A 3231 New Jersey General Assembly · 2026-2027 Regular Session

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

This bill requires businesses in New Jersey's financial, essential infrastructure, and healthcare sectors (defined as "sensitive businesses") to report specific cybersecurity incidents to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) promptly. It mandates reporting for incidents compromising billing, communications, data management, or industrial control systems that affect confidentiality, integrity, or availability. Within 30 days of receiving a report, the NJCCIC must order an independent cybersecurity audit of the business at the business's expense, identifying vulnerabilities and requiring corrective action plans. The audit findings and plans must then be submitted to the NJCCIC. The law takes effect 90 days after enactment.
Bill status in committee 1 of 4 stages cleared
Introduction
Jan 2026
Committee Review
Floor Vote
Governor
Introduced Jan 13, 2026 Last action Jan 13, 2026
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
1
Key actions
0
Committee
0
Jan 13, 2026
Introduced
Introduced, Referred to Assembly Science, Innovation and Technology Committee
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Dan Hutchison
Dan Hutchison
DDemocratic
NJ
4