Back to California

AB-869 • 2026

State agencies: information security: Zero Trust architecture.

State agencies: information security: Zero Trust architecture.

Technology
Active

The official status still shows this bill as active or still awaiting another formal step.

Sponsor
Irwin
Last action
Official status
Senate - Appropriations
Effective date
Not listed

Plain English Breakdown

The specific list of agency exceptions and implementation dates are defined elsewhere or left unspecified in this summary text.

AB-869: State Agencies Must Use Zero Trust Security

This law requires specified state agencies to implement a cybersecurity system called Zero Trust architecture and report on their progress.

What This Bill Does

  • Requires specified state agencies, with some exceptions, to use Zero Trust architecture for data, hardware, software, internal systems, and essential third-party software by set dates.
  • Mandates that agencies prioritize solutions matching federal guidelines, including multifactor authentication, endpoint detection tools, and strong logging practices.
  • Directs the Office of Information Security chief to create or update uniform technology policies in official state manuals for Zero Trust architecture.
  • Updates annual reporting rules so agencies must share information about their progress on improving internal system defenses.

Who It Names or Affects

  • Specified California state agencies, departments, and offices.
  • The Office of Information Security within the Department of Technology.
  • Essential third-party software used by state agencies.

Terms To Know

Zero Trust architecture
A security model required for all data, hardware, and systems that does not automatically trust anyone inside or outside a network.
Multifactor authentication
A login method requiring users to provide two or more forms of proof to access systems and data.
CISA Maturity Model
A set of standards from the federal Cybersecurity and Infrastructure Security Agency used to measure how advanced an agency's security is.

Limits and Unknowns

  • The bill includes specified exceptions for some agencies, but does not list them in this summary.
  • Specific dates for when agencies must finish implementation are mentioned as 'specified' but not listed here.
  • The exact details of how federal fund requirements will be met depend on future actions.

Bill History

  1. California Legislative Information

    Senate - Appropriations

Official Summary Text

State agencies: information security: Zero Trust architecture.