
Unsolicited security scanning laws by state should be researched against defined behaviors, not reduced to a legal-or-illegal map. This 50-state index identifies research starting points and separates reviewed statutory text from work that remains unverified.
Evidence before outreach · Part 4. Research date: October 6, 2026. Preliminary statutory research, not legal advice or a completed 50-state legal clearance. Relevant decisions, effective-date changes, federal law and civil claims require separate review.
- All 50 states have computer-crime laws, but the elements and defenses differ.
- This index is a research map, not a permissionless-scanning risk rating.
- Eight state installments cite official text; decisions and method-specific legal clearance remain pending.
- Pennsylvania's express and implied-consent defense belongs beside its access prohibition.
- SCOUTz prospect intelligence requires separate analysis of public collection, authorized tenant access and outreach.
Why is a state-by-method map better than a legality rating?
A prospect's headquarters is an incomplete legal filter. Requests can originate in one place and reach systems or services in another. The business that owns a domain may also use infrastructure operated by a separate provider.
A state-specific review should identify those connections before applying a statute. Do not assume that choosing a different cloud location removes the relevance of the prospect's state or the location of the accessed systems.
How should MSPs research unsolicited security scanning laws by state?
Use a state-by-method matrix. Reading a third-party index, querying published DNS, contacting an HTTP or TLS service, enumerating ports and using authorized Microsoft 365 permissions are different actions. Record each one separately.
The NCSL survey, consulted October 6, 2026, supplies the comparative starting points below. Its own disclaimer says the material is general comparative information, not legal advice. Some links point to historical code versions and some citations contain apparent typographical errors.
The pending entries have not been independently checked against current official text, amendments and decisions for this series. Do not treat their appearance in a table as evidence that the legal work is complete.
Which statutory starting points need checking in each state?
Review labels mean:
- Official text reviewed: the indicated statutory starting point was read from an official legislative source for this series. This does not mean case-law review or legal clearance is complete.
- Secondary text reviewed: reproduced statutory text was reviewed, but current official confirmation remains outstanding.
- Pending: starting point drawn from the source map; independent current-text verification remains outstanding.
| State | Principal starting point | Review status |
|---|---|---|
| Alabama | Ala. Code § 13A-8-112 | Pending |
| Alaska | Alaska Stat. § 11.46.740 | Pending |
| Arizona | A.R.S. §§ 13-2301(E), 13-2316 | Official text reviewed |
| Arkansas | Ark. Code ch. 5-41 | Pending |
| California | Penal Code § 502 | Official text reviewed |
| Colorado | C.R.S. §§ 18-5.5-101–102 | Pending |
| Connecticut | §§ 53a-250–261; § 53-451 | Pending |
| Delaware | 11 Del. C. §§ 931–941 | Pending |
| Florida | Fla. Stat. ch. 815 | Official text reviewed |
| Georgia | O.C.G.A. §§ 16-9-90–94 | Pending |
| Hawaii | HRS §§ 708-890–895.7 | Pending |
| Idaho | Idaho Code ch. 18-22 | Pending |
| Illinois | 720 ILCS 5/17-50–55 | Pending |
| Indiana | §§ 35-43-1-8, 35-43-2-3 | Pending |
| Iowa | § 716.6B and related definitions | Pending |
| Kansas | K.S.A. § 21-5839 | Pending |
| Kentucky | KRS §§ 434.840–860 | Pending; confirm corrected survey citation |
| Louisiana | La. R.S. §§ 14:73.1–73.8 | Pending |
| Maine | 17-A M.R.S. §§ 431–437 | Pending |
| Maryland | Criminal Law § 7-302 | Pending |
| Massachusetts | M.G.L. ch. 266, § 120F | Official text reviewed |
| Michigan | MCL §§ 752.792, 752.795 | Official text reviewed |
| Minnesota | §§ 609.87–609.8913 | Pending |
| Mississippi | Miss. Code §§ 97-45-1 et seq. | Pending |
| Missouri | §§ 569.095, .097, .099; § 537.525 | Pending |
| Montana | MCA §§ 45-6-310–311 | Pending |
| Nebraska | §§ 28-1341–1348 | Pending |
| Nevada | NRS §§ 205.473–513 | Pending |
| New Hampshire | RSA ch. 638 computer-crime provisions | Pending; confirm survey references |
| New Jersey | §§ 2C:20-23–34; 2A:38A-1–3 | Pending |
| New Mexico | §§ 30-45-1–7 | Pending |
| New York | Penal Law §§ 156.00–156.50 | Pending |
| North Carolina | §§ 14-453–458 | Pending |
| North Dakota | § 12.1-06.1-08 | Pending |
| Ohio | § 2913.04 and related provisions | Pending |
| Oklahoma | 21 O.S. §§ 1951–1959 | Pending |
| Oregon | ORS § 164.377 | Pending |
| Pennsylvania | 18 Pa.C.S. ch. 76 | Official text reviewed |
| Rhode Island | R.I. Gen. Laws ch. 11-52 | Pending |
| South Carolina | §§ 16-16-10–40 | Pending |
| South Dakota | SDCL ch. 43-43B | Pending |
| Tennessee | Tenn. Code ch. 39-14 computer-crime provisions | Pending; confirm corrected survey citation |
| Texas | Penal Code §§ 33.01–33.02 | Official text reviewed; decisions and amendment reconciliation pending |
| Utah | Computer-crime provisions identified in the source survey | Pending; current numbering not confirmed |
| Vermont | 13 V.S.A. §§ 4101 et seq. | Pending |
| Virginia | §§ 18.2-152.1–152.15 | Pending |
| Washington | RCW §§ 9A.90.030, 9A.90.050 | Official text reviewed |
| West Virginia | W. Va. Code ch. 61-3C | Pending |
| Wisconsin | Wis. Stat. § 943.70 | Pending |
| Wyoming | §§ 6-3-501 et seq. | Pending |
No entry means scanning permitted or scanning prohibited. Every state needs a behavior-specific application of the relevant law.
