Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.
This bill requires businesses in New Jersey's financial, essential infrastructure, and healthcare sectors (defined as "sensitive businesses") to report specific cybersecurity incidents to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) promptly. It mandates reporting for incidents compromising billing, communications, data management, or industrial control systems that affect confidentiality, integrity, or availability. Within 30 days of receiving a report, the NJCCIC must order an independent cybersecurity audit of the business at the business's expense, identifying vulnerabilities and requiring corrective action plans. The audit findings and plans must then be submitted to the NJCCIC. The law takes effect 90 days after enactment.
Bill status
in committee
1 of 4 stages cleared
Introduction
Jan 2026
Committee Review
Floor Vote
Governor
Introduced Jan 13, 2026
Last action Jan 13, 2026
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
1
Key actions
0
Committee
0
Jan 13, 2026
Introduced
Introduced, Referred to Assembly Science, Innovation and Technology Committee
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Dan Hutchison
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about A 3231
Scope: NJ
Hi! I can help you understand A 3231. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline