Cure periods were the state legislatures’ training wheels, and they are coming off on schedule. The laws’ drafters traded business support for grace windows, sunset most of them, and the sunsets are now arriving: Colorado’s and Connecticut’s expired in 2025, the January-2025 cohort’s expire through 2026, and California never rebuilt the one the CPRA removed. What remains is a patchwork where the strictest enforcers owe you nothing and the friendliest owe you 30 to 90 days, once.
The current map
| Status | States | Window |
|---|---|---|
| Permanent | Virginia, Utah, Indiana, Kentucky, Texas* | 30 days (*with no-recurrence statement) |
| Permanent, longer | Tennessee (60), Iowa (90) | 60-90 days |
| Expired | California, Colorado, Connecticut | None (discretionary factors only) |
| Sunsetting/sunset | Oregon, Delaware, New Hampshire, New Jersey, Montana, Minnesota | Check current date vs. statute |
What this means operationally
Design for zero. The CPPA’s enforcement actions and Texas’s litigation posture define the real standard: violations found in a sweep proceed on the regulator’s discretion, not your statutory grace. The multi-state baseline should assume immediate enforceability everywhere.
Keep a notice-response runbook. Named owner, 48-hour assessment, evidence-preserving response drafting, and pre-approved fix paths for the common findings (opt-out links, GPC handling, notice mismatches). The response is discovery; legal reviews it as such.
Track the sunsets with dates, not vibes. Each expiration shifts a state from cure-first to discretion-first; the enforcement tracker logs how each AG behaves after its window closes, and amendment cycles (Montana 2025) can move dates mid-life.
Fix before they find. The findings AGs cure-notice most, broken opt-outs, missing rights mechanisms, notices contradicting practice, are externally visible and cheap to self-audit: run a free scan before a regulator runs theirs.