Reference book and organized evidence files for state-law research
Reference book and organized evidence files for state-law research

Unsolicited security scanning laws by state should be researched against defined behaviors, not reduced to a legal-or-illegal map. This 50-state index identifies research starting points and separates reviewed statutory text from work that remains unverified.

Evidence before outreach · Part 4. Research date: October 6, 2026. Preliminary statutory research, not legal advice or a completed 50-state legal clearance. Relevant decisions, effective-date changes, federal law and civil claims require separate review.

TL;DR
  • All 50 states have computer-crime laws, but the elements and defenses differ.
  • This index is a research map, not a permissionless-scanning risk rating.
  • Eight state installments cite official text; decisions and method-specific legal clearance remain pending.
  • Pennsylvania's express and implied-consent defense belongs beside its access prohibition.
  • SCOUTz prospect intelligence requires separate analysis of public collection, authorized tenant access and outreach.

Why is a state-by-method map better than a legality rating?

A prospect's headquarters is an incomplete legal filter. Requests can originate in one place and reach systems or services in another. The business that owns a domain may also use infrastructure operated by a separate provider.

A state-specific review should identify those connections before applying a statute. Do not assume that choosing a different cloud location removes the relevance of the prospect's state or the location of the accessed systems.

How should MSPs research unsolicited security scanning laws by state?

Use a state-by-method matrix. Reading a third-party index, querying published DNS, contacting an HTTP or TLS service, enumerating ports and using authorized Microsoft 365 permissions are different actions. Record each one separately.

The NCSL survey, consulted October 6, 2026, supplies the comparative starting points below. Its own disclaimer says the material is general comparative information, not legal advice. Some links point to historical code versions and some citations contain apparent typographical errors.

The pending entries have not been independently checked against current official text, amendments and decisions for this series. Do not treat their appearance in a table as evidence that the legal work is complete.

Which statutory starting points need checking in each state?

Review labels mean:

  • Official text reviewed: the indicated statutory starting point was read from an official legislative source for this series. This does not mean case-law review or legal clearance is complete.
  • Secondary text reviewed: reproduced statutory text was reviewed, but current official confirmation remains outstanding.
  • Pending: starting point drawn from the source map; independent current-text verification remains outstanding.
StatePrincipal starting pointReview status
AlabamaAla. Code § 13A-8-112Pending
AlaskaAlaska Stat. § 11.46.740Pending
ArizonaA.R.S. §§ 13-2301(E), 13-2316Official text reviewed
ArkansasArk. Code ch. 5-41Pending
CaliforniaPenal Code § 502Official text reviewed
ColoradoC.R.S. §§ 18-5.5-101–102Pending
Connecticut§§ 53a-250–261; § 53-451Pending
Delaware11 Del. C. §§ 931–941Pending
FloridaFla. Stat. ch. 815Official text reviewed
GeorgiaO.C.G.A. §§ 16-9-90–94Pending
HawaiiHRS §§ 708-890–895.7Pending
IdahoIdaho Code ch. 18-22Pending
Illinois720 ILCS 5/17-50–55Pending
Indiana§§ 35-43-1-8, 35-43-2-3Pending
Iowa§ 716.6B and related definitionsPending
KansasK.S.A. § 21-5839Pending
KentuckyKRS §§ 434.840–860Pending; confirm corrected survey citation
LouisianaLa. R.S. §§ 14:73.1–73.8Pending
Maine17-A M.R.S. §§ 431–437Pending
MarylandCriminal Law § 7-302Pending
MassachusettsM.G.L. ch. 266, § 120FOfficial text reviewed
MichiganMCL §§ 752.792, 752.795Official text reviewed
Minnesota§§ 609.87–609.8913Pending
MississippiMiss. Code §§ 97-45-1 et seq.Pending
Missouri§§ 569.095, .097, .099; § 537.525Pending
MontanaMCA §§ 45-6-310–311Pending
Nebraska§§ 28-1341–1348Pending
NevadaNRS §§ 205.473–513Pending
New HampshireRSA ch. 638 computer-crime provisionsPending; confirm survey references
New Jersey§§ 2C:20-23–34; 2A:38A-1–3Pending
New Mexico§§ 30-45-1–7Pending
New YorkPenal Law §§ 156.00–156.50Pending
North Carolina§§ 14-453–458Pending
North Dakota§ 12.1-06.1-08Pending
Ohio§ 2913.04 and related provisionsPending
Oklahoma21 O.S. §§ 1951–1959Pending
OregonORS § 164.377Pending
Pennsylvania18 Pa.C.S. ch. 76Official text reviewed
Rhode IslandR.I. Gen. Laws ch. 11-52Pending
South Carolina§§ 16-16-10–40Pending
South DakotaSDCL ch. 43-43BPending
TennesseeTenn. Code ch. 39-14 computer-crime provisionsPending; confirm corrected survey citation
TexasPenal Code §§ 33.01–33.02Official text reviewed; decisions and amendment reconciliation pending
UtahComputer-crime provisions identified in the source surveyPending; current numbering not confirmed
Vermont13 V.S.A. §§ 4101 et seq.Pending
Virginia§§ 18.2-152.1–152.15Pending
WashingtonRCW §§ 9A.90.030, 9A.90.050Official text reviewed
West VirginiaW. Va. Code ch. 61-3CPending
WisconsinWis. Stat. § 943.70Pending
Wyoming§§ 6-3-501 et seq.Pending