Sources behind the initial state installments
The following sources were consulted October 6, 2026. Official text reviewed does not establish that later amendments, decisions or every relevant provision have been fully checked.
- Arizona: § 13-2316 and § 13-2301(E).
- California: Penal Code § 502.
- Florida: chapter 815.
- Texas: official §§ 33.01(1), (12), 33.02(a), (b-1), (f), retrieved October 6, 2026; decisions, amendment reconciliation and method-specific clearance remain pending.
- Pennsylvania: chapter 76, including its authorization defense.
- Michigan: § 752.792 and § 752.795.
- Massachusetts: chapter 266, § 120F.
- Washington: § 9A.90.030 and § 9A.90.050. The consulted PDFs carry a July 12, 2024 certification date; later changes require confirmation.
Evidence: distinctions the initial state articles examine
The initial installments focus on eight states already highlighted in the source material. They are selected for their different statutory questions, not because the remaining states are safe or unimportant.
| State | Question highlighted in the installment | Important limit |
|---|---|---|
| Arizona | How do § 13-2301(E)(1) and § 13-2316(A) interact? | Lack of damage does not settle the access question |
| California | What do § 502(b)(1), (c)(2), (3), (7), (e) require? | Investigation expense does not establish a violation by itself |
| Florida | Did the actor know access or use was unauthorized under § 815.06(2)(a), (7)(c)? | The security-operations exception specifies authorized operations |
| Texas | Was the owner's effective consent given for this purpose under § 33.01(12)? | Official text is available; its application remains unresolved |
| Pennsylvania | How does § 7605(1)–(2) apply? | Read the defense alongside § 7611, not after the analysis |
| Michigan | Was access used to acquire property or use services under § 752.795(a)? | The statute is not limited to destructive conduct |
| Massachusetts | Did the person know access was unauthorized or fail to terminate it under § 120F, first paragraph? | Lack of a password is not an automatic permission grant |
| Washington | Were access barriers circumvented under § 9A.90.030(11)–(12)? | The research exception is not an automatic commercial-prospecting exemption |
These are questions for review. The installments do not predict prosecution, litigation outcomes or how a court would classify a particular SCOUTz collector.
Insight: definitions and defenses change the answer
A statutory heading such as computer tampering can suggest that damage is always necessary. The actual subsections can be broader. Read the definition of access, the authorization language and the particular offense elements together.
Defenses also matter. Pennsylvania § 7605(1)–(2) expressly addresses entitlement by law or contract and reasonable belief in authorization; it includes express or implied consent. A summary that quotes only § 7611(a)(2) gives readers an incomplete view of the chapter.
Washington uses a different framework in § 9A.90.030(11)–(12): its definition of without authorization addresses knowing circumvention of technological access barriers and contains a white-hat research exclusion. That wording is not a nationwide rule and does not erase separate claims or laws.
Civil exposure is a separate research column
A criminal provision and a civil remedy do not necessarily have identical requirements. California § 502(e)(1)–(2) addresses owners or lessees suffering damage or loss by reason of a violation. Florida § 815.06(5)(a)–(b) identifies an action against a person convicted under the section.
Do not copy a civil-liability statement from one state into another. Confirm who can sue, what predicate conduct or loss is required and which remedies are available. A claim about investigation costs must be tied to the actual statutory language and qualifying facts.
Jurisdiction is not just headquarters
California § 502(j) and Florida § 815.06(8) address access between jurisdictions. Pennsylvania § 7602 considers where conduct or an element's result occurs and states that out-of-state acts are not themselves a defense.
