A carrier domiciled in Connecticut with operations across the other Model Law 668 states currently files the same cybersecurity event notification up to 19 times, in 19 formats, through 19 submission procedures, each on its own 72-hour clock running simultaneously.
The NAIC's Cybersecurity (H) Working Group adopted a revised intake form for a centralized notification portal at the Spring 2026 National Meeting, with the Innovation, Cybersecurity and Technology (H) Committee due to vote on adoption at an interim meeting on April 30, 2026.
Key Takeaways
- 19 states have enacted Model Law 668 in substantially similar form, each requiring commissioner notification within 72 hours of determining an event occurred that involves the domiciliary state or 250 or more consumers resident in the state.
- The portal is a push system, not a shared repository. The submitter selects which states receive the notification, and only those regulators can see it, which is the direct answer to the concentration-risk objection.
- Cyber premium growth has slowed to roughly 5% compound annual growth since 2023 on Swiss Re's $16.4 billion 2026 projection, partly because the market lacks the loss data granularity to differentiate risk.
- The design that answers the security objection is the one that caps the data's pricing value, since NAMIC's request was that submissions stay high-level rather than centralize granular technical detail.
- A 2023 DHS report counted 52 existing or proposed federal cybersecurity reporting requirements, none of which the portal consolidates.
What the Portal Replaces
The portal collapses one step of a multi-step obligation, and it is worth being precise about which step.
Model Law 668, adopted by the NAIC in 2017, covers information security programs, event investigation, commissioner notification, consumer notification and third-party oversight. The notification trigger sits in Section 6: a licensee must notify its domiciliary commissioner no later than 72 hours after determining a cybersecurity event has occurred, where the event involves its state of domicile or affects nonpublic information of 250 or more consumers resident in that state. The clock starts at determination rather than discovery, which leaves room for an initial investigation first.
For a carrier with policyholders across all 19 adopting states, a ransomware event compromising 50,000 policyholders currently produces 19 separate filings, each potentially with its own portal, form, formatting rules and preferred level of detail, followed by 19 parallel follow-up tracks. Under the portal, the initial notification becomes one standardized submission with the recipient states selected on it.
The architecture is a distribution mechanism rather than a database. A licensee completes one form and selects the states; only regulators in those states can view the submission. That answers the objection NAMIC raised during the Fall 2025 comment period, that a centralized repository of event descriptions would itself become a high-value target whose breach could show threat actors which companies had patched a vulnerability and, by inference, which had not.
The remaining design commitments came out of the same comment process: no licensee fees, SOC 3 reporting on the portal's own controls, a standardized intake form adopted March 13, 2026, and phased development rather than a single deployment. New York is the hardest case, since 23 NYCRR 500 predates the model law and demands more, including a designated CISO and annual penetration testing.
Standardized Records Against an Immature Triangle
The reason this matters beyond compliance hours is that cyber pricing has been constrained by data since the line began, and the portal produces the first uniform incident record across jurisdictions.
Swiss Re projects global cyber premium at $16.4 billion in 2026, with growth down from double-digit rates to roughly 5% compound annual growth since 2023, driven partly by rate deterioration in a market that cannot differentiate risk precisely enough to hold price. Munich Re's 2026 cyber report names the same constraint: better data on risk trends, losses and incidents is the precondition for underwriting and modeling to advance. S&P Global Ratings puts the market at $23 billion of annual premium by 2026 on a wider definition, into tougher competition.
Three things change when 19 states receive the same form instead of 19 different ones. Incident categorization becomes comparable, so events that different states would have classified differently aggregate. Frequency becomes observable by insurer type, size and geography, which is what cyber pricing currently estimates from general industry surveys. And because the portal timestamps notification and states track follow-ups, notification-to-resolution timelines become measurable.
That third one is the reserving item. Cyber loss development triangles remain immature relative to established P&C lines, and a standardized regulatory record of how long different event types take to resolve is a reference point that does not currently exist. The American Academy of Actuaries has put the gap between data needs and data availability at the center of why the market struggles to serve smaller commercial policyholders.
