The U.S. privacy map has grown far more complex. In 2025, eight new comprehensive state privacy laws took effect. That brings the total to twenty states.
Do you handle consumer data? Then this patchwork is a test of your compliance. It also shifts how you guard data and fix flaws.
The European Union has one rule book, the General Data Protection Regulation (GDPR). The United States does not. It keeps building privacy law state by state.
The parts share common themes, but the details differ. That creates real headaches when you work across state lines.
By the end of 2025, about 150 million Americans will be covered by comprehensive state privacy laws. That is 43% of the population.
Here is why this matters to your team. Nearly every state privacy law either names vulnerability management or demands it in practice.
The link is clear. You cannot protect personal data unless you find and fix the holes that expose it.
This guide maps where state privacy laws meet vulnerability management. It gives you a plan for multi-state compliance and a defensible security posture. Maybe you are a defense contractor who must meet CMMC (Cybersecurity Maturity Model Certification) requirements and state privacy duties at once.
Maybe you run a healthcare team that must balance the Health Insurance Portability and Accountability Act (HIPAA) with state data protection law. Either way, you need to know this ground.
Congress has not passed a comprehensive federal privacy law. So the states now set the pace on privacy and security. The count has climbed fast:
At that point twenty comprehensive state privacy laws will be in force. That is just seven years after California passed the trail-blazing California Consumer Privacy Act (CCPA).
The pace is not slowing. Sixteen more states are weighing privacy bills right now.
Some are still in drafting, and some are deep in debate. Within a few years, most Americans will be covered.
California (CCPA/CPRA): California still sets the bar. In September 2025 the California Privacy Protection Agency (CPPA) finalized new rules. The new rules cover four areas:
Some businesses must now run a yearly cybersecurity audit. They must also finish a privacy risk assessment before any high-risk data processing.
The CCPA also gives consumers a private right of action, which matters a lot for security. Say personal information that was not encrypted or redacted is stolen in a breach.
Consumers can then sue for statutory damages of up to $750 per incident. The claim turns on whether the business failed to keep reasonable security procedures and practices. Weak vulnerability management now carries a direct price tag.
New York (23 NYCRR Part 500): This rule comes from the New York Department of Financial Services. It is a financial services rule, not a comprehensive privacy law. Even so, it sets some of the strictest demands in the nation.
The November 2023 amendments phase in through November 2025. They tell covered entities to run penetration testing once a year. Covered entities must also run vulnerability assessments twice a year.
Since May 2025, covered entities must also run automated vulnerability scans. They must review by hand any system the scans do not reach.
Part 500 also requires a full asset inventory by November 2025. For each asset you track:
Other states may copy this blueprint.
Florida Digital Bill of Rights: Florida ties its security duty straight to a federal framework. The final rules tell regulated industries to follow the NIST risk management framework SP 800-37.
Follow it and you meet the state's duty. That is a big step toward hard security baselines in state privacy law.
Tennessee Information Protection Act: Tennessee adds a rare affirmative defense. A business can avoid liability by showing it reasonably conforms to the NIST Privacy Framework. Some certification programs count too, such as the Asia Pacific Economic Cooperation's Cross Border Privacy Rules system.
No other state offers this safe harbor. It rewards firms that invest in known frameworks.
New Jersey Data Privacy Act: New Jersey's law took effect in January 2025. It bars high-risk processing unless you first run and record a data protection assessment. Colorado takes the same tack.
The link to security is direct. The assessment must weigh the safeguards that protect personal data.
Maryland Online Data Privacy Act: Maryland wrote one of the strictest data minimization rules in the nation. You may process sensitive data only when it is strictly necessary. The service must be one the consumer asked for.
That is a high bar. You need full sight of what you process, plus strong vulnerability management for the data you do keep.
Nearly every state privacy law and breach notice statute calls for "reasonable security" measures. Yet lawmakers skip the technical detail on purpose. They know it sits outside their expertise.
They also know it would date fast. The word "reasonable" comes from tort law, where courts judge each case on its own facts.
