Compliance Resource
Security Legislation & Mandate Tracker
The definitive database of active, enacted, and pending laws requiring security technology upgrades across schools, healthcare, and critical infrastructure. Updated July 13, 2026.

Legislation Database
Search the Legislation Tracker
152 laws shown
Intelligence Brief
The Compliance Landscape in 2026
Alyssa’s Law now covers 16 states with effective or enacted mandates, requiring silent panic alert systems in all public schools. Healthcare workplace violence prevention laws have expanded to 20+ state and federal measures, with Oregon, Washington, New York, Illinois, and Ohio among the most comprehensive. The Joint Commission’s NPG 2a, effective January 1, 2026, now imposes WPV prevention program, training, and worksite-analysis requirements on every accredited U.S. hospital — making this the highest-impact compliance change of the year for healthcare security leaders.
Critical infrastructure security mandates — from NDAA equipment bans to CIRCIA cyber requirements — continue to expand federal obligations for operators of essential services. State consumer privacy laws covering biometric data now number 21 comprehensive statutes, with Alabama, Indiana, Kentucky, and Rhode Island the newest additions; Maryland and Virginia have layered on first-of-their-kind police facial recognition rules. Tennessee added the first AI-in-mental-health-care statute in April 2026 with a private right of action. The EU AI Act’s high-risk obligations were politically deferred to December 2027 by the May 7, 2026 Digital Omnibus agreement, while Connecticut’s SB 1295 amendments rewrite the CTDPA effective July 2026 — both reshape the compliance posture for biometric and video-analytics deployments. Compliance deadlines in 2026 are accelerating action across every sector.
Compliance Intelligence
Understand Your Compliance Obligations
IntelliSee monitors this legislative landscape continuously, helping organizations in education, healthcare, and critical infrastructure identify which laws apply to their facilities — and what technology investments are required to meet them.
Legislation & Compliance FAQ
Common questions about security mandates, compliance deadlines, and how IntelliSee helps meet regulatory requirements.
What states have enacted Alyssa’s Law?
As of May 2026, Alyssa’s Law or functionally equivalent silent panic alert legislation has been enacted in 16 states: New Jersey, Florida, New York, Texas, Tennessee, Utah, Virginia, Oklahoma, Georgia, Louisiana, Maryland, Oregon, Pennsylvania, Washington, and West Virginia, plus Virginia’s wearable expansion (HB 592) and Illinois (HB 1072 / Mobile Panic Alert System Act, effective January 1, 2026). Mississippi, Michigan, and South Carolina have pending legislation; Kentucky’s HB 643 passed the House but failed in the Senate. Federal ALYSSA Act (HR 1524 / HR 6809) has been introduced but not enacted. The law requires K-12 public schools to install silent panic alert systems that connect directly to local law enforcement and first responders.
Does Alyssa’s Law apply to private schools or universities?
Most state-level Alyssa’s Law mandates apply specifically to public K-12 schools. Private schools and higher education institutions are generally not covered by these mandates, though several states have extended requirements to charter schools and certain higher education settings. Organizations beyond the mandate scope often choose to adopt compliant systems proactively to align with safety best practices and position for future grant funding eligibility.
What does a Workplace Violence Prevention Plan require?
State workplace violence prevention laws — particularly for healthcare facilities — typically require a written prevention plan, annual security risk assessment, employee training, incident reporting and tracking systems, and designated safety committees. California SB 553, effective July 2024, sets a broad template requiring all employers to identify hazards and implement controls. Healthcare-specific laws such as New York S5294B (effective September 2026) add requirements for trained security personnel in emergency departments and site-specific security plans. Joint Commission-accredited hospitals must also meet NPG 2a, which became effective January 1, 2026 and applies nationwide to every TJC-accredited facility.
Does IntelliSee help organizations meet NDAA Section 889 compliance?
NDAA Section 889 prohibits the procurement or use of video surveillance equipment from specified Chinese manufacturers — including Hikvision, Dahua, and others — by federal agencies and federal contractors. IntelliSee layers onto existing IP camera infrastructure and is compatible with NDAA-compliant camera systems. For organizations replacing non-compliant cameras, IntelliSee’s deployment model requires no camera replacement, which means compliance upgrades can be prioritized without affecting the IntelliSee implementation timeline.
How quickly can IntelliSee be deployed to meet a compliance deadline?
IntelliSee connects to your existing IP camera infrastructure and begins detection within seconds of deployment — no camera replacement, no network redesign, no extended installation window. A typical facility can be fully operational in hours. For organizations facing a specific compliance deadline, IntelliSee’s team conducts a pre-deployment assessment to identify required detection types, map camera coverage, and confirm integration with existing mass notification or dispatch systems. Contact us to discuss your timeline.
Know Your Obligations. Act Before the Deadline.
Schedule a compliance assessment and see exactly which laws apply to your facilities, what gaps exist in your current security posture, and how IntelliSee closes them.
