S.3101

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

Introduced·4/15/24
Introduced Text

New Jersey S3101 mandates businesses in financial, essential infrastructure, and health care sectors to report cybersecurity incidents.

New Jersey S3101 requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC). The NJCCIC must audit the business's cybersecurity program within 30 days of receiving a report. The audit identifies cyber threats, vulnerabilities, and weaknesses, and recommends strategies to protect against future incidents. The audit is conducted by a qualified and independent cybersecurity company at the business's expense.

Included in complete analysis

  • Overview
  • Core Provisions
  • Implementation
  • Impact
  • Legal Framework
  • Critical Issues

See what it does, who it affects, and the critical issues in plain language. Free, 30 seconds.

Where it stands

Current
In committee
Next
Session adjourned — paused until it reconvenes

Sponsors

DD
2
0
Democratic CaucusRepublican Caucus

Roll Call Votes

Senate Law and Public Safety Committee: Reported with Substitution

4 Yea

DDRD

0 Nay

1 Not Voting

R

Calendar

Jun 13, 2024

10:00 AM

Senate Law and Public Safety Hearing

History

Jun 13, 2024

Senate

Combined with S3100 (SCS)

Apr 15, 2024

Senate

Introduced in the Senate, Referred to Senate Law and Public Safety Committee