Qualification Call
Headcount, data you hold, and which tier applies to you. Some businesses are closer than they think.
Since 1 September 2025, Texas businesses under 250 employees can be shielded from punitive damages in a data breach lawsuit — but only if a documented cybersecurity program was already running when the breach happened. You cannot build it afterwards. We build the program, document it, and keep it current.
SB 2610 shields a qualifying business from exemplary (punitive) damages in a breach lawsuit. That is real protection — punitive awards are what bankrupt small companies. But it is narrower than the marketing around it suggests, and you should hear the limits from us before you hear them from opposing counsel.
Three conditions decide whether SB 2610 applies: you operate in Texas, you have fewer than 250 employees, and you hold sensitive personal information. If all three are true, your requirements scale with your headcount.
Basic documented safeguards — password policy, employee awareness training, and evidence that both are actually in force rather than aspirational.
CIS Controls Implementation Group 1 — foundational cyber hygiene across inventory, access control, data protection, and response. This is where most Austin SMBs land.
A full recognized framework: NIST CSF, NIST SP 800-53 or 800-171, ISO/IEC 27001, CIS Controls, or FedRAMP, implemented and maintained against the current version.
Full compliance with HIPAA, Gramm-Leach-Bliley, or PCI DSS also qualifies. If you are already meeting one of those, much of the work is done — the gap is usually documentation.
A SOC 2 program aligns with the frameworks the statute recognizes. If you are already pursuing SOC 2 with Drata, you are building most of this anyway.
Safe harbor is an affirmative defense. Your lawyers must show the program existed before the breach — dated policies, deployment records, training logs. Good intentions are not evidence.
This is the part most coverage of SB 2610 skips. The statute protects a program that was implemented and maintained at the time of the incident. There is no retroactive qualification, no grace period, and no credit for having meant to get around to it. Every day without a documented program is a day of exposure you cannot recover later.
Built primarily on the Microsoft security stack, because most companies your size already own most of it. The controls SB 2610 expects are largely the controls we already deploy — the work the statute adds is documenting them well enough to hold up.
The incidents that actually hit companies your size are ordinary: a password reused across services, a laptop two months behind on patches, a backup nobody tested, an ex-employee whose account still works. Security vendors sell you a dashboard for this. What it really takes is someone operating the fundamentals every week.
Headcount, data you hold, and which tier applies to you. Some businesses are closer than they think.
Your current controls measured against the framework your tier requires, with the gaps ranked.
What has to change, in what order, with what it costs — not a 90-page report you will never read.
Controls deployed and, just as important, documented and dated so the program is evidenced from day one.
Monitoring, patching, access reviews, training and an annual documented review — because the safe harbor only holds while the program is maintained.
This page is general information, not legal advice. Radtak Solutions is a technology company, not a law firm, and nothing here creates an attorney-client relationship or guarantees that your business will qualify for safe harbor under Texas Senate Bill 2610. Whether the statute applies to you, and whether a given program satisfies it, are legal questions that depend on your specific circumstances and are ultimately decided by a court. Consult a licensed Texas attorney. We build and document the cybersecurity program; your counsel advises you on the law. Summary current as of August 2026 — SB 2610 was signed 20 June 2025 and took effect 1 September 2025.
A free 30-minute call. We will tell you which tier applies to you and how far you are from it.