strategies. All incident reports and audit details are exempt from public disclosure under New Jersey’s open records law. The Department of Law and Public Safety covers audit costs and allows reimbursement for related expenses incurred by affected entities.
Bill status in committee 1 of 4 stages cleared
Introduction
Feb 2024
Committee Review
Floor Vote
Governor
Introduced Feb 27, 2024 Last action Nov 14, 2024
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
3
Key actions
0
Committee
2
Nov 14, 2024
Committee
Reported and Referred to Assembly Appropriations Committee
lower
Jun 6, 2024
Committee
Reported out of Assembly Committee with Amendments and Referred to Assembly State and Local Government Committee
lower
Feb 27, 2024
Introduced
Introduced in the Assembly, Referred to Assembly Science, Innovation and Technology Committee
lower
3 primary · 2 co-sponsors

Sponsors