With no official definition, you must look to regulator guidance and industry standards. Take the 2016 California Data Breach Report, issued when Kamala Harris served as Attorney General.
It points to the Critical Security Controls from the Center for Internet Security as a baseline. It also urges strong encryption and multi-factor authentication.
Experts note that many other standards could serve just as well, from ISO 27001 to the NIST CSF. In breach lawsuits, courts rarely settle the question by asking if you followed one named framework. They ask whether you took reasonable care overall.
Legal review of CCPA breach cases points to a few clear rules. Courts weigh these when they judge reasonable security:
Reasonableness always calls for balance. The level of security must fit the risk and the cost of more safeguards. That matters here.
You must rank fixes by risk. You cannot chase every finding at once.
The NIST CSF 2.0 came out in February 2024. It is now the best known framework in the country. New York's Part 500 rule is built around the CSF core functions: Identify, Protect, Detect, Respond, and Recover.
CSF 2.0 added a new Govern function. It lines up with the governance duties that keep showing up in state privacy laws.
NIST also put out a draft update to its Privacy Framework in April 2025. The draft is built to align with CSF 2.0.
That merger of privacy and security frameworks mirrors the law, because the two fields now overlap. Run both frameworks as one program and you will find it much easier to show compliance across many states.
The tie between frameworks and legal defense keeps getting stronger. Tennessee grants an affirmative defense for NIST Privacy Framework compliance. Florida demands NIST SP 800-37.
Both signal a trend. States are writing known frameworks into law. Align with them early and you stand on firmer ground if your security is ever questioned.
Most state privacy laws speak of reasonable security in broad terms. A few name the work outright. New York's 23 NYCRR Part 500 is the most exact.
Covered entities must run penetration testing once a year. They must run vulnerability assessments twice a year. Both sit inside the cybersecurity program.
The May 2025 changes to Part 500 go further. Covered entities must run automated scans and review by hand any system those scans miss.
The schedule for reporting and fixing what the scans find must come from the entity's risk assessment. That ties risk work straight to fix deadlines.
California's new CCPA rules take effect in 2026. They tell some businesses to run a yearly cybersecurity audit.
Guidance is still shaping the exact scope. Even so, scans and penetration testing should be core parts of it.
You may reuse a security report written for another purpose. It just has to meet every rule. So a NIST CSF 2.0 audit could satisfy California.
Some states never name vulnerability management, but the reasonable security standard still demands it. You cannot claim reasonable measures if you have never checked your systems for flaws.
The CIS Controls, cited far and wide as a baseline, list Control 7 (Continuous Vulnerability Management) as a foundation. Regulators expect reasonable security measures. That means regular scans and tests, risk assessments, and fixes for the weak spots you find.
Many enforcement actions start with a breach. Investigators then ask whether you ran regular checks before it. If you have no records, your legal exposure grows fast.
The upshot is simple. This work is not optional under state privacy law. Named or implied, you need a steady process to find, rank, and fix flaws.
All fifty states have data breach notification laws. So do the District of Columbia, Guam, Puerto Rico, and the U.S. Virgin Islands. These laws raise the stakes by pinning real cost to breaches you could have stopped.
Recent amendments tightened the clocks. New York now wants notice within 30 days of finding a breach. Colorado, Florida, Maine, Washington, and California also set fixed windows.
Shorter clocks mean you need a mature incident response. That depends on knowing your security posture, which comes from steady scans and tests.
Many states now write security duties into the breach statutes too. Pennsylvania's 2024 amendments stand out. Say a breach exposes Social Security numbers, driver's license numbers, or bank account numbers.
You must then give 12 months of free credit monitoring. That is one more cost of a security failure you could have prevented.
State privacy laws are fragmented, which is hard on any team that works across many states. So many firms take a "high-water mark" approach. You apply the strictest rule everywhere instead of running a program per state.
Maryland sets two strict rules. Sensitive data may be processed only when it is strictly necessary, and selling it is banned per se. For firms that take this route, those rules may become the de facto national baseline.
For vulnerability management, that means meeting the toughest state bar. Use New York's Part 500 as your practical benchmark:
Hiring qualified pros for network penetration testing gives you full coverage across your estate.
