Legis
Finance
SB 505, Chapter 648, Statutes of 2026 · Sunday 27 September 2026

Money Transmission Act: authentication

California will require licensed money transmitters to use stronger login authentication starting January 1, 2028.

The law adds account-access safeguards for services that send, receive, or manage money transfers. It also requires an accessible way for users to report login errors or suspected fraud.

What the law does ​

  • Requires two-factor authentication, multifactor authentication, or an equally secure or more secure access control before a user can log in.
  • Requires licensees to reverify the user, device, or system through secure authentication processes.
  • Requires the access-control method to receive written approval from the person overseeing the licensee’s information security program.
  • Requires risk-based reverification that considers transaction risk, unusual behavior, and transaction sensitivity without weakening security.
  • Requires a way to report errors or suspected fraud through the service platform or a reasonably accessible alternative.
  • Makes the requirements operative on January 1, 2028.

Who it affects ​

  • Businesses licensed under California’s Money Transmission Act.
  • Users accessing money-transmission accounts or platforms.

Context ​

The requirements apply to licensees regulated by the Money Transmission Act.