Most Texas contractors don’t have one compliance program. They have a stack of obligations, and each new contract type adds a layer. Every contractor carries Texas breach and data protection duties. Public owners add records and training terms. Federal and defense work adds safeguarding clauses that flow down to subs. This guide sorts those layers, with FY2025 award data on 684 Texas construction contractors. For the wider picture, start with our IT services for construction companies.
IT compliance for Texas contractors is set mostly by the contracts they sign. Every contractor has to protect sensitive personal data and report breaches within 60 days, then public, federal and defense work each add their own security, training and recordkeeping rules on top.
That’s the whole idea. The rest is detail.
I’m a vCIO, so I spend a lot of time with contractors who’ve been told they need to “get compliant” and can’t get a straight answer about what that means. Honestly? It depends on your customer list. A homebuilder selling to families, a GC building a county courthouse and a sub pouring foundations on a military base all live under different rules, even when they run the same software and hire from the same labor pool.
So when I map a contractor’s obligations, I don’t start with a policy template. I start with the contract list. Who pays you, and what did you sign? Everything below follows from those 2 questions.
What does IT compliance mean for a general contractor?
IT compliance for a general contractor means meeting the legal and contractual rules that govern the data your company holds, how you protect it, how long you keep it and who you tell when it leaks. For most builders that data is employee records, subcontractor banking details and project documents owned by someone else.
People underestimate the pile. A mid-sized GC routinely holds all of this.
- Social Security numbers, addresses and pay rates from payroll and onboarding
- Bank routing details for every sub and supplier you pay by wire or ACH
- Injury and illness logs that include medical details
- Drawings, specifications and security plans that belong to the owner
- Bid files and pricing that a public owner may one day have to release
None of that is exotic. It’s just spread across more people, devices and job sites than most industries ever deal with. A project engineer’s laptop in a trailer in Katy carries the same legal weight as a server in the main office. Maybe more, because nobody’s watching it.

Which IT compliance rules apply to every Texas contractor?
The baseline is the Texas Identity Theft Enforcement and Protection Act, Chapter 521 of the Business and Commerce Code. Size doesn’t matter here. It applies to any business in the state. Section 521.052 requires reasonable procedures to protect sensitive personal information and requires you to destroy records you no longer need in a way that makes them unreadable.
Then comes the clock. Under Section 521.053 you have to notify affected individuals no later than the 60th day after you determine a breach occurred. If the breach involves at least 250 Texas residents, the attorney general gets notice within 30 days, through the online form on the attorney general’s data breach reporting page. That 30-day rule dates to Senate Bill 768 in 2023. A 250-person payroll file crosses the threshold on its own. That’s one export.
Penalties are real, too. Section 521.151 sets civil penalties of $2,000 to $50,000 per violation, plus up to $100 per affected person for each day notice is late, capped at $250,000 for a single breach.
Does the Texas privacy law cover contractors?
Usually not. A lot of guides get this wrong. The Texas Data Privacy and Security Act excludes any business that counts as small under Small Business Administration standards, and its definition of consumer leaves out anyone acting in an employment or commercial context. Your employee and subcontractor records don’t make you a covered business. That’s a big carve-out.
SBA thresholds for construction are generous. Under 13 CFR 121.201, building and heavy civil contractors stay small up to $45 million in average annual receipts, and most specialty trades up to $19 million. Big homebuilders are different. A large builder selling directly to families is the case to watch. And one rule still applies. Even small businesses can’t sell sensitive personal data without consent.
What does SB 2610 change?
Senate Bill 2610 added Chapter 542, effective September 1, 2025. It doesn’t order anyone to do anything. It offers a deal. A Texas business with fewer than 250 employees that keeps a qualifying cybersecurity program can’t be hit with exemplary damages after a breach. Shield, not mandate.
Requirements scale with headcount. Under 20 employees, password policies and security training. From 20 to 99, the CIS Controls Implementation Group 1. From 100 to 249, a recognized framework such as the NIST Cybersecurity Framework, NIST SP 800-171, ISO 27001 or SOC 2. Most contractors I talk to sit in that middle tier, between 20 and 99 employees, and very few of them know the offer exists or that CIS IG1 is a published standard anyone can download. Our guide to what SB 2610 requires walks through the tiers in detail.
What changes when you build for a Texas public owner?
Public work brings the Public Information Act onto your servers. Under Sections 552.371 and 552.372 of the Government Code, any contract with a governmental body worth at least $1 million, either on paper or in public funds spent during one of its fiscal years, must require you to preserve contracting information under the owner’s retention schedule. You also have to produce it promptly on request. Promptly means promptly.