No entry means scanning permitted or scanning prohibited. Every state needs a behavior-specific application of the relevant law.

Sources behind the initial state installments

The following sources were consulted October 6, 2026. Official text reviewed does not establish that later amendments, decisions or every relevant provision have been fully checked.

Evidence: distinctions the initial state articles examine

The initial installments focus on eight states already highlighted in the source material. They are selected for their different statutory questions, not because the remaining states are safe or unimportant.

StateQuestion highlighted in the installmentImportant limit
ArizonaHow do § 13-2301(E)(1) and § 13-2316(A) interact?Lack of damage does not settle the access question
CaliforniaWhat do § 502(b)(1), (c)(2), (3), (7), (e) require?Investigation expense does not establish a violation by itself
FloridaDid the actor know access or use was unauthorized under § 815.06(2)(a), (7)(c)?The security-operations exception specifies authorized operations
TexasWas the owner's effective consent given for this purpose under § 33.01(12)?Official text is available; its application remains unresolved
PennsylvaniaHow does § 7605(1)–(2) apply?Read the defense alongside § 7611, not after the analysis
MichiganWas access used to acquire property or use services under § 752.795(a)?The statute is not limited to destructive conduct
MassachusettsDid the person know access was unauthorized or fail to terminate it under § 120F, first paragraph?Lack of a password is not an automatic permission grant
WashingtonWere access barriers circumvented under § 9A.90.030(11)–(12)?The research exception is not an automatic commercial-prospecting exemption

These are questions for review. The installments do not predict prosecution, litigation outcomes or how a court would classify a particular SCOUTz collector.

Insight: definitions and defenses change the answer

A statutory heading such as computer tampering can suggest that damage is always necessary. The actual subsections can be broader. Read the definition of access, the authorization language and the particular offense elements together.

Defenses also matter. Pennsylvania § 7605(1)–(2) expressly addresses entitlement by law or contract and reasonable belief in authorization; it includes express or implied consent. A summary that quotes only § 7611(a)(2) gives readers an incomplete view of the chapter.

Washington uses a different framework in § 9A.90.030(11)–(12): its definition of without authorization addresses knowing circumvention of technological access barriers and contains a white-hat research exclusion. That wording is not a nationwide rule and does not erase separate claims or laws.

Civil exposure is a separate research column

A criminal provision and a civil remedy do not necessarily have identical requirements. California § 502(e)(1)–(2) addresses owners or lessees suffering damage or loss by reason of a violation. Florida § 815.06(5)(a)–(b) identifies an action against a person convicted under the section.

Do not copy a civil-liability statement from one state into another. Confirm who can sue, what predicate conduct or loss is required and which remedies are available. A claim about investigation costs must be tied to the actual statutory language and qualifying facts.

Jurisdiction is not just headquarters

California § 502(j) and Florida § 815.06(8) address access between jurisdictions. Pennsylvania § 7602 considers where conduct or an element's result occurs and states that out-of-state acts are not themselves a defense.

The technical inventory should therefore identify where relevant requests originate and which systems receive them, as far as those facts are known. Unknown infrastructure locations should remain unknown until reviewed, not be assigned to the prospect's mailing address.

