Bill

Bill > SB00403


CT SB00403

CT SB00403
An Act Concerning Cybersecurity.


summary

Introduced
03/04/2026
In Committee
03/04/2026
Crossed Over
Passed
Dead
05/06/2026

Introduced Session

2026 General Assembly

Bill Summary

To establish various cybersecurity provisions relating to (1) a cybersecurity framework, (2) a prohibition on penalizing cybersecurity employees for certain reports, (3) notifications regarding cybersecurity incidents, (4) minimum safeguards, (5) quantum-transition readiness requirements, (6) the "Connecticut Cybersecurity Seed Fund" grant program, (7) a "bug bounty" program, (8) the dissemination of cybersecurity intelligence, (9) the State Cybersecurity Intelligence Task Force, and (10) the state's operational response to cybersecurity emergencies.

AI Summary

This bill establishes a comprehensive cybersecurity framework for the state, defining "covered entities" as businesses, healthcare entities, or government contractors handling sensitive data or operating critical infrastructure. It mandates that by July 1, 2027, covered entities complying with the National Institute of Standards and Technology's (NIST) Cybersecurity Framework 2.0 and high-level identity assurance standards (AAL3 identity assurance, meaning robust identity verification resistant to impersonation) will meet state cybersecurity requirements, while critical infrastructure entities must use decentralized security systems that ensure non-repudiation, meaning transactions cannot be denied, and eliminate centrally stored passwords or biometrics by the same date. The bill also prohibits employers from retaliating against cybersecurity employees who report significant security flaws, referred to as "material security deficiencies" (systemic failures posing a risk to public safety or operations), or failures to maintain non-repudiation. Covered entities must report cybersecurity incidents that compromise sensitive data, disrupt services, or pose a material risk within 72 hours to the Division of Emergency Management and Homeland Security, providing details about the incident and its impact. Minimum cybersecurity safeguards, aligned with NIST principles, including timely patching, data encryption, backup systems, and annual risk assessments, are required starting January 1, 2027. Furthermore, critical infrastructure entities, healthcare providers, financial institutions, and state agencies must prepare for quantum computing threats by January 1, 2028, by planning for post-quantum cryptography and implementing systems capable of rapid cryptographic algorithm changes. To support these efforts, the bill establishes the "Connecticut Cybersecurity Seed Fund" grant program to aid in developing decentralized and non-repudiated security solutions, and mandates the creation of a "bug bounty" program by January 1, 2028, to incentivize security researchers to find vulnerabilities in state systems, granting them immunity for good-faith efforts. The Connecticut Intelligence Center will collect and share cybersecurity intelligence, and a State Cybersecurity Intelligence Task Force will be formed to analyze threats and coordinate responses, with the Division of Emergency Management and Homeland Security coordinating the state's operational response to cybersecurity emergencies and serving as a liaison between the task force and local emergency management officials.

Committee Categories

Justice

Sponsors (0)

No sponsors listed

Other Sponsors (1)

Public Safety and Security Committee (Joint)

Last Action

Public Safety and Security Public Hearing (00:00:00 3/10/2026 ) (on 03/10/2026)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...