Don’t do SECURITY. Do business SECURELY.

California’s connected device security law takes effect

California now requires connected devices to have reasonable security features, such as unique passwords, effectively ending default passwords.

California’s connected device security law (SB-327, Civil Code 1798.91.04) comes into force today, the first US law setting security requirements for Internet of Things devices.

Key points

  • Manufacturers of connected devices sold in California must equip them with reasonable security features.
  • Devices with a preprogrammed password must use a unique password for each device.
  • Otherwise, users must be required to set a new password before first use.
  • Enforcement is by the Attorney General and local prosecutors.

UK device manufacturers selling into California should review their products against these requirements, which closely mirror the UK’s own consumer IoT security plans.

Source: California SB 327 connected devices law (California Legislative Information)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights