Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Legislation topic

No spam. Unsubscribe anytime.

Rep. Gill Lombardo’s cybersecurity bill preempts local rules and offers limited liability safe harbor; amendment adopted

IT Budget & Policy Subcommittee · January 20, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The IT Budget & Policy Subcommittee reported House Bill 635 favorably after the sponsor’s amendment clarified that local governments cannot impose vendor cybersecurity requirements that exceed generally accepted standards. Supporters said the bill promotes uniform NIST-based rules and encourages reporting; members pressed liability and accountability questions.

Rep. Gill Lombardo introduced House Bill 635 to the IT Budget and Policy Subcommittee, saying the measure would require local governments to adopt cybersecurity standards consistent with guidance from Florida Digital Service and create a presumption against class-action liability for covered entities and third‑party vendors that substantially comply with established frameworks and practices.

The bill’s sponsor told the committee: “This bill requires local governments to only adopt cybersecurity standards consistent with those established by Florida Digital Service.” He said the proposal gives covered entities a “presumption of against liability” if they substantially comply with frameworks such as the NIST Cybersecurity Framework, maintain disaster‑recovery plans and use multifactor authentication.

Committee members focused on how the bill would affect local authority and accountability. Rep. Cross asked whether any municipalities currently exceed state standards, and whether the bill would set a ceiling rather than a floor. The sponsor said many local governments already use NIST and that the bill’s intent is alignment and consistency, not lowering protections. Rep. Blanco pressed whether a failure to perform (for example, not applying patches) would still constitute a violation; the sponsor replied that audits and documented practices create accountability and that poor maintenance would be evident in logs and reviews.

An amendment offered by Rep. Gill Lombardo (barcode 130573) clarified definitions and prohibited local governments from imposing cybersecurity requirements on vendors that exceed generally accepted best practices, including the NIST framework. The committee waived closing arguments and adopted the amendment by voice vote after no public testimony on the amendment was offered.

Business and policy groups spoke in favor during general public testimony. Adam Bassford thanked the sponsor and said the measure protects businesses and consumers by encouraging stronger safeguards and reducing litigation risk. Turner Lozel of the James Madison Institute said a safe harbor for good‑faith actors would incentivize reporting of attacks and help law enforcement better assess statewide cyber threats.

After debate closed, the committee called the roll and reported House Bill 635 favorably out of committee.

What’s next: The committee reported the bill favorably; the record shows the measure cleared this subcommittee with an adopted amendment and will proceed according to the legislative process.

Sources and limitations: Quotations and attributions come directly from committee testimony and exchanges. The transcript records witnesses and members’ statements; where a numeric or organizational detail in testimony was unclear in the record (for example, an affiliation phrase in one proponent’s introduction), the article uses only the wording provided to the committee.