The technical inventory should therefore identify where relevant requests originate and which systems receive them, as far as those facts are known. Unknown infrastructure locations should remain unknown until reviewed, not be assigned to the prospect's mailing address.
Proof: build a review file for each state and method
For each state, use the same research fields:
- Access: the statutory definition and how it could apply to the request.
- Authorization: express consent, implied consent, effective consent or barrier language.
- Mental state: knowledge, intention, recklessness, deception or other required elements.
- Conduct: access alone, acquisition, service use, changes, damage or interference.
- Defenses and exceptions: the exact conditions, not a generic security-research label.
- Civil remedies: claimant, predicate violation, required loss and available relief.
- Jurisdiction: locations and connections relevant to the conduct.
- Decisions: relevant holdings and their actual limits.
- Outreach: commercial-email, advertising, privacy and disclosure questions.
Each file should preserve the official source, the text consulted, the research date and the unresolved items. This is a suggested review method, not a legal safe harbor.
Where SCOUTz fits in the research map
SCOUTz's prospect-intelligence workflow, as described by the team, begins with public records and passive enumeration. Indexed observations are publicly discoverable, with no request sent to verify them. The authorized Microsoft 365 review is a separate stage using OAuth after prospect authorization and full sign-up.
The described design excludes exploit checks, brute-forcing, authentication testing and content reads. Reports are diagnosis only, without threatened disclosure or a built-in remediation upsell. Those facts narrow what counsel needs to review; they do not supply automatic clearance across all 50 states.
If a collector changes, revisit the affected analysis. Moving from an index observation to live verification changes the behavior even if the report still uses the same heading.
FAQ
Does this guide clear SCOUTz in all 50 states?
No. It is a preliminary research index with explicit source-review limits, not legal clearance.
Are states marked pending safe for scanning?
No conclusion has been assigned. Pending means independent current-text and application work remains outstanding.
Does official text reviewed mean the legal review is complete?
No. It means the indicated statutory text was consulted; decisions, amendments, other claims and method-specific application still need review.
Has official Texas text been checked?
Yes. The official §§ 33.01–33.02 text was retrieved October 6, 2026. Decisions, amendment reconciliation and method-specific clearance remain pending.
Why not assign red, yellow and green risk ratings?
A state-level color would conceal the differences among collection methods and unresolved legal elements. Analyze state and behavior together.
Can an MSP choose law based only on prospect headquarters?
No. Originating conduct, accessed systems and jurisdictional provisions can create other relevant connections.
Does a public-source report remove email obligations?
No. Commercial outreach requires a separate analysis of message purpose, disclosures, opt-outs and truthful claims.
One last thing
The most useful legal map contains blanks. Marking a state or case question unverified is more defensible than converting a source index into a permission slip.
Where should an MSP begin the state comparison?
Start with the distinct questions in Arizona's authority provisions, Florida's knowledge and authorized-security provisions, Texas's effective-consent provisions, Pennsylvania's authorization defense and Washington's barrier and research definitions. Those installments connect to California, Michigan and Massachusetts where the statutory contrast is useful. A linked installment is research, not clearance.
Which federal laws remain a separate layer?
18 U.S.C. § 1030(a)(2)(C), (a)(5), (e)(2), (e)(6), (g) supplies federal access, information-acquisition, damage, definitions and conditional civil-remedy provisions. State permission analysis does not substitute for those elements.
Commercial purpose is defined in 15 U.S.C. § 7702(2); § 7704(a)(1)–(5) contains commercial-email duties. Sending a report and obtaining access remain separate inquiries. Federal citations use GovInfo's official 2024 edition, effective January 6, 2025, not independently verified current 2026 code.
DOJ Justice Manual § 9-48.000 B.3(8), C is charging policy, not immunity. The FTC CAN-SPAM business guide is agency guidance explaining outreach duties, not authorization for collection.
Sources
Statutes: official state sources appear above, with subsection-specific citations beside substantive claims. The 42 remaining state entries are survey-derived starting points, not verified official-code analyses. Federal §§ 1030, 7702, 7704 use the official 2024 edition, effective January 6, 2025; later comparison remains pending.
Court decisions: no holding is asserted. Relevant state and federal case-law review remains pending across the series.
Agency guidance: DOJ Justice Manual § 9-48.000 and FTC CAN-SPAM business guidance, linked above. Neither creates universal permission or immunity.
Comparative and product sources: NCSL is a research index, not law. The team's SCOUTz workflow description supports the indexed-versus-verified and consent distinctions, not legal certification. Sources consulted October 6, 2026. Currentness reconciliation, civil claims and exact-method clearance remain incomplete.
