Skip to main content
    RESOURCES/NORTH CAROLINA LAW
    ·By Budget Security

    North Carolina Cybersecurity Laws for Businesses (2026)

    North Carolina has no single cybersecurity statute for private companies. Three laws shape what a business must do. The Identity Theft Protection Act (G.S. 75-60 to 75-66) governs breach notices. G.S. 143-800 bans public entities from paying ransoms. Federal rules then apply by industry. None of them orders a penetration test by name. Here is what each one asks of you.

    This page is general information, not legal advice. Check the current statute or ask counsel before relying on it. Last reviewed: 2 October 2026.

    Who must comply with the Identity Theft Protection Act

    The Act applies to "any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise)".

    Two things in that sentence matter. First, you do not need an office in the state. A Texas SaaS company with North Carolina customers is in scope. Second, paper counts. A filing cabinet in a Greensboro clinic is covered just as a cloud database is.

    The scale is not small. The North Carolina Department of Justice recorded 2,349 data breaches affecting more than nine million North Carolinians in 2025.

    What the notice letter must say: "the general acts of the business"

    G.S. 75-65 does not just tell you to send a notice. It tells you what the notice has to contain. The letter must describe:

    • "The incident in general terms."
    • "The type of personal information that was subject to the unauthorized access and acquisition."
    • "The general acts of the business to protect the personal information from further unauthorized access."
    • "A telephone number that the person may call for further information and assistance, if one exists."
    • "Advice that directs the person to remain vigilant" by reviewing account statements and credit reports.

    Item three is the one most business owners miss until the letter is being drafted. You have to tell every affected resident, in writing, what you did to stop it happening again. "We reset passwords" is thin. "We commissioned an independent penetration test, fixed the findings and had the fixes verified" is the sentence most companies want to be able to write. That is where a post-incident test earns its place.

    Timing is "without unreasonable delay". The statute allows for law-enforcement holds and for "measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system". In other words, you are expected to investigate and contain first, then notify, but not to sit on it.

    Attorney General notice and the 1,000-person trigger

    The statute sets one hard regulator threshold. Under 75-65(f): "In the event a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General's Office and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis".

    The Attorney General's office publishes a breach reporting form and annual breach figures. Ask counsel whether your incident should be reported there even below 1,000 people; the office's reporting practice is broader than the statutory trigger quoted above, and this guide only vouches for the quoted text.

    Enforcement under G.S. 75-1.1

    A violation of the Identity Theft Protection Act is treated as an unfair or deceptive trade practice under G.S. 75-1.1, North Carolina's general consumer protection law. That is what gives the Attorney General the power to bring an action and what opens the door to civil claims from affected residents.

    The practical point: North Carolina does not need a dedicated breach penalty, because the general unfair trade practices machinery already applies. A failure to notify, or a notice that leaves out the required content, is actionable on its own.

    G.S. 143-800: public entities may not pay a ransom

    In 2022 North Carolina became the first state to prohibit public bodies from paying ransoms. The statute reads: "No State agency or local government entity shall submit payment or otherwise communicate with an entity that has engaged in a cybersecurity incident on an information technology system by encrypting data and then subsequently offering to decrypt that data in exchange for a ransom payment."

    It applies to cities, counties, state agencies, public school units, community colleges and the UNC system. Those bodies must also report incidents to the North Carolina Department of Information Technology under G.S. 143B-1379.

    If your company sells to North Carolina local government, read that clause from your customer's side. They cannot buy their way out of a ransomware event, so they cannot afford one. Expect their procurement to ask for your testing evidence, your incident response plan and your notification commitments before they sign.

    NC CSRF: National Guard testing for public bodies, and what everyone else does

    The Cyber Security Response Force (CSRF) is a North Carolina National Guard unit whose mission is to "provide cyber security assistance to State, Local, and Critical Infrastructure providers". Its penetration testing page lists internal and external network testing, web and API testing, wireless and phishing engagements, with "Week 0 coordination through a trusted agent" and deliverables that include an executive summary, a prioritized roadmap, technical findings and post-remediation validation.

    Two things to know. The program serves government and critical infrastructure, not private businesses. And its capacity is limited: in 2023 the CSRF completed 13 penetration tests for state and local municipalities. If you are a county IT director, request an engagement and expect a queue. If you are a private company, the CSRF is not an option, and public bodies that cannot wait for a slot also go to the market.