This approach pays off in three ways:
The right framework is the backbone of multi-state compliance. NIST CSF 2.0 is the best known choice, and it links to many state rules.
Its core functions are Govern, Identify, Protect, Detect, Respond, and Recover. They map well to what state privacy laws expect.
Look at the CIS Controls too. They give sharper how-to guidance.
The 2016 California Data Breach Report names them as a baseline for reasonable security, and industry has adopted them widely. Control 7 (Continuous Vulnerability Management) and Control 18 (Penetration Testing) spell out how to run the work state laws call for.
Want a certified route? ISO 27001 gives you an auditable framework. It shows regulators and partners that you take security to heart.
But ISO alone may not meet every state rule. Check that your ISO program covers the exact practices your states require.
Privacy law and security law keep converging, so manage them as one program. Privacy risk sits close to security risk, and the two often overlap.
Treat them as separate chores and you will double the work. You will also miss the links between rules.
NIST saw this too and aligned Privacy Framework 1.1 with CSF 2.0. The update adds a section on how AI tools create privacy risk.
An AI system can leak facts about people through data reconstruction, prompt injection, or membership inference. If you use AI, fold those risks into both your privacy work and your vulnerability management.
In practice, that means three things:
A virtual Chief Information Security Officer (vCISO) can steer all of it without the cost of a full-time hire.
Good vulnerability management starts with finding your assets. You cannot protect what you do not know you have.
You also cannot judge the risk of a flaw until you know which systems process personal data. New York's Part 500 asset inventory deadline of November 2025 shows this.
Your inventory has to reach past normal IT. Include operational technology, Internet of Things (IoT) devices, cloud services, and shadow IT. Part 500 says "information systems" covers special gear as well:
Make sure your discovery sweeps that far.
Map your data at the same time. Note which systems store, process, or send personal data. That map lets you rank fixes by risk.
It puts your effort where a breach would hurt privacy most. It also helps with data minimization rules in states like Maryland, since it exposes data you do not need.
Regular scanning is the base of any program built for compliance. Use automated tools that cover the whole estate:
Let risk set the pace. Scan critical systems more often.
Scanning alone is not enough. Part 500 requires manual review of systems the scans do not reach. Many flaws hide from tools, such as logic flaws, bad settings, and business logic errors.
Manual penetration testing by skilled pros closes that gap. If you ship web or mobile apps, add application penetration testing to find flaws in your software.
Run network penetration testing at least once a year. Test more often in high-risk settings or after big changes.
Application penetration testing matters just as much if you build or host web and mobile apps. Use certified testers who can spot the complex flaws that tools miss.
Not all flaws are equal, and you cannot fix them all at once. Ranking by risk puts your effort where personal data is most at stake.
Weigh two things. How severe is the flaw? How sensitive is the data behind it?
The Common Vulnerability Scoring System (CVSS) gives you a severity baseline, and you add your own context on top. The Exploit Prediction Scoring System (EPSS) rates the chance that a flaw will be exploited in the next 30 days. That helps you chase live threats, not theory.
How critical the asset is counts just as much. Say a medium-severity flaw sits on a system that holds sensitive personal data. It may deserve a faster fix than a high-severity flaw on a lone test box.
Set your fix deadlines from that combined risk view. Write down the method. Then you can show your security was reasonable.
Finding flaws only pays off if you fix them. Feed findings into your normal change management so IT can act.
Name an owner, set a due date, and hold people to it. That is what drives fixes to done.
Then check the work. Rescan or retest after each fix. Confirm that it worked and broke nothing new.
Write down the result. If a breach is ever probed, that record shows due diligence.
Some flaws cannot be fixed right away. In that case, put compensating controls in place and log them.
They should cut how easy the flaw is to exploit, or cut the harm it can do. Keep them until a real fix ships.
Taking the risk instead of fixing it is a management call. Make it at the right level and log it in the risk assessment.
Records are how you prove compliance with state privacy law. Missing records are often read as proof of weak security.