Think about what that does to a project file. Their retention schedule, not yours, now decides how long your bid correspondence, change order email and pay application backup must survive. When the contract ends you either hand all of it over or keep preserving it. Your choice. A records request doesn’t care that the PM who ran the job left 2 years ago and that mailbox was deleted.
State agency contracts can add training too. If your people get access to a state computer system or database, the agency must require them to complete a certified cybersecurity training program during the contract and every renewal. Subs included. Officers and employees too.
Here’s a correction worth making. Most guides, and some agency pages, still cite Government Code 2054.5192 for that rule. In 2025, House Bill 150 created the Texas Cyber Command, and the same requirement now sits in Section 2063.104. Agencies report your completion to the Command by August 31 each year. Little changed in substance. Your contract’s citation might.
What do federal construction contracts require?
More Texas contractors hold federal work than most people assume. I pulled FY2025 prime contract obligations from USAspending.gov for construction work performed in Texas. 684 companies received net positive obligations. Total? $4.73 billion. Half received $190,838 or less. And 377 of them, 55%, got under $250,000. Plenty of small shops, in other words.
Homeland Security was the largest buyer at $2.81 billion, followed by Defense at $1.06 billion net, then GSA at $312 million and Veterans Affairs at $210 million, with the Department of Transportation a distant fifth at $47 million. Each of those contracts can carry FAR 52.204-21, which requires 15 basic safeguards on any system that holds Federal Contract Information. Think unique logins, authentication, malware protection, patching, physical access control and sanitizing old drives. It flows down. Every subcontract tier gets it, so a $90,000 electrical sub is on the hook too.
Federal Contract Information is anything the government provides or you generate under the contract that isn’t meant for the public. Submittals count. So do site logistics plans and schedules. It’s a low bar. Most federal jobs clear it on day 1.
Prevailing wage work adds a records problem. The Davis-Bacon rules at 29 CFR 5.5 require payroll records with each worker’s Social Security number, address, phone and email, kept for at least 3 years after all work on the prime contract is complete. Weekly certified payrolls you send out must carry only an identifying number, such as the last 4 digits. Full numbers stay home, protected.
Civilian CUI rules are tightening as well. GSA began applying NIST SP 800-171 Revision 3 to contractors handling Controlled Unclassified Information on January 5, 2026, with third-party assessment, according to Holland and Knight’s summary of the new GSA process. Most construction work won’t touch CUI. Some will.

Does CMMC apply to military construction in Texas?
It can. That same USAspending pull shows 342 contractors with net positive Defense obligations for Texas construction in FY2025, $1.26 billion in total, with a median of $254,906. Construction gets no exemption. Where a solicitation includes the CMMC clause, Level 1 means an annual self-assessment against those same 15 safeguards, and any contractor handling CUI owes the 110 requirements of NIST SP 800-171 under DFARS 252.204-7012.
Timing changed this summer. DoD suspended CMMC Phase 2 on July 13, 2026, and on September 3 a class deviation told contracting officers to remove third-party assessment requirements from contracts, as Washington Technology reported. Recommendations from the reform task force weren’t public as of September 17. Watch this space.
What didn’t pause? Self-assessment, annual affirmations and the underlying controls. If a prime flows the clause into your subcontract, you still owe the work. Our CMMC timeline for Texas contractors tracks the dates as they move.
Which records do contractors have to keep, and for how long?
Retention is where compliance turns into an IT problem. Every rule above assumes you can find a record years later, prove nobody altered it and destroy it safely when the clock runs out. Here are the periods that matter most for a Texas builder.
| Record | Rule | Keep it at least |
|---|---|---|
| OSHA 300 log, 300A summary and 301 reports | 29 CFR 1904.33 | 5 years after the calendar year they cover |
| Davis-Bacon payroll and basic records | 29 CFR 5.5 | 3 years after all work on the prime contract is complete |
| Contracting information on public contracts of $1 million or more | Gov. Code 552.372 | The owner’s retention schedule |
| Project records you’d need to defend a construction defect claim | Civ. Prac. and Rem. Code 16.009 | 10 years after substantial completion is the practical floor |
| Records with sensitive personal information you no longer need | Bus. and Com. Code 521.052 | Destroy them so they can’t be read |
That last row matters. Hoarding isn’t safe either. Old payroll exports sitting in a shared folder are exactly what turns a minor intrusion into a 60-day notification project.
One more correction, because I see it constantly. OSHA’s electronic reporting rule doesn’t require every large contractor to upload detailed case records. Under 29 CFR 1904.41, construction establishments with 20 to 249 employees submit the 300A summary each year by March 2. The 100-employee rule for uploading 300 and 301 detail covers only foundation, structure and building exterior contractors among the construction codes. Check your code first.
