Michigan has no single cross-sector product-security or cyber-resilience statute.
Its only enacted baseline-security duty is narrow: MCL 445.72a (Sec. 12a of the Identity Theft Protection Act, Act 452 of 2004, added by 2006 PA 566 and effective July 2, 2007) requires a person or agency that maintains a database including personal information about multiple Michigan residents to destroy, or arrange for the destruction of, any data containing an individual's personal information once it is removed from the database and not retained elsewhere for a purpose state or federal law does not prohibit, with retention for an investigation, audit, or internal review expressly permitted; a knowing violation is a misdemeanor punishable by a fine of up to $250 per violation, and the section neither creates a private right of action nor displaces whatever other civil remedy state or federal law might otherwise provide.
This is a disposal-only duty split out of the Act's breach-notification section, MCL 445.72, already this jurisdiction's privacy-topic row; it does not by its own text impose the broader administrative, technical, and physical safeguards program that New York's SHIELD Act (General Business Law 899-bb) or Utah's Protection of Personal Information Act (Utah Code 13-44-201) require, and no other enacted Michigan statute does either.
A broader, comprehensive reasonable-security-procedures duty is pending, not yet law.
Senate Bill 360 of the 2025-2026 Regular Session, as passed by the Senate on August 26, 2025 (Roll Call No. 212, 19-15) and referred to the House Committee on Government Operations the same day, would add a new Section 11a to the Identity Theft Protection Act requiring a person or agency that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a coordinator, identify internal and external risks, include safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures over time; reasonableness would turn on the entity's size, the amount and type of personal information involved, and the cost of the procedures relative to the entity's resources, and an entity that reasonably conforms to NIST CSF 2.0, or is already regulated under and conforms to Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Title V, the Federal Information Security Modernization Act of 2014, or HITECH, would be deemed compliant.
The bill would also add a duty to investigate a suspected breach (proposed Section 11b) and would arm only the Attorney General, through a new civil-investigative-demand and assurance-of-discontinuance framework, with a civil fine of up to $2,000 for a knowing failure to implement or maintain reasonable security procedures and a further $2,000 for a knowing failure to investigate a breach; no provision of the bill as passed by the Senate was located creating a private right of action.
This bill has not been enacted and binds nothing today. It is a reintroduction of Senate Bills 888 through 892 of the 2023-2024 Regular Session, which likewise passed the Senate on December 12, 2024 (Roll Call No. 540, 20-15) and were referred to the same House committee but received no further action before that session ended; as of September 14, 2026 the reintroduced bill remains in the House Committee on Government Operations, with no further recorded action since its Senate passage.
No enacted Michigan statute provides a Utah, Ohio, or Iowa-shaped cybersecurity affirmative-defense safe harbor conditioned on a framework-conforming program.
Senate Bill 672 of the 2021-2022 Regular Session would have added exactly that, an affirmative defense to a tort claim for a person that maintained a written cybersecurity program reasonably conforming to a named framework; it passed the Senate on March 9, 2022 (Roll Call No. 65, 20-17) and was referred to the House Committee on Financial Services the same day, but received no further action before the session ended, and no successor safe-harbor bill has been introduced since.
Senate Bill 360, the currently pending bill, does not include an affirmative-defense provision; it imposes a mandatory duty rather than offering a shield.
Michigan's one sector-specific cyber-resilience regime is the Insurance Data Security Act, MCL 500.550 to 500.565 (Chapter 5A of the Insurance Code of 1956, added by 2018 PA 690 and effective January 20, 2021), adopting the NAIC Insurance Data Security Model Law.
Its core duty, MCL 500.555, requires a licensee (a licensed insurer, producer, or other person licensed, authorized, or registered under the Insurance Code) to develop, implement, and maintain a comprehensive written information security program with administrative, technical, and physical safeguards, board-level oversight, a written incident-response plan, and an annual compliance certification to the Director of the Department of Insurance and Financial Services; MCL 500.559 separately requires a licensee to notify the Director within ten business days of determining that a qualifying cybersecurity event occurred.
Because a licensee is a financial-services-style regulated entity, a role the LexLint activity vocabulary cannot yet express, this regime is deferred rather than flagged on a guess (#6740): no instrument for it is filed here, exactly as New York's parallel regime, 23 NYCRR Part 500, is deferred on this jurisdiction's own row.
MCL 500.550 forecloses a private cause of action for the chapter's violation and states that the chapter sets the exclusive Michigan standards for a licensee's data security, and MCL 500.553's definition of nonpublic information, which names biometric records among other elements, is already this jurisdiction's privacy-topic row rather than repeated here.
No enacted Michigan statute sets security requirements a connected device or software product must meet to be placed on the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, and no enacted Michigan statute imposes a general private-sector duty to report an exploited vulnerability or a security incident to a state authority; the federal Cyber Incident Reporting for Critical Infrastructure Act's reporting duty, not yet in effect pending a final rule, is this jurisdiction's national-layer row rather than a Michigan-specific one.
Michigan's computer-misuse statute, the Fraudulent Access to Computers, Computer Systems, and Computer Networks Act (1979 PA 53), binds a person who accesses a computer system without authorization; it belongs to this jurisdiction's scraping-topic computer_misuse family and is not recorded here, because it binds the intruder rather than the operator or manufacturer this profile researches.