Texas Law

Texas SB 2610
Safe Harbor Compliance.

Since 1 September 2025, Texas businesses under 250 employees can be shielded from punitive damages in a data breach lawsuit — but only if a documented cybersecurity program was already running when the breach happened. You cannot build it afterwards. We build the program, document it, and keep it current.

What the Law Does
A Safe Harbor Is Not Immunity. Know the Difference.

SB 2610 shields a qualifying business from exemplary (punitive) damages in a breach lawsuit. That is real protection — punitive awards are what bankrupt small companies. But it is narrower than the marketing around it suggests, and you should hear the limits from us before you hear them from opposing counsel.

  • Does not cover compensatory damages — actual losses remain your responsibility
  • Does not stop regulatory enforcement, breach notification duties, or class actions
  • Does not apply retroactively — the program must predate the breach and be evidenced
What We Do
Do You Qualify, and at What Level?

Three conditions decide whether SB 2610 applies: you operate in Texas, you have fewer than 250 employees, and you hold sensitive personal information. If all three are true, your requirements scale with your headcount.

Fewer Than 20 Employees

Basic documented safeguards — password policy, employee awareness training, and evidence that both are actually in force rather than aspirational.

20–99 Employees

CIS Controls Implementation Group 1 — foundational cyber hygiene across inventory, access control, data protection, and response. This is where most Austin SMBs land.

100–249 Employees

A full recognized framework: NIST CSF, NIST SP 800-53 or 800-171, ISO/IEC 27001, CIS Controls, or FedRAMP, implemented and maintained against the current version.

Already Regulated?

Full compliance with HIPAA, Gramm-Leach-Bliley, or PCI DSS also qualifies. If you are already meeting one of those, much of the work is done — the gap is usually documentation.

SOC 2 Counts Too

A SOC 2 program aligns with the frameworks the statute recognizes. If you are already pursuing SOC 2 with Drata, you are building most of this anyway.

The Documentation Test

Safe harbor is an affirmative defense. Your lawyers must show the program existed before the breach — dated policies, deployment records, training logs. Good intentions are not evidence.

Timing
You Cannot Buy This
After the Breach.

This is the part most coverage of SB 2610 skips. The statute protects a program that was implemented and maintained at the time of the incident. There is no retroactive qualification, no grace period, and no credit for having meant to get around to it. Every day without a documented program is a day of exposure you cannot recover later.

  • Effective 1 September 2025 — incidents before that date are outside the statute
  • Evidence, not assertion — dated policies, deployment records and training logs
  • Maintained, not one-off — frameworks get revised, and your program has to keep up
  • Reviewed annually — with the review itself documented
Capabilities
What We Do to Get You There

Built primarily on the Microsoft security stack, because most companies your size already own most of it. The controls SB 2610 expects are largely the controls we already deploy — the work the statute adds is documenting them well enough to hold up.

Administrative Safeguards
  • Written security policies mapped to your tier
  • Security awareness training with completion records
  • Access control and least-privilege standards
  • Incident response plan and tabletop exercises
  • Vendor and third-party risk documentation
Technical Safeguards
  • Endpoint detection and response (EDR)
  • Device compliance baselines and encryption
  • Vulnerability and patch management
  • Email security and anti-phishing controls
  • Backup and tested restore to defined targets
Evidence & Review
  • Dated deployment and configuration records
  • Control-to-framework mapping for your tier
  • Centralized logging and audit retention
  • Annual program review, documented
  • Evidence package your counsel can actually use
  • Risk register kept current
Why Radtak
Most Breaches Are Not Sophisticated.
They Are Unpatched and Unnoticed.

The incidents that actually hit companies your size are ordinary: a password reused across services, a laptop two months behind on patches, a backup nobody tested, an ex-employee whose account still works. Security vendors sell you a dashboard for this. What it really takes is someone operating the fundamentals every week.

  • Risk assessment before product — defense in depth, not another agent to license
  • A managed IT practice behind it — controls get operated, not just recommended
  • Austin-based, working your hours and on site when it matters
Process
How an SB 2610 Engagement Works

Qualification Call

Headcount, data you hold, and which tier applies to you. Some businesses are closer than they think.

STEP 01

Gap Assessment

Your current controls measured against the framework your tier requires, with the gaps ranked.

STEP 02

Remediation Plan

What has to change, in what order, with what it costs — not a 90-page report you will never read.

STEP 03

Implementation & Documentation

Controls deployed and, just as important, documented and dated so the program is evidenced from day one.

STEP 04

Maintain & Review

Monitoring, patching, access reviews, training and an annual documented review — because the safe harbor only holds while the program is maintained.

STEP 05

This page is general information, not legal advice. Radtak Solutions is a technology company, not a law firm, and nothing here creates an attorney-client relationship or guarantees that your business will qualify for safe harbor under Texas Senate Bill 2610. Whether the statute applies to you, and whether a given program satisfies it, are legal questions that depend on your specific circumstances and are ultimately decided by a court. Consult a licensed Texas attorney. We build and document the cybersecurity program; your counsel advises you on the law. Summary current as of August 2026 — SB 2610 was signed 20 June 2025 and took effect 1 September 2025.

Austin, Texas skyline at dusk
Get Started
Find Out Whether You
Would Qualify Today.

A free 30-minute call. We will tell you which tier applies to you and how far you are from it.

Check Your SB 2610 Readiness

Full Name
Work Email
Company
How many employees do you have?

We use your details only to reply to you. We never sell your information. See our Privacy Policy.