Cyber Civilian Corps Act
· About Cyber Civilian Corps Act
Key Takeaways
- The Cyber Civilian Corps Act applies in Michigan and creates a statutory volunteer cybersecurity program administered by the Department of Technology, Management and Budget (DTMB) to support responses to cybersecurity incidents.[1][2]
- The act authorizes deployment of civilian experts to assist municipal, educational, nonprofit, and critical infrastructure organizations during cybersecurity incidents, including data breaches, when invited by DTMB.[1][2][3]
- The law took effect on 24 January 2018, and the current codified text reflects amendments enacted by 2020, Act 288 and related history notes showing an effective date of 24 March 2021 for amended sections.[1][3][4]
- Volunteers must enter a volunteer agreement and are subject to background screening, including fingerprint-based criminal history checks, before serving in the program.[2][8]
- The act provides tort-liability immunity for the state and department for acts or omissions by volunteers under the act, and it also grants volunteers protection from liability when acting within scope and without gross negligence or material breach of the agreement.[6][13]
- There is no general private-sector compliance obligation to join the corps; the statute mainly governs state program administration, volunteer eligibility, and incident-response authority rather than imposing a broad regulatory regime on Michigan businesses.[1][2][3]
What It Is
The Cyber Civilian Corps Act is Michigan Public Act 132 of 2017, codified at Michigan Compiled Laws sections 18.221 to 18.230, and it creates a volunteer program under which cybersecurity professionals may provide rapid-response assistance during cybersecurity incidents.[2][7] The act is enforced through the Department of Technology, Management and Budget (DTMB) and an advisory board established by the statute.[2][8]
The act was enacted in 2017 and became effective 24 January 2018.[1][2][7] The codified history shows amendments in 2020, Act 288 and related section history entries with amended provisions effective 24 March 2021.[1][3][4] No later 2025–2026 amendment is identified in the codified materials reviewed here, so any claimed 2025–2026 changes should be treated as unconfirmed unless a newer enrolled bill or session law is produced.[1][3][4]
Who Must Comply
The statute primarily binds the State of Michigan, DTMB, the advisory board, and volunteers who enter the program rather than regulated private companies as a class.[1][2] A Michigan cyber civilian corps volunteer is an individual who has entered into a volunteer agreement with DTMB to serve as a deployable volunteer in the corps.[3][13]
The program’s operational reach includes municipal, educational, nonprofit, and critical infrastructure organizations that request or receive assistance during a cybersecurity incident.[2][3] The law also contemplates assistance in response to incidents involving data breaches as part of the broader concept of a cybersecurity incident.[2][5]
Exemptions are not framed as industry carve-outs in the usual compliance-law sense; instead, the act defines who may volunteer, who may be assisted, and when DTMB may deploy help.[2][3] The statutory protections for the state and volunteers are conditioned on acting within the program’s scope and not engaging in gross negligence or a material breach of the volunteer agreement.[6][13]
Core Requirements
- Create and maintain the program. DTMB must administer the Michigan cyber civilian corps as a state volunteer capability for incident response.[2][8]
- Use a volunteer agreement. A participant must enter a written volunteer agreement with DTMB before serving as a deployable volunteer.[3][13]
- Screen volunteers before deployment. Volunteers must consent to background screening, including criminal history checks and fingerprinting, before participating in program activities.[2][8]
- Deploy only for authorized assistance. DTMB may invite or appoint qualified civilians to provide rapid response assistance to eligible organizations during cybersecurity incidents.[2][3]
- Observe liability conditions. Volunteer and state immunities depend on acting within the statutory scope, avoiding gross negligence, and not materially breaching the volunteer agreement.[6][13]
- Support governance and oversight. The advisory board reviews policies and procedures connected to the corps and its operation.[2][8]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Act enacted | 2017 | Public Act 132 of 2017 creates the volunteer cyber corps program.[2][7] | | Act effective | 24 January 2018 | The program takes effect and becomes operational in statute.[1][2][7] | | Amended provisions effective | 24 March 2021 | Codified history notes amendments from 2020, Act 288, taking effect for relevant sections.[1][3][4] |
The act does not set a civil money-penalty schedule or criminal penalty scheme for ordinary noncompliance by private entities.[1][2] The principal consequence structure is liability allocation: the state and DTMB generally receive tort immunity for acts or omissions by corps volunteers, while volunteers lose protection if they act with gross negligence or materially breach the agreement.[6][13] In practical terms, the sanctions are contractual and tort-based rather than administrative fines.[6][13]
