The Cybersecurity and Accountability Amendment Act of 2026 requires insurance licensees in the District of Columbia to implement comprehensive data security standards, investigate cybersecurity events, and promptly notify the Commissioner of the Department of Insurance, Securities, and Banking of any such incidents. The bill defines key terms related to cybersecurity, mandates the development of a written information security program with necessary safeguards, and requires regular risk assessments along with annual compliance statements to the Commissioner. Licensees must maintain records of cybersecurity events for at least five years and notify the Commissioner within three business days if an event affects a significant number of consumers or necessitates notifications to other regulatory bodies.

Additionally, the bill introduces specific notification requirements for cybersecurity events involving nonpublic information, including obligations for licensees to inform the Commissioner within three days of learning about an event from a third-party service provider or upon gaining actual knowledge. It also outlines the responsibilities of insurers regarding events involving independent insurance producers and establishes confidentiality for documents related to cybersecurity investigations, protecting them from public disclosure while allowing for sharing with regulatory and law enforcement agencies under confidentiality agreements. The legislation includes exemptions for certain licensees based on size and compliance, and mandates the Commissioner to create rules for implementation, along with a conforming amendment to the Freedom of Information Act to exempt specific information from disclosure.