After a breach probe or an enforcement action, you must show three things:
Your vulnerability management file should hold:
New York's Part 500 requires audit trail records to be kept for not fewer than five years.
Map your program to the rules that apply to you, and write that map down. It shows you complied on purpose, not by luck. That strengthens your hand in any legal fight.
California's new cybersecurity audit rules make some businesses file a yearly audit report. You do not have to hand these to regulators up front.
But the CPPA or the Attorney General can subpoena them in an investigation. They may also be discoverable in a lawsuit after a breach.
So think hard about how those reports get written, reviewed, and stored. Bring in legal counsel where it fits. Careful handling helps keep sensitive detail from cutting against your own legal interests.
At the same time, the report must be thorough, accurate, and done by pros. Avoid careless, speculative, or poorly considered statements, which can be twisted and used against you in a legal fight.
Experienced cybersecurity advisors can help you strike that balance.
State privacy laws keep moving. Regulators issue guidance, enforcement actions set precedent, and new laws add duties.
Your program has to keep pace. Review it often against current law and best practice.
The NIST CSF tier model is a handy way to gauge maturity. Aim to climb the tiers in order:
Higher tiers track with better security and a stronger compliance stance.
Set metrics and key performance indicators to track how well the program works. Useful ones include:
Report to leadership on a set cadence. It shows the firm is serious about security. It also helps leaders decide where to spend.
Firms in the Defense Industrial Base juggle three sets of rules: CMMC 2.0, NIST SP 800-171, and state privacy law. CMMC guards Controlled Unclassified Information (CUI). But these same firms also handle personal data that state privacy laws cover.
The good news is the overlap. CMMC's vulnerability management duties line up well with what state privacy laws expect. NIST SP 800-171, which CMMC maps to, tells you to:
So put your CMMC work to double duty. A secure enclave that walls off sensitive defense data can shield personal data too. A program built for CMMC will often clear the state privacy bar with room to spare.
Financial firms carry the heaviest load. They answer to three layers of rules:
Those layers overlap and sometimes clash. The business still has to run.
The SEC's 2024 amendments to Regulation S-P added broad customer notice duties and incident response program rules. Large entities face deadlines in December 2025.
These federal rules add to state duties rather than replace them. Plan both streams of work together.
Treat Part 500 as your baseline vulnerability management standard. It is specific, and the regulator enforces it hard.
Meeting Part 500 will often satisfy or beat other states. Just check for state-specific clauses that reach beyond New York.
Healthcare teams must square HIPAA with state privacy law. A new class of health data privacy laws now reaches past HIPAA as well.
Washington's My Health My Data Act took effect in March 2024. It covers consumer health data that HIPAA does not. It also gives people a private right of action.
The Department of Health and Human Services publishes an official crosswalk. It maps HIPAA Security Rule duties to the NIST CSF.
That makes CSF a strong bridge between federal and state work. The HIPAA Safe Harbor Law helps too.
It tells regulators to weigh your use of recognized security practices, above all NIST-based ones. That applies when they set fines and audits after a breach.
Make sure your scans and tests cover every system that processes health data, not just the ones HIPAA names. Think of patient portals, wellness apps, and connected medical devices.
They may fall under state health data privacy laws even when HIPAA does not apply. Hold one standard across the whole data estate.
A federal privacy law is still an open question. Bipartisan drafts such as the American Data Privacy Protection Act have been filed. Politics and lobbying have stalled them.
The sticking points repeat:
California has pushed back hard on any preemption that would weaken its Consumer Privacy Act. Other states with strong privacy laws may fight federal standards that cut protection for their residents.
So even if a federal bill passes, it may leave much of state law intact. Multi-state compliance would still be your job.
Do not wait on Washington. State law keeps getting stricter no matter what Congress does. Build a solid vulnerability management program now and you will be ready either way.
State attorneys general now work together more and more, so you need to know the scope of each law now. One action in one state can spark probes in others, and the costs multiply fast.
Recent cases show regulators are testing whether opt-out systems, cookie banners, and request portals really work. So audit and test your privacy controls often, above all the ones a third party runs. Fold live testing of those tools into your security assessment program.
