Does CCPA Require MFA? No — But the Private Right of Action Changes the Math

Table of contents
No. CCPA, as amended by CPRA, does not require multi-factor authentication by name.
What it does have is a private right of action for certain personal-information security breaches. California Civil Code §1798.150 lets consumers sue when covered personal information is breached as a result of a business's failure to implement and maintain reasonable security procedures and practices. Statutory damages can be USD 100 to USD 750 per consumer per incident, or actual damages if greater.
That changes the authentication risk calculation for customer-facing systems.
What CCPA Actually Says
CCPA does not publish an MFA checklist. The key security phrase is "reasonable security procedures and practices appropriate to the nature of the information."
That means the question after a breach is not whether a specific MFA clause existed. The question is whether the business's authentication and access controls were reasonable for the personal information at stake.
Why Reasonable Security Points Toward MFA
California's Attorney General previously recommended adopting the CIS Critical Security Controls as a baseline for reasonable security and specifically recommended making multi-factor authentication available on consumer-facing online accounts that contain sensitive personal information.
The California Privacy Protection Agency has also finalized regulations that include cybersecurity audits and risk assessments for certain businesses, with phased audit certification deadlines beginning in 2028. That does not make MFA a universal CCPA mandate, but it increases the pressure to document why high-risk consumer systems are protected appropriately.
The Customer Portal Risk
The highest-risk scenario is easy to picture:
- A customer portal contains personal information.
- The portal uses only username and password.
- Attackers reuse stolen credentials or phish users.
- A large number of California consumers are affected.
- Plaintiffs argue password-only access was not reasonable security.
With statutory damages multiplied across many consumers, authentication gaps can become expensive even before regulatory enforcement.
Systems to Prioritize
Prioritize MFA for systems that hold or expose consumer data:
- Customer portals.
- Account-management apps.
- Healthcare and financial portals.
- Support and admin consoles.
- CRM and profile-management systems.
- Legacy web applications with local login.
How Datawiza Helps
Datawiza Access Proxy adds MFA in front of existing web applications without changing application code. Customers can keep existing portal credentials while Datawiza enforces the MFA challenge before the application is reached.
That is especially useful when a customer portal was not built for CIAM, SAML, OIDC, or native MFA. Datawiza built-in MFA can protect users without requiring every customer to be migrated into a new IdP.
Sources Reviewed
- California Civil Code §1798.150
- California Attorney General 2016 data breach report announcement
- CPPA cybersecurity audit and risk-assessment regulations update
FAQ
Does CCPA require MFA?
No. CCPA does not mandate MFA by name. It requires reasonable security, and authentication strength becomes part of that analysis after a covered breach.
What are CCPA breach damages?
California Civil Code §1798.150 allows statutory damages of USD 100 to USD 750 per consumer per incident, or actual damages if greater, for qualifying breaches caused by failure to maintain reasonable security.
Does MFA count as reasonable security?
MFA is a strong evidence point for reasonable authentication controls, especially for consumer-facing accounts with sensitive personal information. It is not the only required security measure.
How do we add MFA to a customer portal without migrating users?
Use an access-layer proxy. Datawiza Access Proxy can enforce MFA before access while users keep their existing portal credentials.



