NAIC Insurance Data Security
NAIC Insurance Data Security Model Law: State-by-State Requirements
What the model law covers, why state adoption varies, and where to verify the requirements that may apply to your organization.
Direct answer
The NAIC Insurance Data Security Model Law provides a framework for insurance cybersecurity, written information security programs, nonpublic information protection, cybersecurity awareness training, vendor oversight, incident response, and executive accountability. States do not all adopt the model in exactly the same way. Some enact a near-complete version, some create a hybrid, and others address similar obligations through separate insurance or data-security laws. NAIC Cybersecurity
Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check
Last reviewed
Scope: The NAIC Insurance Data Security Model Law framework and published state authority pages · Jurisdiction: United States, state by state
General educational and informational content. Not legal, insurance, or coverage advice. Requirements depend on your facts, contracts, policy language, and applicable law.
Three questions this hub helps answer
- Does my state have an insurance-specific cybersecurity requirement?
- Is my state's law a full model adoption, a hybrid, or a materially similar framework?
- What should management, the technical provider, the insurance professional, and legal counsel each understand?
What the model law is
A model law is drafting guidance for state legislatures and insurance regulators. It becomes enforceable only when a state enacts it, or enacts something similar, through its own statute or regulation. The model generally:
- Describes a written information security program based on a risk assessment
- Addresses the protection of nonpublic information
- Addresses cybersecurity awareness training for personnel
- Addresses oversight of third-party service providers
- Addresses investigation of a cybersecurity event and notice obligations
- Addresses executive management or board oversight where applicable
What the model law does not do
- It does not itself create a legal duty in any state. Only a state's enacted statute, regulation, or official guidance does that.
- It does not require every licensee to buy the same products or use the same technology stack.
- It does not determine whether a particular organization is a covered licensee.
- It does not guarantee that a cyber-insurance claim will be covered.
Why state adoption varies
Each state decides whether to enact the framework, which licensees it covers, how notice and certification duties work, and when the requirements take effect. Two states can use similar language and still differ on scope, thresholds, deadlines, and exceptions. For that reason, a state should never be described as having adopted the model simply because it appears in a list. Each page in this hub is built from the state's own statute, code, or regulator guidance.
How each state is classified
- Full or near-full Model #668 adoption
- The state enacted substantially the model framework, including the written information security program and cybersecurity event provisions.
- Hybrid adoption or modified model
- The state enacted a modified version, changing scope, thresholds, notice rules, or certification duties.
- Materially similar insurance cybersecurity framework
- The state imposes comparable insurance cybersecurity obligations through a different statute or regulation.
- Related insurance data-security requirement, but not a Model #668 adoption
- The state has insurance-related data-security duties that do not track the model framework.
- No verified Model #668 adoption located
- Primary-source review did not locate an insurance-specific model adoption.
Published state authority pages
| Jurisdiction | Classification | Law | Last verified |
|---|---|---|---|
| Virginia | Full or near-full Model #668 adoption | Va. Code Title 38.2, Chapter 6, Article 7.1 | September 21, 2026 |
Additional jurisdictions are added only after a page is written from primary sources. This hub does not publish an adoption count, because a count is only accurate once every included state has a verified citation.
Virginia
Virginia's insurance data-security provisions require covered licensees to develop, implement, and maintain a written information security program appropriate to the organization's size, complexity, activities, vendors, and risks, and require the program to provide personnel with cybersecurity awareness training. Va. Code 38.2-623
How these pages are researched
Each page is written from the state's own legislature or official code first, then the state insurance department or bureau, then official regulations, then official bulletins or legislative history, then NAIC material. Secondary sources are used only to locate leads, never as the final authority where a primary source exists. Every published page shows a visible last-verified date and is revisited when the law or official guidance changes.
Start with cybersecurity awareness training
The first practical step for many organizations is cybersecurity awareness training. Ante Up is Infosec Check's introductory cybersecurity awareness training program. It is not a compliance certification, regulatory determination, legal opinion, or complete organizational security-awareness program. It is a starting point for the people who handle nonpublic information every day.
Infosec Check helps insurance agencies and other regulated businesses understand cybersecurity governance, regulatory applicability, executive accountability, and cyber-insurance readiness. Infosec Check does not replace qualified legal counsel, an MSP, MSSP, managed security provider, software vendor, carrier, broker, forensic investigator, or incident-response firm, and regulatory duties may exist independently of whether an organization purchases Infosec Check services.
Related resources
Legal and educational disclaimer
This page provides general educational information and is not legal advice, an insurance coverage opinion, a compliance certification, or a guarantee of claim payment. Laws, regulations, regulatory interpretations, contracts, and insurance policies may change or apply differently to different organizations. Consult qualified legal counsel, the appropriate regulator, and the organization's insurance and technology professionals regarding a specific situation.
Frequently asked questions
What is the NAIC Insurance Data Security Model Law?
It is a model framework developed for state insurance cybersecurity and information security requirements. A state model law is not automatically binding everywhere. The state's enacted statute, regulations, official guidance, and effective dates control.
Why does state adoption vary?
Each state legislature decides whether to enact the model, how to modify it, and which licensees it covers. Some states enact a near-complete version, some create a hybrid, and others address similar obligations through separate insurance or data-security laws.
Does a written information security program guarantee cyber-insurance coverage?
No. Coverage depends on the policy language, representations, conditions, exclusions, security requirements, and facts of the loss. A governance program may improve preparedness and documentation, but it does not control an insurer's coverage decision.
Does having an MSP mean an agency meets its state's requirements?
No. An MSP may support technical safeguards, but management remains responsible for understanding its information security program, assigning responsibility, overseeing vendors, training personnel, and making documented risk decisions.
Where should an insurance agency begin?
Begin with practical cybersecurity awareness training, assignment of responsibility, identification of nonpublic information, a review of vendors and access, and confirmation that an incident-response plan exists. Ante Up is Infosec Check's introductory cybersecurity awareness training starting point.
Clarify Your Position
How certain are you that your organization could prove its cybersecurity answers today?
A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.
Call Infosec Check
(855) 624-6262