govt.fyi
Back to HB 4132
Oklahoma Legislature· HB 4132Second Reading referred to Technology and Telecommunications

An act relating to technology, the official text

Shown verbatim: the complete text as captured from the official PDF posted by the Oklahoma Legislature, fetched 2026-07-23. Page and line markers are part of the official record; nothing is edited or removed. The official bill page.
1                             STATE OF OKLAHOMA

2   2nd Session of the 60th Legislature (2026)

3 HOUSE BILL 4132             By: Fetgatter

4

5

6                             AS INTRODUCED

7   An Act relating to technology; providing liability

    protections for counties and municipalities that

8   adopt recognized cybersecurity frameworks; providing

    requirements for safe harbor qualification;

9   permitting counties and municipalities to submit

    summary information to State Auditor and Inspector;

10  providing for codification; and providing an

    effective date.

11

12

13

14

15 BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA:

16  SECTION 1.      NEW LAW   A new section of law to be codified

17 in the Oklahoma Statutes as Section 1000 of Title 75A, unless there

18 is created a duplication in numbering, reads as follows:

19  A. No county or municipality shall be held liable in a civil

20 lawsuit for damages resulting from a data breach or cybersecurity

21 incident if, at the time of the breach, the county or municipality

22 had adopted and reasonably conformed its practices to one or more of

23 the following frameworks:

24

    Req. No. 15468                                           Page 1
1   1. The National Institute of Standards and Technology (NIST)

2 Cybersecurity Framework;

3   2. The Center for Internet Security (CIS) Critical Security

4 Controls; or

5   3. The ISO/IEC 27000 series of information security standards.

6   B. To qualify for safe harbor under this section, a county or

7 municipality shall:

8   1. Complete an annual self-certification by the county or

9 municipality information technology officer or designee to the

10 governing body of the county or municipality affirming conformity to

11 the selected framework;

12  2. Maintain documentation and records demonstrating

13 implementation of cybersecurity practices, including, but not

14 limited to, policies, asset inventories, multifactor authentication,

15 patching, backups, employee training, incident response, business

16 continuity, and disaster recovery plans; and

17  3. Obtain an independent review by a qualified external

18 assessor not less than once every three (3) years, with the

19 resulting report to be retained by the county and deemed

20 confidential pursuant to the Oklahoma Open Records Act.

21  C. A county or municipality may voluntarily submit summary

22 information regarding its self-certification or independent review

23 to the State Auditor and Inspector for the purpose of statewide

24 benchmarking and education.

    Req. No. 15468                                                  Page 2
1   SECTION 2. This act shall become effective November 1, 2026.

2

3   60-2-15468      MJ  12/29/25

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

    Req. No. 15468                Page 3
Every fact on this page links to its source, starting with the official bill record.