Proof: build a review file for each state and method

For each state, use the same research fields:

  1. Access: the statutory definition and how it could apply to the request.
  2. Authorization: express consent, implied consent, effective consent or barrier language.
  3. Mental state: knowledge, intention, recklessness, deception or other required elements.
  4. Conduct: access alone, acquisition, service use, changes, damage or interference.
  5. Defenses and exceptions: the exact conditions, not a generic security-research label.
  6. Civil remedies: claimant, predicate violation, required loss and available relief.
  7. Jurisdiction: locations and connections relevant to the conduct.
  8. Decisions: relevant holdings and their actual limits.
  9. Outreach: commercial-email, advertising, privacy and disclosure questions.

Each file should preserve the official source, the text consulted, the research date and the unresolved items. This is a suggested review method, not a legal safe harbor.

Where SCOUTz fits in the research map

SCOUTz's prospect-intelligence workflow, as described by the team, begins with public records and passive enumeration. Indexed observations are publicly discoverable, with no request sent to verify them. The authorized Microsoft 365 review is a separate stage using OAuth after prospect authorization and full sign-up.

The described design excludes exploit checks, brute-forcing, authentication testing and content reads. Reports are diagnosis only, without threatened disclosure or a built-in remediation upsell. Those facts narrow what counsel needs to review; they do not supply automatic clearance across all 50 states.

If a collector changes, revisit the affected analysis. Moving from an index observation to live verification changes the behavior even if the report still uses the same heading.

FAQ

Does this guide clear SCOUTz in all 50 states?

No. It is a preliminary research index with explicit source-review limits, not legal clearance.

Are states marked pending safe for scanning?

No conclusion has been assigned. Pending means independent current-text and application work remains outstanding.

Does official text reviewed mean the legal review is complete?

No. It means the indicated statutory text was consulted; decisions, amendments, other claims and method-specific application still need review.

Has official Texas text been checked?

Yes. The official §§ 33.01–33.02 text was retrieved October 6, 2026. Decisions, amendment reconciliation and method-specific clearance remain pending.

Why not assign red, yellow and green risk ratings?

A state-level color would conceal the differences among collection methods and unresolved legal elements. Analyze state and behavior together.

Can an MSP choose law based only on prospect headquarters?

No. Originating conduct, accessed systems and jurisdictional provisions can create other relevant connections.

Does a public-source report remove email obligations?

No. Commercial outreach requires a separate analysis of message purpose, disclosures, opt-outs and truthful claims.

One last thing

The most useful legal map contains blanks. Marking a state or case question unverified is more defensible than converting a source index into a permission slip.

Where should an MSP begin the state comparison?

Start with the distinct questions in Arizona's authority provisions, Florida's knowledge and authorized-security provisions, Texas's effective-consent provisions, Pennsylvania's authorization defense and Washington's barrier and research definitions. Those installments connect to California, Michigan and Massachusetts where the statutory contrast is useful. A linked installment is research, not clearance.

Which federal laws remain a separate layer?

18 U.S.C. § 1030(a)(2)(C), (a)(5), (e)(2), (e)(6), (g) supplies federal access, information-acquisition, damage, definitions and conditional civil-remedy provisions. State permission analysis does not substitute for those elements.

Commercial purpose is defined in 15 U.S.C. § 7702(2); § 7704(a)(1)–(5) contains commercial-email duties. Sending a report and obtaining access remain separate inquiries. Federal citations use GovInfo's official 2024 edition, effective January 6, 2025, not independently verified current 2026 code.

DOJ Justice Manual § 9-48.000 B.3(8), C is charging policy, not immunity. The FTC CAN-SPAM business guide is agency guidance explaining outreach duties, not authorization for collection.

Sources

Statutes: official state sources appear above, with subsection-specific citations beside substantive claims. The 42 remaining state entries are survey-derived starting points, not verified official-code analyses. Federal §§ 1030, 7702, 7704 use the official 2024 edition, effective January 6, 2025; later comparison remains pending.

Court decisions: no holding is asserted. Relevant state and federal case-law review remains pending across the series.

Agency guidance: DOJ Justice Manual § 9-48.000 and FTC CAN-SPAM business guidance, linked above. Neither creates universal permission or immunity.

Comparative and product sources: NCSL is a research index, not law. The team's SCOUTz workflow description supports the indexed-versus-verified and consent distinctions, not legal certification. Sources consulted October 6, 2026. Currentness reconciliation, civil claims and exact-method clearance remain incomplete.