Texas's security posture rests on three enacted state statutes plus one new state cybersecurity-coordination body whose reach to a private operator is contractual rather than a status-based duty, and it has no separate connected-device or product-security statute.
The Identity Theft Enforcement and Protection Act's Business and Commerce Code Section 521.052, added by Acts 2007, 80th Leg., R.S., Ch. 885 (H.B. 2278), effective April 1, 2009, requires any business, a financial institution as defined by 15 U.S.C. § 6809 excepted, to implement and maintain reasonable procedures, including appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information it collects or maintains in the regular course of business, and to destroy or arrange for the destruction of customer records containing that information once it is no longer to be retained; the section states no further content for what 'reasonable' requires beyond that general standard.
The Texas Data Privacy and Security Act (H.B. 4, 2023), Business and Commerce Code Section 541.101(a)(2), effective July 1, 2024, layers a second, narrower security duty onto any controller the chapter reaches, a person conducting business in Texas or producing a product or service consumed by a Texas resident, that processes or sells personal data and is not a small business as defined by the United States Small Business Administration: to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue, for the purpose of protecting its confidentiality, integrity, and accessibility.
S.B. 2610 (2025), Business and Commerce Code Chapter 542, effective September 1, 2025, is a genuine security instrument built as an incentive rather than a mandate: a business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information may not be held liable for exemplary damages in an action arising from a breach of system security if it demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program conforming to a named industry framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, the HITRUST Common Security Framework, the Secure Controls Framework, SOC 2, or a similar framework), scaled to size: simplified measures such as password policies and employee training for an entity with fewer than 20 employees, the CIS Controls Implementation Group 1 for one with 20 to 99 employees, and full conformance with a named framework for one with 100 to 249 employees.
No enacted Texas statute sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's connected-device statute or the Cyber Resilience Act; this is a researched absence rather than a gap in coverage.
Texas has no general private-sector duty to report an exploited vulnerability or a security incident to an authority: House Bill 150 (2025), effective September 1, 2025, created the Texas Cyber Command (Government Code Chapter 2063) as a state coordination body, and a private entity operating critical infrastructure becomes a 'covered entity' bearing reporting and coordination duties only if it contracts with the Command for cybersecurity services, a contractual relationship rather than a status-based regulatory duty the LexLint activity vocabulary can express, so it is recorded here rather than flagged on a guess or filed as an instrument.
Section 521.052 is enforced solely by the attorney general, who may recover a civil penalty of $2,000 to $50,000 per violation and injunctive relief under Section 521.151; Section 541.101 is enforced solely by the attorney general under the Texas Data Privacy and Security Act's own exclusive-enforcement provision, Section 541.151, after a mandatory 30-day cure notice under Section 541.154, with a civil penalty of up to $7,500 per violation under Section 541.155 and no private right of action under Section 541.156.
Texas's breach-notification duty, Business and Commerce Code Section 521.053, the other half of the Identity Theft Enforcement and Protection Act, is already this jurisdiction's privacy row rather than repeated here.
The Texas Data Privacy and Security Act's own data-security duty, section 541.101(a)(2), belongs to the privacy topic rather than here: it is one subsection of the comprehensive regime addressed to a controller, the same place the General Data Protection Regulation's Article 32 sits, and the chapter's other controller duties are already researched there.