Skip to main content

NAIC Insurance Data Security

NAIC Insurance Data Security Model Law: State-by-State Requirements

What the model law covers, why state adoption varies, and where to verify the requirements that may apply to your organization.

Direct answer

The NAIC Insurance Data Security Model Law provides a framework for insurance cybersecurity, written information security programs, nonpublic information protection, cybersecurity awareness training, vendor oversight, incident response, and executive accountability. States do not all adopt the model in exactly the same way. Some enact a near-complete version, some create a hybrid, and others address similar obligations through separate insurance or data-security laws. NAIC Cybersecurity

Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check

Last reviewed

Scope: The NAIC Insurance Data Security Model Law framework and published state authority pages · Jurisdiction: United States, state by state

General educational and informational content. Not legal, insurance, or coverage advice. Requirements depend on your facts, contracts, policy language, and applicable law.

Three questions this hub helps answer

  1. Does my state have an insurance-specific cybersecurity requirement?
  2. Is my state's law a full model adoption, a hybrid, or a materially similar framework?
  3. What should management, the technical provider, the insurance professional, and legal counsel each understand?

What the model law is

A model law is drafting guidance for state legislatures and insurance regulators. It becomes enforceable only when a state enacts it, or enacts something similar, through its own statute or regulation. The model generally:

  • Describes a written information security program based on a risk assessment
  • Addresses the protection of nonpublic information
  • Addresses cybersecurity awareness training for personnel
  • Addresses oversight of third-party service providers
  • Addresses investigation of a cybersecurity event and notice obligations
  • Addresses executive management or board oversight where applicable

What the model law does not do

  • It does not itself create a legal duty in any state. Only a state's enacted statute, regulation, or official guidance does that.
  • It does not require every licensee to buy the same products or use the same technology stack.
  • It does not determine whether a particular organization is a covered licensee.
  • It does not guarantee that a cyber-insurance claim will be covered.

Why state adoption varies

Each state decides whether to enact the framework, which licensees it covers, how notice and certification duties work, and when the requirements take effect. Two states can use similar language and still differ on scope, thresholds, deadlines, and exceptions. For that reason, a state should never be described as having adopted the model simply because it appears in a list. Each page in this hub is built from the state's own statute, code, or regulator guidance.

How each state is classified

Full or near-full Model #668 adoption
The state enacted substantially the model framework, including the written information security program and cybersecurity event provisions.
Hybrid adoption or modified model
The state enacted a modified version, changing scope, thresholds, notice rules, or certification duties.
Materially similar insurance cybersecurity framework
The state imposes comparable insurance cybersecurity obligations through a different statute or regulation.
Related insurance data-security requirement, but not a Model #668 adoption
The state has insurance-related data-security duties that do not track the model framework.
No verified Model #668 adoption located
Primary-source review did not locate an insurance-specific model adoption.

Published state authority pages

Published state insurance data security authority pages, with classification and last verified date
JurisdictionClassificationLawLast verified
VirginiaFull or near-full Model #668 adoptionVa. Code Title 38.2, Chapter 6, Article 7.1September 21, 2026

Additional jurisdictions are added only after a page is written from primary sources. This hub does not publish an adoption count, because a count is only accurate once every included state has a verified citation.

Virginia

Virginia's insurance data-security provisions require covered licensees to develop, implement, and maintain a written information security program appropriate to the organization's size, complexity, activities, vendors, and risks, and require the program to provide personnel with cybersecurity awareness training. Va. Code 38.2-623

Read the Virginia insurance data security requirements guide

How these pages are researched

Each page is written from the state's own legislature or official code first, then the state insurance department or bureau, then official regulations, then official bulletins or legislative history, then NAIC material. Secondary sources are used only to locate leads, never as the final authority where a primary source exists. Every published page shows a visible last-verified date and is revisited when the law or official guidance changes.

Start with cybersecurity awareness training

The first practical step for many organizations is cybersecurity awareness training. Ante Up is Infosec Check's introductory cybersecurity awareness training program. It is not a compliance certification, regulatory determination, legal opinion, or complete organizational security-awareness program. It is a starting point for the people who handle nonpublic information every day.

Infosec Check helps insurance agencies and other regulated businesses understand cybersecurity governance, regulatory applicability, executive accountability, and cyber-insurance readiness. Infosec Check does not replace qualified legal counsel, an MSP, MSSP, managed security provider, software vendor, carrier, broker, forensic investigator, or incident-response firm, and regulatory duties may exist independently of whether an organization purchases Infosec Check services.

Legal and educational disclaimer

This page provides general educational information and is not legal advice, an insurance coverage opinion, a compliance certification, or a guarantee of claim payment. Laws, regulations, regulatory interpretations, contracts, and insurance policies may change or apply differently to different organizations. Consult qualified legal counsel, the appropriate regulator, and the organization's insurance and technology professionals regarding a specific situation.

Frequently asked questions

What is the NAIC Insurance Data Security Model Law?

It is a model framework developed for state insurance cybersecurity and information security requirements. A state model law is not automatically binding everywhere. The state's enacted statute, regulations, official guidance, and effective dates control.

Why does state adoption vary?

Each state legislature decides whether to enact the model, how to modify it, and which licensees it covers. Some states enact a near-complete version, some create a hybrid, and others address similar obligations through separate insurance or data-security laws.

Does a written information security program guarantee cyber-insurance coverage?

No. Coverage depends on the policy language, representations, conditions, exclusions, security requirements, and facts of the loss. A governance program may improve preparedness and documentation, but it does not control an insurer's coverage decision.

Does having an MSP mean an agency meets its state's requirements?

No. An MSP may support technical safeguards, but management remains responsible for understanding its information security program, assigning responsibility, overseeing vendors, training personnel, and making documented risk decisions.

Where should an insurance agency begin?

Begin with practical cybersecurity awareness training, assignment of responsibility, identification of nonpublic information, a review of vendors and access, and confirmation that an incident-response plan exists. Ante Up is Infosec Check's introductory cybersecurity awareness training starting point.

Clarify Your Position

How certain are you that your organization could prove its cybersecurity answers today?

A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.

Call Infosec Check

(855) 624-6262
Prefer a return call?

Your information will be used only to respond to this inquiry. See our Privacy Policy.