veeto
Home
Bills
Influence
Feedback
hamburger
    Privacy Policy
    © 2025 Veeto. All rights reserved.
    AB-869
    Government Operations

    State agencies: information security: Zero Trust architecture.

    Introduced
    CA
    ∙
    2025-2026 Regular Session
    0
    0
    Track
    Track

    Key Takeaways

    • Requires all California state agencies to implement Zero Trust cybersecurity architecture by 2030.
    • Mandates multifactor authentication and continuous monitoring for all state systems and data access.
    • Establishes a two-phase implementation with Advanced maturity required by 2026 and Optimal by 2030.
    • Requires agencies to submit annual security assessment reports tracking Zero Trust implementation progress.

    Summary

    Assembly Member Irwin's Zero Trust architecture mandate would require California state agencies to implement comprehensive cybersecurity protocols across all data systems and third-party software by 2030. The legislation establishes a two-phase implementation timeline, with agencies required to achieve "Advanced" maturity level by June 2026 and "Optimal" maturity level by June 2030, as defined by the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model.

    The bill outlines three core security requirements for state agencies: multifactor authentication for all system access, enterprise-level endpoint detection and response capabilities, and enhanced logging practices for security monitoring. Agencies must prioritize solutions that align with federal guidelines, including the Federal Risk and Authorization Management Program and National Institute of Standards and Technology frameworks. The Office of Information Security would develop uniform policies and standards for implementation while collecting annual progress reports from agencies on their Zero Trust adoption.

    The legislation's scope extends to all state agencies, though the University of California system may opt in through a Regents resolution. The bill's findings cite recent cyber breaches as the impetus for adopting Zero Trust principles, which require continuous verification of all users accessing state systems, regardless of their location. Implementation timelines align with federal funding requirements, including conditions attached to Infrastructure Investment and Jobs Act allocations.

    Key Dates

    Next Step
    Referred to the Assembly Standing Committee on Appropriations
    Next Step
    Assembly Committee
    Referred to the Assembly Standing Committee on Appropriations
    Hearing has not been scheduled yet
    Assembly Privacy And Consumer Protection Hearing
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    Assembly Privacy And Consumer Protection Hearing
    Read first time. To print.
    Assembly Floor
    Read first time. To print.
    Read first time. To print.

    Contacts

    Profile
    Jacqui IrwinD
    Assemblymember
    Bill Author
    Not Contacted
    Not Contacted
    Profile
    Joaquin ArambulaD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Buffy WicksD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Lisa CalderonD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Mike FongD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    0 of 16 row(s) selected.
    Page 1 of 4
    Select All Legislators
    Profile
    Jacqui IrwinD
    Assemblymember
    Bill Author
    Profile
    Joaquin ArambulaD
    Assemblymember
    Committee Member
    Profile
    Buffy WicksD
    Assemblymember
    Committee Member
    Profile
    Lisa CalderonD
    Assemblymember
    Committee Member
    Profile
    Mike FongD
    Assemblymember
    Committee Member
    Profile
    Diane DixonR
    Assemblymember
    Committee Member
    Profile
    Gregg HartD
    Assemblymember
    Committee Member
    Profile
    Blanca PachecoD
    Assemblymember
    Committee Member
    Profile
    Gail PellerinD
    Assemblymember
    Committee Member
    Profile
    Kate SanchezR
    Assemblymember
    Committee Member
    Profile
    Tri TaR
    Assemblymember
    Committee Member
    Profile
    Jessica CalozaD
    Assemblymember
    Committee Member
    Profile
    Mark GonzalezD
    Assemblymember
    Committee Member
    Profile
    Heather HadwickR
    Assemblymember
    Committee Member
    Profile
    Jose SolacheD
    Assemblymember
    Committee Member
    Profile
    Sade ElhawaryD
    Assemblymember
    Committee Member

    Similar Past Legislation

    Bill NumberTitleIntroduced DateStatusLink to Bill
    AB-749
    State agencies: information security: uniform standards.
    February 2023
    Failed
    View Bill
    Showing 1 of 1 items
    Page 1 of 1

    Get Involved

    Act Now!

    Email the authors or create an email template to send to all relevant legislators.

