Loading chat...

CT SB00403

Bill

Status

Introduced

3/4/2026

Primary Sponsor

Public Safety and Security Committee

Click for details

Origin

Senate

2026 General Assembly

AI Summary

  • Covered entities complying with NIST Cybersecurity Framework 2.0 and AAL3 identity assurance standards are deemed compliant with equivalent state cybersecurity requirements starting July 1, 2027; critical infrastructure entities must eliminate centrally stored passwords and biometrics by the same date.

  • Cybersecurity professionals receive whistleblower protections when reporting material security deficiencies or non-repudiation failures to supervisors or the Division of Emergency Management and Homeland Security.

  • Covered entities must notify the Division of Emergency Management and Homeland Security within 72 hours of discovering cybersecurity incidents involving unauthorized data access, service disruption, or material operational risk.

  • Critical infrastructure entities, health care providers, financial institutions, and state agencies must adopt quantum-transition readiness postures and implement cryptographic agility architectures by January 1, 2028.

  • Establishes the Connecticut Cybersecurity Seed Fund grant program, a bug bounty program for state systems with researcher immunity, and a State Cybersecurity Intelligence Task Force comprising commissioners from Emergency Services, Administrative Services, and the Military Department.

Legislative Description

An Act Concerning Cybersecurity.

Last Action

Public Hearing 03/10

3/5/2026

Committee Referrals

Public Safety and Security3/4/2026

Full Bill Text

No bill text available