South Carolina Insurance Data Security Act: Testing, Certification and Deadlines
The South Carolina Insurance Data Security Act (S.C. Code 38-99-10 to 38-99-100) does not require a penetration test by name. It requires every licensee to run a written information security program, to decide whether to be "regularly testing and monitoring systems and procedures to detect actual and attempted attacks", to report to its board, and to notify the regulator within 72 hours of a cybersecurity event. Here is how a pentest fits that duty.
Who is a licensee, and who is exempt
South Carolina was the first state to adopt the NAIC Insurance Data Security Model Law, in 2018. The Act applies to a "licensee", defined in 38-99-10 as "a person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered pursuant to the insurance laws of this State". Carriers, agencies, producers, adjusters and third-party administrators licensed in South Carolina are all in. Purchasing groups, risk retention groups chartered elsewhere and assuming insurers domiciled in another state are carved out.
Section 38-99-70(A) exempts three groups from the information security program requirements: licensees with "fewer than ten employees", employees and agents who are already covered by another licensee's program, and HIPAA-compliant entities that certify their compliance in writing.
So an independent agency with eight staff is outside the program requirement. An agency with twelve is inside it, and so is every carrier and administrator regardless of size.
The honest answer: what 38-99-20 says about testing
You will read elsewhere that the Act asks licensees to decide on "regular penetration testing". The enacted text does not say that. The word "penetration" does not appear anywhere in Chapter 99. What the Act does say is this.
The risk assessment in 38-99-20(C) must "identify reasonably foreseeable internal or external threats that could result in the unauthorized access to or transmission, disclosure, misuse, alteration, or destruction of nonpublic information", and "assess the likelihood and potential damage of these threats, considering the sensitivity of the nonpublic information". The same subsection, at (C)(5), requires the licensee to "at least annually assess the effectiveness of the safeguards' key controls, systems, and procedures".
Then 38-99-20(D) says: "Based on its risk assessment, the licensee shall" design its program to mitigate the identified risks and determine which security measures are appropriate. The list of measures to weigh runs from access controls and encryption to multifactor authentication and secure disposal. Two items on that list describe testing. Item (e) covers "procedures for evaluating, assessing, and testing the security of externally developed applications". Item (h) is "regularly testing and monitoring systems and procedures to detect actual and attempted attacks on, or intrusions into, information systems".
Read those clauses together and the structure is clear. The Act does not hand you a checklist. It makes you assess your own threats, decide which safeguards fit, prove once a year that the key ones work, and document all of it. If your assessment says an attacker could reach policyholder data through your agency portal, your quoting API, a vendor-built application or your cloud environment, then testing those systems is the safeguard the Act expects you to have considered, and you need a reason on file if you chose not to.
The 15 February annual certification
Under 38-99-20(I), each insurer domiciled in South Carolina must submit a written statement to the Director of Insurance by 15 February each year certifying compliance with the Act. Records supporting the certification must be kept for five years. Where the insurer identifies areas that need material improvement, it must document them and record the remedial effort, and keep that documentation available for the Director's inspection.
The filing duty sits with domestic insurers. Agencies and other licensees do not file the statement, but they still have to run the program and be able to show it when a carrier or the regulator asks.
For insurers the practical consequence is a calendar. Whatever testing you rely on has to be finished, remediated and written up before February, or the certification will describe work you have not yet done.
The 72-hour incident notice
Under 38-99-40(A), a licensee "shall notify the director no later than seventy-two hours after determining that a cybersecurity event has occurred". The duty applies where South Carolina is the licensee's state of domicile or home state, or where the event involves at least 250 consumers and meets the Act's impact criteria.
72 hours starts from the determination, not the intrusion. That makes detection capability part of compliance. A licensee that cannot tell whether an attempted attack succeeded will struggle to start the clock, let alone stop it. The regulator's cybersecurity page at the South Carolina Department of Insurance explains how to file.
Board reporting
Section 38-99-20(E) requires the board, or a board committee, to require executive management to develop and implement the program and to report to the board in writing at least annually. The report covers the overall status of the program, the risk assessment, risk management decisions, third-party arrangements, the results of testing, cybersecurity events and any recommended changes. If management delegates the program, management still has to oversee the delegate and receive compliant reports.