Connecticut settled with TicketNetwork in the first money penalty under the Connecticut Data Privacy Act. The lesson is plain. Regulators are running sweeps.
They have little tolerance for flawed notices or broken systems. They have even less for firms that drag their feet on cure notices. Get ahead of it.
AI brings fresh privacy and security problems. NIST Privacy Framework 1.1 adds a section on how AI tools create privacy risk.
It names data reconstruction, prompt injection, and membership inference attacks. If you deploy AI, build those risks into your security program.
Shadow AI is the unauthorized use of AI tools by staff, and it adds real risk. Recent research puts the added cost at an average of $670,000 per breach.
It also finds that 20% of breaches involve unauthorized AI tools. Your scans and tests must reach AI systems and the data they process.
California's new ADMT rules give consumers an opt-out right. It applies when the tech replaces, or largely replaces, a human decision. If you use AI in decisions that affect consumers, you need proper controls and clear disclosure.
State privacy law and vulnerability management now meet head-on. That crossroads is one of the toughest compliance problems U.S. firms face. Twenty states, each with its own terms, duties, and enforcement, call for a sharp and coordinated answer.
There is upside in the mess. Build a strong program on a known framework and you get more than compliance, because you also get better security. The spend pays you back in lower breach risk, cheaper incident response, and greater customer trust.
The keys to success are clear:
Putting those in place is easier with help. Look for cybersecurity advisors who grasp both the tech and the law.
The stakes are high and the rules are dense. Contact Essendis today.
We can walk you through our vulnerability management services, penetration testing, and vCISO support. Each one moves you toward multi-state privacy compliance and a defensible security posture.
It varies by state, but New York's Part 500 is a good yardstick. It calls for penetration testing once a year. It also calls for vulnerability assessments twice a year for covered financial services entities.
If several state laws apply to you, run quarterly scans plus a yearly penetration test. That gives you a defensible posture. Scan critical systems, and any system that holds sensitive personal data, more often.
NIST CSF 2.0 is the best known choice. It links to many state rules, including New York's Part 500. Tennessee's law lets NIST Privacy Framework compliance serve as an affirmative defense.
Weigh the CIS Controls too, which California's guidance names as a baseline for reasonable security. If you want certification, ISO 27001 gives you an auditable framework that shows you take security to heart.
A breach alone does not prove your security procedures were unreasonable. Courts accept that breaches happen even with reasonable security measures. You will, though, need to show the right measures were in place before it.
Scan records, penetration test reports, and fix tracking prove due diligence. Without those records, your legal position gets much weaker.
Weigh two things. How bad is the flaw, and how critical is the asset? Use CVSS and EPSS scores to grade the flaw.
Start with flaws that attackers are exploiting in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) tracks those in its Known Exploited Vulnerabilities catalog.
Next take high-severity flaws on systems that process personal data. Write down your method so your choices read as risk-based, not random.
Yes. New York's Part 500 requires both automated vulnerability scans and manual review of systems those scans do not cover. Scanning gives you breadth and speed across known flaws.
Manual penetration testing gives you depth. It uncovers logic flaws and business logic errors that tools cannot catch. Industry data shows manual tests turn up far more unique issues than scans alone.
New York's Part 500 requires audit trail records for not fewer than five years. California's statute of limitations for CCPA violations is generally three years, though probes can look back further.
As a best practice, keep five years of records: policies, scan results, penetration test reports, and fix records.
Those states still have data breach notification laws. Nearly all of them point back to reasonable security. Say you collect personal data from residents of states that do have comprehensive laws.
That now means about 43% of the U.S. population. Those laws likely reach you no matter where you sit. More states pass such laws each year, so acting early pays.
A mix often works best. In-house teams can test more often, aim at what changed, and watch your posture day to day. Outside vendors bring fresh eyes, deep skills, and the independence some rules demand.
New York's Part 500 requires independent audits of the cybersecurity program. Many firms prefer outside penetration testing to show they are objective. Certified testers give you full coverage and credible results.

