S 3100 New Jersey Senate · 2024-2025 Regular Session

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.*

This bill requires businesses in New Jersey's financial, critical infrastructure (like utilities), and healthcare sectors to create and maintain cybersecurity plans. These plans must include risk assessments, incident response procedures, and alignment with recognized industry standards such as NIST. Businesses must submit their plans to the state's cybersecurity agency (NJCCIC) and annually certify compliance, with failure to do so triggering a state-ordered audit by an independent cybersecurity firm. The law aims to strengthen protections for critical systems without mandating immediate incident reporting to the state.
Bill status in committee 1 of 4 stages cleared
Introduction
Apr 2024
Committee Review
Floor Vote
Governor
Introduced Apr 15, 2024 Last action Jun 13, 2024
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
3
Key actions
0
Committee
1
Jun 13, 2024
Committee
Referred to Senate Budget and Appropriations Committee
upper
Apr 15, 2024
Introduced
Introduced in the Senate, Referred to Senate Law and Public Safety Committee
upper
2 primary · 0 co-sponsors

Sponsors