Assembly Advances Zero Trust Cybersecurity Bill
Assembly Bill 869, authored by Assemblymember Jacqui Irwin (D-Thousand Oaks), passed the Assembly Floor on Monday (6/2/25) without opposition and now moves to the Senate for further consideration.
The legislation would require state agencies to adopt Zero Trust architecture across all data, hardware, software, internal systems, and essential third-party software, defined as “a set of system design principles, and a coordinated cybersecurity and system management strategy that employs continuous monitoring, risk-based access controls, secure identity and access management practices, and system security automation techniques to address the cybersecurity risk from threats inside and outside traditional network boundaries.”
Under AB 869, agencies must implement multifactor authentication, enterprise endpoint detection and response solutions, and robust logging practices. The bill directs the Office of Information Security within the California Department of Technology (CDT) to update its policies and procedures, as well as reporting requirements, to track agency progress toward compliance.
“The State has a strong tradition of leveraging the expertise and example of our federal partners in the cybersecurity space to ensure Californians can have the same level of confidence in the security of their data and the dependability of services regardless of which level of government is responsible,” says the author statement in an Assembly floor analysis.
The technology industry has voiced strong support for AB 869. Microsoft Corporation, in its support letter, called the bill “a significant step towards ensuring the security and integrity of California’s digital infrastructure,” according to the analysis.
No formal opposition has been filed against the bill, which now awaits committee assignment in the Senate.

