S 1262 New Jersey Senate · 2026-2027 Regular Session

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

This bill requires businesses in New Jersey's financial, essential infrastructure (like utilities), and healthcare sectors to create cybersecurity plans and report certain incidents. Specifically, "sensitive businesses" must develop programs following industry standards (such as NIST frameworks), identify a cybersecurity lead, conduct risk assessments, and submit annual compliance certifications. They must also report incidents affecting billing systems, data privacy, or industrial control systems (e.g., power grid operations) to the New Jersey Cybersecurity Cell. The bill applies only to covered businesses operating in New Jersey and does not create new penalties for noncompliance.
Bill status in committee 1 of 4 stages cleared
Introduction
Jan 2026
Committee Review
Floor Vote
Governor
Introduced Jan 13, 2026 Last action Jan 13, 2026
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
1
Key actions
0
Committee
0
Jan 13, 2026
Introduced
Introduced in the Senate, Referred to Senate Law and Public Safety Committee
upper
2 primary · 0 co-sponsors

Sponsors