Law / United States / California
Security of Connected Devices
Cal. Civ. Code sections 1798.91.04-1798.91.06 (Title 1.81.26, added by Stats. 2018, Ch. 860 (AB 1906) and Ch. 886 (SB 327); sections 1798.91.04 and 1798.91.05 amended by Stats. 2022, Ch. 785 (AB 2392))
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 January 2023.
A product security requirements rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds a manufacturer of a physical connected device, a device or other physical object capable of connecting to the internet, directly or indirectly, and assigned an internet protocol or Bluetooth address, that is sold or offered for sale in California; it does not by itself reach a developer who publishes only an app or other software with no connected device of its own, and it does not reach unaffiliated third-party software or apps a user chooses to add to someone else's device.
- Equip the device with a security feature or features appropriate to its nature, function, and the information it may collect, contain, or transmit, designed to protect the device and that information from unauthorized access, destruction, use, modification, or disclosure.
- Where the device authenticates outside a local area network, give each unit a unique preprogrammed password or require the user to generate a new means of authentication before first use; meeting a NIST-conforming Internet of Things cybersecurity labeling scheme's baseline criteria and conformity assessment is an alternative way to satisfy the duty.
- The duty does not apply to a connected device already subject to security requirements under federal law, regulation, or federal agency guidance, or to an activity already regulated by HIPAA or California's Confidentiality of Medical Information Act.
- There is no private right of action for a violation; only the Attorney General, a city attorney, a county counsel, or a district attorney may enforce this title.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Who enforces it
Enforcement body
The Attorney General, a city attorney, a county counsel, or a district attorney, given exclusive authority to enforce this title; the statute names no other regulator and no penalty amount of its own.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A manufacturer of a connected device, any device or other physical object capable of connecting to the internet, directly or indirectly, and assigned an internet protocol or Bluetooth address, that is sold or offered for sale in California, must equip the device with a reasonable security feature or features appropriate to the device's nature and function and to the information it may collect, contain, or transmit, designed to protect the device and any information in it from unauthorized access, destruction, use, modification, or disclosure.
Where a connected device authenticates outside a local area network, the statute deems that duty met if the device's preprogrammed password is unique to each unit manufactured, or the device requires the user to generate a new means of authentication before first use; a manufacturer may instead satisfy the duty by meeting or exceeding the baseline criteria of a NIST-conforming Internet of Things cybersecurity labeling scheme and completing that scheme's conformity assessment.
The duty does not reach unaffiliated third-party software or applications a user chooses to add to someone else's connected device. It also imposes no duty on an app store, gateway, or marketplace to review or enforce compliance, nor on the manufacturer to prevent a user from modifying the device's own software or firmware. The title does not apply to a connected device already subject to security requirements under federal law, regulation, or federal agency guidance.
It also does not apply to a covered entity, health care provider, health plan, business associate, contractor, or employer as to an activity already regulated by HIPAA or California's Confidentiality of Medical Information Act. The statute creates no private right of action; the Attorney General, a city attorney, a county counsel, or a district attorney have the exclusive authority to enforce it, and the statute names no penalty amount of its own.
When LexLint raises it
distributes_software_product
Read the law
Official statute text, California Legislative Information, Civil Code Title 1.81.26