The timing argument is stronger than the accuracy one. William Altman of CyberCube told the Spring meeting that generative AI is letting threat actors "scale, localize, and personalize attacks more effectively," and the Alston & Bird summary records regulators shifting emphasis from breach containment to business continuity. If the attack technology has changed the threat generation rate, a frequency assumption fitted to historical data is understating forward risk, and incident records collected as events are reported signal that turn earlier than an annual survey does.
The Detail That Was Deliberately Left Out
The complication is that the portal's answer to the security objection and its ceiling as a data source are the same decision.
NAMIC asked the Working Group to document an intent that submissions stay high-level, so the portal centralizes notification logistics without centralizing attack vectors, unpatched vulnerabilities or remediation timelines. That is a reasonable trade and it is a trade. The technical depth that would let a pricing actuary distinguish a credential-stuffing loss from a supply-chain compromise is the same depth that would make the repository worth attacking. Standardizing the format helps aggregation; limiting the content limits what aggregation yields.
The reporting stack around it also stays where it is.
| Federal Requirement | Agency | Notification Timeline | Applicability to Insurers |
|---|---|---|---|
| CIRCIA | CISA | 72 hours for cyber incidents; 24 hours for ransomware payments | Applies to covered entities in critical infrastructure sectors; insurers may qualify depending on final rule definitions |
| SEC Cybersecurity Disclosure | SEC | 4 business days for material incidents (Form 8-K) | Publicly traded insurers only |
| GLBA Safeguards Rule | FTC | 30 days for breaches affecting 500+ consumers | Financial institutions including some insurance entities |
| HIPAA Breach Notification | HHS | 60 days for breaches affecting 500+ individuals; annual for smaller breaches | Health insurers and business associates handling PHI |
CIRCIA adds reporting to CISA within 72 hours for covered incidents and 24 hours for ransomware payments, with insurer coverage still depending on how CISA draws the sector boundaries. A publicly traded health insurer with a significant breach files the NAIC portal, a Form 8-K, HIPAA notification to HHS, potentially CIRCIA to CISA, and state attorney general notifications under general-purpose statutes. The DHS count of 52 federal reporting requirements describes the fragmentation before any state insurance obligation is added.
New York is the specific unresolved case. Its DFS system under 23 NYCRR 500 captures more than the model law notification and requires ongoing updates as an investigation proceeds, so the portal has to interoperate with it rather than replace it unless DFS agrees to accept portal submissions as satisfying its own rule. Until that is settled, the carrier most exposed to multi-state filing burden keeps filing twice.
Further Reading
- NAIC Four-Tier AI Risk Taxonomy Redefines Insurer Compliance
- NAIC Proposes Third-Party AI Vendor Registry for Insurers
- NAIC Flags Agentic AI as Insurance’s Next Governance Gap
- The AI Governance Gap in Actuarial Practice
- Cyber Insurance Market 2026: Pricing, Coverage, and Emerging Risks
Sources
- NAIC Cybersecurity (H) Working Group
- NAIC Insurance Data Security Model Law #668 (Full Text)
- NAIC Model Law 668 State Adoption Tracker
- NAIC Model Law 668 State Adoption Map (April 2026)
- NAIC Government Affairs Brief: Insurance Data Security Model Law
- Sidley Austin: NAIC Spring 2026 Regulatory Update (April 14, 2026)
- Mayer Brown: NAIC Spring 2026 H Committee Update (April 2026)
- Alston & Bird: Key AI, Cybersecurity, and Privacy Takeaways from NAIC 2026 Spring Meeting
- Munich Re: Cyber Insurance Risks and Trends 2026
- Swiss Re: Shifting Cyber Insurance Growth Into the Next Gear
- S&P Global Ratings: Cyber Insurance Market Outlook 2026
- American Academy of Actuaries: Cyber Insurance Nears an Inflection Point
- CISA: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)
- DHS: Harmonization of Cyber Incident Reporting to the Federal Government (2023)
- NAIC Cybersecurity (H) Working Group Meeting Minutes