    Introduced By

    Jacqui Irwin
    Jacqui IrwinD
    California State Assembly Member
    10% progression
    Bill has been formally introduced and read for the first time in its house of origin (2/19/2025)

    Latest Voting History

    View History
    April 1, 2025
    PASS
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    AyesNoesNVRTotalResult
    150015PASS

    Key Takeaways

    • Requires all California state agencies to implement Zero Trust cybersecurity architecture by 2030.
    • Mandates multifactor authentication and continuous monitoring for all state systems and data access.
    • Establishes a two-phase implementation with Advanced maturity required by 2026 and Optimal by 2030.
    • Requires agencies to submit annual security assessment reports tracking Zero Trust implementation progress.

    Get Involved

    Act Now!

    Email the authors or create an email template to send to all relevant legislators.

    Introduced By

    Jacqui Irwin
    Jacqui IrwinD
    California State Assembly Member

    Summary

    Assembly Member Irwin's Zero Trust architecture mandate would require California state agencies to implement comprehensive cybersecurity protocols across all data systems and third-party software by 2030. The legislation establishes a two-phase implementation timeline, with agencies required to achieve "Advanced" maturity level by June 2026 and "Optimal" maturity level by June 2030, as defined by the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model.

    The bill outlines three core security requirements for state agencies: multifactor authentication for all system access, enterprise-level endpoint detection and response capabilities, and enhanced logging practices for security monitoring. Agencies must prioritize solutions that align with federal guidelines, including the Federal Risk and Authorization Management Program and National Institute of Standards and Technology frameworks. The Office of Information Security would develop uniform policies and standards for implementation while collecting annual progress reports from agencies on their Zero Trust adoption.

    The legislation's scope extends to all state agencies, though the University of California system may opt in through a Regents resolution. The bill's findings cite recent cyber breaches as the impetus for adopting Zero Trust principles, which require continuous verification of all users accessing state systems, regardless of their location. Implementation timelines align with federal funding requirements, including conditions attached to Infrastructure Investment and Jobs Act allocations.

    10% progression
    Bill has been formally introduced and read for the first time in its house of origin (2/19/2025)

    Key Dates

    Next Step
    Referred to the Assembly Standing Committee on Appropriations
    Next Step
    Assembly Committee
    Referred to the Assembly Standing Committee on Appropriations
    Hearing has not been scheduled yet
    Assembly Privacy And Consumer Protection Hearing
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    Assembly Privacy And Consumer Protection Hearing
    Read first time. To print.
    Assembly Floor
    Read first time. To print.
    Read first time. To print.

    Latest Voting History

    View History
    April 1, 2025
    PASS
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    AyesNoesNVRTotalResult
    150015PASS

    Contacts

    Profile
    Jacqui IrwinD
    Assemblymember
    Bill Author
    Not Contacted
    Not Contacted
    Profile
    Joaquin ArambulaD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Buffy WicksD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Lisa CalderonD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Mike FongD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    0 of 16 row(s) selected.
    Page 1 of 4
    Select All Legislators
    Profile
    Jacqui IrwinD
    Assemblymember
    Bill Author
    Profile
    Joaquin ArambulaD
    Assemblymember
    Committee Member
    Profile
    Buffy WicksD
    Assemblymember
    Committee Member
    Profile
    Lisa CalderonD
    Assemblymember
    Committee Member
    Profile
    Mike FongD
    Assemblymember
    Committee Member
    Profile
    Diane DixonR
    Assemblymember
    Committee Member
    Profile
    Gregg HartD
    Assemblymember
    Committee Member
    Profile
    Blanca PachecoD
    Assemblymember
    Committee Member
    Profile
    Gail PellerinD
    Assemblymember
    Committee Member
    Profile
    Kate SanchezR
    Assemblymember
    Committee Member
    Profile
    Tri TaR
    Assemblymember
    Committee Member
    Profile
    Jessica CalozaD
    Assemblymember
    Committee Member
    Profile
    Mark GonzalezD
    Assemblymember
    Committee Member
    Profile
    Heather HadwickR
    Assemblymember
    Committee Member
    Profile
    Jose SolacheD
    Assemblymember
    Committee Member
    Profile
    Sade ElhawaryD
    Assemblymember
    Committee Member

    Similar Past Legislation

    Bill NumberTitleIntroduced DateStatusLink to Bill
    AB-749
    State agencies: information security: uniform standards.
    February 2023
    Failed
    View Bill
    Showing 1 of 1 items
    Page 1 of 1