How to Comply
- Map whether the statute touches your organization. Michigan public-sector entities, nonprofits, and critical infrastructure operators should determine whether they may seek MiC3 assistance and who has authority to request it.[2][3]
- Build incident-response triggers. Align the decision to request external volunteer help with your incident-response plan, using NIST CSF 2.0 functions for Identify, Protect, Detect, Respond, and Recover as the operational frame.[2][8]
- Pre-negotiate governance. If your organization may request corps support, define approval authority, data-access limits, and on-site escort requirements before an incident occurs, and document those rules in your response playbooks.[2][3]
- Integrate vendor and volunteer controls. Treat corps volunteers like privileged emergency responders: issue least-privilege access, time-bound credentials, logging, and supervision consistent with ISO 27001 access-control and incident-management concepts.[6][13]
- Maintain evidence and chain of custody. Preserve logs, ticket history, and forensic artifacts so volunteer work can be reviewed, validated, and, if needed, separated from internal remediation activities.[2][6]
- Assess cybersecurity governance maturity. Use ISO 42001 where your organization deploys AI-enabled security tools or automated triage in incident response, so human oversight, risk treatment, and documentation are explicit.[2]
- Train leadership and counsel. Ensure legal, privacy, and security leaders understand that the act is a response-capability statute, not a substitute for breach-notification law or regulatory reporting duties under other regimes.[1][2][6]
Related Regulations
Michigan data-breach notification laws overlap because organizations suffering an incident may need to notify affected individuals and regulators even when MiC3 assists with containment.
NIST CSF 2.0 is not a law, but it aligns closely with the incident-response, recovery, and governance processes that a corps-assisted response should follow.
ISO 27001 overlaps on access control, incident management, and supplier-like oversight for external responders, even though the act itself is a state-response statute.
ISO 42001 may conflict only if AI-driven security tools are deployed without governance; the act does not regulate AI directly, but modern response operations should document human oversight and accountability.
FAQ
Does the Cyber Civilian Corps Act apply to private companies in Michigan?
Not as a direct licensing or registration law. The statute mainly creates a state-administered volunteer response program and identifies eligible recipient organizations such as municipal, educational, nonprofit, and critical infrastructure entities.[2][3] Private companies are implicated only if they are part of the eligible response ecosystem or are otherwise affected by a cyber incident.
Does the law require organizations to use MiC3 during a breach?
No mandatory-use rule appears in the statute. DTMB may deploy volunteers when invited or appointed under the act, but the law does not make corps assistance a universal legal requirement for incident response.[2][3] Organizations should treat MiC3 as an optional emergency resource, not a substitute for their own response plan.
Are volunteers protected from liability?
Yes, but only within limits. The statute provides protection tied to acting within scope, avoiding gross negligence, and not materially breaching the volunteer agreement.[6][13] The state and department also receive tort-liability protection for volunteer acts or omissions under the act.[6]
When did the law take effect?
The act was effective 24 January 2018.[1][2][7] Codified history also reflects amendments effective 24 March 2021 for sections changed by 2020, Act 288.[1][3][4]
Were there 2025–2026 amendments or delays?
No 2025–2026 amendment was identified in the codified sources reviewed here.[1][3][4] If a 2025–2026 bill or enrolled act exists, it would need to be confirmed from the Michigan Legislature’s session-law record before treating it as current law.
Who can receive help from the corps?
The statute’s coverage includes municipal, educational, nonprofit, and critical infrastructure organizations facing cybersecurity incidents.[2][3] The program is designed for rapid technical assistance during an incident, not for routine managed-security services.[2][5]
Sources
- Michigan Legislature, MCL 18.230
- Michigan Legislature, Cyber Civilian Corps Act, Act 132 of 2017 (PDF)
- Michigan Legislature, MCL 18.222
- Michigan Legislature, MCL 18.225
- Michigan Legislature, House Bill 4508 analysis as enacted
- Michigan Legislature, MCL 18.227
- CISA, Michigan Cyber Civilian Corps (MiC3)
- NGA, Re-Envisioning State Cyber Response Capabilities: The Role of Volunteers in Strengthening Our Systems
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)