    Where a penetration test fits

    No North Carolina statute names a penetration test. Three North Carolina-specific reasons make one worth scheduling anyway.

    The notice letter. Item three of 75-65(d) asks what you did to protect the data from further access. A dated, independent test report is the cleanest answer.

    Public-sector sales. Bodies covered by 143-800 cannot pay a ransom, so they screen vendors on prevention. A current report shortens that conversation.

    Audit demand. Charlotte fintechs and Research Triangle SaaS companies are asked for SOC 2 reports by their customers, and SOC 2 auditors expect a pentest as evidence. Our SOC 2 pentesting page covers what auditors look for.

    Budget Security tests North Carolina companies remotely with OSCP-certified testers at $985 per tester-day (€849 per day for EU clients). Scope online, start within 7 days of booking, receive the report within 48 hours after the test ends, and pay after the report is delivered. Charlotte companies start on our Charlotte penetration testing page.

    GLBA Safeguards Rule for Charlotte lenders and fintechs

    Charlotte is the second-largest banking center in the United States, home to Bank of America's headquarters, Truist's headquarters and Wells Fargo's East Coast headquarters. Around them sit lenders, payment firms and fintechs under FTC jurisdiction, and those companies follow the GLBA Safeguards Rule. 16 CFR 314.4(d)(2) requires annual penetration testing plus vulnerability assessments at least every six months, unless you run effective continuous monitoring. Banks follow the equivalent interagency guidelines. Vendors to Charlotte's banks inherit the same expectations through their contracts. Scope and evidence details are on our GLBA penetration testing page.

    HIPAA evaluations for Research Triangle health-tech and biotech

    The Raleigh-Durham region holds roughly 675 life-science companies, plus the Duke and UNC health systems and the health-tech startups that sell into them. Every covered entity and business associate in that chain falls under the HIPAA Security Rule. 45 CFR 164.308(a)(8) requires "a periodic technical and nontechnical evaluation"; the rule never says "penetration test", but a pentest report is the evidence regulators and hospital procurement teams look for. See our HIPAA penetration testing page. Triangle companies can also start on our Raleigh penetration testing page.

    Questions we get

    Does North Carolina require penetration testing?
    No state statute requires it by name. The Identity Theft Protection Act governs breach notices, and G.S. 143-800 bans public bodies from paying ransoms. Testing requirements for North Carolina companies come from federal and industry rules such as GLBA, HIPAA, PCI DSS and CMMC, and from SOC 2 auditors.
    What is the North Carolina Identity Theft Protection Act?
    It is Article 2A of Chapter 75 of the General Statutes (G.S. 75-60 to 75-66). Section 75-65 sets out when a business must notify North Carolina residents of a security breach, what the notice must contain and when the Attorney General must be told.
    When do I have to notify the North Carolina Attorney General about a breach?
    Under 75-65(f), when you notify more than 1,000 persons at one time, you must also notify the Consumer Protection Division of the Attorney General's Office and the nationwide consumer reporting agencies, without unreasonable delay.
    Does the North Carolina breach law cover paper records?
    Yes. The Act covers personal information "in any form (whether computerized, paper, or otherwise)".
    Can a North Carolina city or county pay a ransomware demand?
    No. G.S. 143-800 prohibits state agencies and local government entities from paying a ransom or communicating with the attacker about one. Those bodies must also report the incident to NCDIT.
    Can my company request a penetration test from the NC CSRF?
    The CSRF serves state and local government and critical infrastructure providers. It completed 13 penetration tests for municipalities in 2023. Private companies hire a commercial provider.
    Does North Carolina have a consumer privacy law?
    Not as of October 2026. Bills including SB 757, HB 462 and SB 1022 were in committee. North Carolina has also not adopted the NAIC Insurance Data Security Model Law.
    Which rules do require a penetration test for a North Carolina company?
    GLBA 16 CFR 314.4(d)(2) for non-bank financial institutions, PCI DSS Requirement 11.4 for anyone handling card data, and CMMC Level 3 for defense suppliers. HIPAA requires a periodic evaluation, for which a pentest is the usual evidence. ---
    NEXT STEP

    See the price for your scope before you book.

    $985 per tester-day for US clients (€849 per day for EU clients). Start within 7 days of booking. Report within 48 hours after testing ends. Pay after delivery.