A3231

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

Introduced·1/13/26
Introduced Text

New Jersey A3231 mandates reporting of cybersecurity incidents by businesses in financial, essential infrastructure, and healthcare sectors.

New Jersey A3231 requires businesses in financial, essential infrastructure, and healthcare industries to report cybersecurity incidents to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC). A "cybersecurity incident" is defined as an event that jeopardizes the integrity, confidentiality, or availability of information systems. The NJCCIC must audit the affected business's cybersecurity program within 30 days of receiving a report. The audit is conducted by a qualified and independent cybersecurity company at the business's expense.

Included in complete analysis

  • Overview
  • Core Provisions
  • Implementation
  • Impact
  • Legal Framework
  • Critical Issues

See what it does, who it affects, and the critical issues in plain language. Free, 30 seconds.

Where it stands

Current
Science, Innovation and Technology Committee
Next
Committee decision

Sponsors

D
1
0
Democratic CaucusRepublican Caucus

History

Jan 13

Assembly

Introduced, Referred to Assembly Science, Innovation and Technology Committee