For a board member, "results of testing" is the line to ask about. A test that was never run cannot be reported.
How a scoped annual pentest fits the testing clause and the certification file
A penetration test produces, in one engagement, the evidence five parts of the Act want on file. It feeds the threat assessment in (C) with real findings rather than a guess. It is the annual check on "the effectiveness of the safeguards' key controls, systems, and procedures" that (C)(5) demands. It is the clearest way to show you considered and implemented "regularly testing" under (D)(2)(h), and, where the scope includes a vendor-built portal or application, the "testing the security of externally developed applications" under (D)(2)(e). Its results populate the board report under (E). And its remediation record is the documentation (I) asks the insurer to keep for the February certification.
A sensible scope for a South Carolina licensee is the external perimeter, the agency or policyholder portal, any API used for quoting or claims, any externally developed application that touches nonpublic information, and the cloud environment behind them. Run it once a year, timed so remediation is complete before the certification deadline, and after any major change to those systems.
Budget Security runs penetration tests for South Carolina licensees and their technology vendors with OSCP-certified testers at $985 per tester-day (€849 per day for EU clients). You scope online, testing starts within 7 days of booking, the report is delivered within 48 hours after the test ends, and you pay after the report is delivered. Start on our South Carolina penetration testing page.
South Carolina's general breach law: 39-1-90 and the $1,000-per-resident fine
The Insurance Data Security Act is not the only South Carolina statute an insurance business answers to. S.C. Code 39-1-90 applies to "a person conducting business in this State, and owning or licensing computerized data or other data that includes personal identifying information". That person "shall disclose a breach of the security of the system" to affected residents "in the most expedient time possible and without unreasonable delay" when the information was not encrypted or otherwise rendered unusable and misuse has occurred or is reasonably likely.
The teeth are in subsection (H): "A person who knowingly and wilfully violates this section is subject to an administrative fine in the amount of one thousand dollars for each resident whose information was accessible by reason of the breach, the amount to be decided by the Department of Consumer Affairs." Under subsection (K), a breach notified to more than 1,000 persons must also be reported to the Consumer Protection Division of the Department of Consumer Affairs and to the nationwide consumer reporting agencies.
The scale is real. The Department's 2025 report counted 99 businesses reporting breaches affecting 2,985,506 South Carolina residents, down from 121 breaches and 6,710,824 residents in 2024.
CMMC for Charleston and Upstate defense suppliers
South Carolina's defense base is large. NIWC Atlantic in North Charleston employs almost 8,000 people with a $2.1 billion economic impact, Joint Base Charleston sits next door, Boeing assembles the 787 in North Charleston, and BMW's Greer plant employs 11,000 as the state's largest industrial employer. Suppliers in that chain face CMMC 2.0, in force under 32 CFR Part 170 since 16 December 2024 and written into DoD contracts since 10 November 2025. Level 2 does not mandate a penetration test. Level 3 requires one each year. See our CMMC penetration testing page.
HIPAA: the exemption and the evaluation duty
Health insurers and other licensees that comply with HIPAA can certify that in writing and step outside Chapter 99's program requirements under 38-99-70(A). That does not remove testing from the picture. The HIPAA Security Rule at 45 CFR 164.308(a)(8) requires "a periodic technical and nontechnical evaluation", and a pentest report is the evidence regulators look for. Claiming the HIPAA exemption means being able to show HIPAA-grade evidence instead. See our HIPAA penetration testing page.
FAQ
Questions we get
Does the South Carolina Insurance Data Security Act require penetration testing?
Who has to comply with S.C. Code 38-99?
Is my small insurance agency exempt?
When is the annual certification due?
How fast must I report a cybersecurity event to the South Carolina Department of Insurance?
What is the penalty for violating the Act?
What does South Carolina's general breach law cost if ignored?
How often should an insurance licensee run a penetration test?
See the price for your scope before you book.
$985 per tester-day for US clients (€849 per day for EU clients). Start within 7 days of booking. Report within 48 hours after testing ends. Pay after delivery.