# Iowa Code § 507F.9: Cybersecurity event third-party service providers

> Iowa · Statutes · In force

URL: https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.9

## Section

- **Citation:** Iowa Code § 507F.9
- **Heading:** Cybersecurity event third-party service providers
- **Jurisdiction:** Iowa
- **Kind:** Statutes
- **Status:** In force
- **Text as of:** August 14, 2026
- **Source:** Compiled text
- **Location:** IA Code / Title XIII / Chapter 507F / Section 507F.9

## Text

(1) If a licensee becomes aware of a cybersecurity event in an information system maintained by a third-party service provider of the licensee, the licensee shall comply with section 507F.7, or the licensee may obtain a written certification from the third-party service provider that the provider is in compliance with section 507F.7. If the third-party provider fails to provide written certification to the licensee, the licensee shall comply with section 507F.7. The computation of the licensee’s deadlines pursuant to section 507F.7 shall begin on the business day after the date on which the licensee’s third-party service provider notifies the licensee of a cybersecurity event, or the date on which the licensee has actual knowledge of the cybersecurity event, whichever date is earlier.

(2) This section shall not be construed to prohibit or abrogate an agreement between a licensee and another licensee, a third-party service provider, or any other party for the other licensee, third-party service provider, or other party to execute the requirements under section 507F.6 or section 507F.7 on behalf of the licensee.

2021 Acts, ch 79, §9, 17

## Nearby sections

- [Iowa Code § 507F.1 Title.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.1.md)
- [Iowa Code § 507F.2 Purpose and scope.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.2.md)
- [Iowa Code § 507F.3 Definitions.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.3.md)
- [Iowa Code § 507F.4 Information security program.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.4.md)
- [Iowa Code § 507F.5 Third-party service provider arrangements.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.5.md)
- [Iowa Code § 507F.6 Cybersecurity event investigation.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.6.md)
- [Iowa Code § 507F.7 Cybersecurity event notification and report to the commissioner.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.7.md)
- [Iowa Code § 507F.8 Cybersecurity event notification to consumers.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.8.md)
- [Iowa Code § 507F.9 Cybersecurity event third-party service providers.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.9.md)
- [Iowa Code § 507F.10 Cybersecurity event reinsurers.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.10.md)
- [Iowa Code § 507F.11 Cybersecurity event producers of record.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.11.md)
- [Iowa Code § 507F.12 Confidentiality.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.12.md)
- [Iowa Code § 507F.13 Applicability.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.13.md)
- [Iowa Code § 507F.14 Penalties.](https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.14.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/STATE_IA_TXIII_C507F_S507F.9. Check the current official text before relying on it. Not legal advice.