That 10-year row shapes storage design most. It’s why the technology stack DFW general contractors need treats retention as its own layer.

How do you map IT compliance to your own contracts?
Start with your contract list, not a framework. This table shows how each type of work stacks onto the baseline.
| Type of work | What it adds | First IT control to prove |
|---|---|---|
| Private commercial or residential | Chapter 521 duties, optional SB 2610 safe harbor | MFA on email and a tested breach response plan |
| Texas public owner, $1 million or more | Contracting information retention and production | Mailbox and project file retention that survives turnover |
| Texas state agency with system access | Certified cybersecurity training for every person with access | Training records by name, renewed each contract term |
| Federal civilian | FAR 52.204-21, Davis-Bacon records where wage rules apply | The 15 safeguards on every device that touches the job |
| Department of Defense | All of the above, plus CMMC and DFARS 252.204-7012 where CUI is present | A current SPRS score you can defend |
Then work through it in order.
- List every active contract and bid, with the owner type and dollar value.
- Pull the cybersecurity, records and training clauses from each one, including flow-downs from primes.
- Map where the covered data actually lives, including field laptops, phones and personal email.
- Pick one framework that covers the strictest contract, usually NIST SP 800-171 or CIS IG1.
- Set retention by record type, and automate deletion for anything past its period.
- Write the breach response plan with the 30-day and 60-day clocks in it.
- Review the list every time you win a new type of work.
Most contractors stall at step 3. It’s messy. It’s also where the real risk lives, because data spreads fastest on job sites. We cover that side in the IT risks that stop Texas construction projects.
Where do Texas contractors usually fall short?
Evidence. Not tools.
In most contractor reviews I run, the right software is already bought and licensed, and the gap sits somewhere far less obvious than a missing product or an expired subscription. MFA is licensed, backups run, and there’s an endpoint agent on most laptops. What’s missing is proof. Nobody can show when MFA was enforced for the superintendents, who approved the exception for the estimator, or whether last quarter’s restore test actually worked. A compliance review asks for exactly those things.
Ownership is the second gap. Compliance tends to land on the controller because the contracts cross that desk, while IT sits with an outside provider who never sees the contracts. Nobody sees everything. Connecting those 2 people fixes more than any new product.
A structured compliance and regulatory assessment closes both gaps fastest, because it ties every control to the contract that requires it. Good news on cost. It’s usually smaller than feared. Our breakdown of construction IT services cost in Texas shows what it adds to a monthly budget.
Questions Texas contractors ask about IT compliance
Does SB 2610 require Texas contractors to have a cybersecurity program?
No, SB 2610 is voluntary. It protects Texas businesses with fewer than 250 employees from exemplary damages after a breach, but only if they already had a qualifying cybersecurity program in place when the breach happened.
Do subcontractors have to follow FAR 52.204-21?
Yes, when the subcontract involves Federal Contract Information. The clause requires primes to include its substance in their subcontracts, so a trade contractor that receives submittals, schedules or site plans on a federal job owes the same 15 safeguards as the prime. The main carve-out is a subcontract for commercially available off-the-shelf items.
Is a general contractor covered by the Texas Data Privacy and Security Act?
Most aren’t. The law exempts businesses that are small under SBA standards, which for building contractors means average annual receipts up to $45 million, and it doesn’t treat employee or business contact data as consumer data. Large homebuilders selling directly to households should check more carefully.
How fast must a Texas contractor report a data breach?
Within 60 days to the affected people, and within 30 days to the Texas attorney general if 250 or more Texans are involved. Both clocks start when you determine the breach occurred. Don’t wait for day 59.
Is CMMC required on military construction contracts in 2026?
Sometimes, at the self-assessment level. Third-party assessments are paused under a September 2026 class deviation, but Level 1 and Level 2 self-assessments still apply where a solicitation includes the CMMC clause, and DFARS 252.204-7012 still applies wherever CUI is involved. Read each solicitation rather than assuming the pause covers you.
How long should a contractor keep project records?
Plan on 10 years after substantial completion for anything you’d need in a defect claim. Shorter legal minimums apply to specific records, such as 3 years after the prime contract for Davis-Bacon payroll and 5 years for OSHA logs, and public owners can set their own schedules.
Not sure which of these rules your contracts actually trigger? Let’s find out. Uprite’s team of 42 supports 2,227 users across Texas, and our vCIOs map contractor obligations clause by clause, then build the controls and the evidence to match.
Speak to an IT Expert








