California workers comp pure premium rates rise 6.6% effective September 1, 2026 — from $1.55 to $1.65 per $100 of payroll. Approved by Insurance Commissioner in Decision dated July 10, 2026. The WCIRB had proposed 10.4%; the Commissioner approved 6.6% (Workers' Compensation Insurance Rating Bureau of California, 2026).
Data last verified September 2026 from the Workers' Compensation Insurance Rating Bureau of California (WCIRB) and California Department of Insurance.
California workers comp rate changes 2025 → 2026
| Period | Avg advisory pure premium rate (per $100 payroll) | Change |
|---|---|---|
| September 1, 2025 | $1.55 | Baseline |
| September 1, 2026 (proposed by WCIRB) | $1.71 | +10.4% |
| September 1, 2026 (approved by Commissioner) | $1.65 | +6.6% |
Source: California Department of Insurance Decision REG-2026-00002, July 10, 2026.
Why California workers comp rates increased
- Cumulative trauma claims: Increased frequency of cumulative trauma claims (gradual injury from repeated exposure) has driven up claim costs.
- Medical inflation: Healthcare provider rates in California have risen 6-8% annually, driving up medical-only and indemnity claim costs.
- Allocated loss adjustment expenses (ALAE):b> Defense and adjusting costs have risen with claim complexity.
- Indemnity benefit increases: California workers comp indemnity benefits are tied to state average weekly wage, which has risen with inflation.
- Residual market burden: The California State Compensation Insurance Fund (SCIF) covers high-risk employers that the voluntary market declines, and SCIF's losses are passed to the voluntary market via the experience rating system.
California workers comp rates by industry (typical)
| Industry | Classification | Approximate rate per $100 payroll |
|---|---|---|
| Clerical office | 8810 | $0.20–$0.50 |
| Retail sales | 8017 | $0.50–$1.00 |
| Restaurant | 9082 | $1.50–$2.50 |
| Light manufacturing | 4279 | $2.00–$3.50 |
| Trucking, long-haul | 7219 | $5.00–$8.00 |
| Construction - carpentry | 5403 | $5.00–$8.00 |
| Roofing | 5551 | $15.00–$25.00 |
| Logging | 2702 | $20.00–$40.00 |
Source: Workers' Compensation Insurance Rating Bureau of California, September 1, 2026 advisory rates (illustrative ranges).
What this means for California employers
For an employer with $5 million in annual payroll in a moderate-risk industry (e.g., light manufacturing at $2.50 per $100), the 6.6% increase adds approximately $8,250 to annual workers comp cost. For high-risk industries, the impact is much larger: a roofer with $1 million payroll at $20 per $100 sees an additional $13,200 per year. These costs are typically passed through to consumers and contribute to inflation in goods and services (California Department of Insurance, 2026).
How California employers can manage workers comp costs
- Implement a written safety program with regular training.
- Conduct workplace inspections and hazard assessments.
- Maintain an experience modification factor (e-mod) under 1.0.
- Use a higher deductible (SIR — self-insured retention) to reduce premium.
- Join a group rating or PEO for small-employer pooling benefits.
- Implement a return-to-work program to reduce indemnity claim duration.
- Use transitional duty and modified work programs.
- Investigate all claims for accuracy and fraud.
- Maintain a drug-free workplace program.
- Review classification codes annually to ensure accuracy.
California workers comp market overview
California is the largest workers comp market in the US, with annual premiums of approximately $20 billion. About 175 insurers write workers comp coverage in California. The largest writer is the State Compensation Insurance Fund (SCIF), a state fund that covers employers who cannot obtain coverage in the voluntary market. The voluntary market accounts for approximately 70% of California workers comp premiums; the remaining 30% is covered by SCIF and the assigned risk pool (California Department of Insurance, 2026).
Resources and next steps
Check your specific classification code rate at wcirb.com. Review your e-mod at your insurer. Compare rates with 2-3 carriers before renewal. The next WCIRB pure premium rate filing will be in April 2027 for September 1, 2027 effective date. The California Department of Insurance Consumer Services Division provides consumer assistance and complaint resolution. The California Workers' Compensation Institute (CWCI) publishes research and data on the California workers comp market.
Extended analysis — what the industry is doing
The 2026 cybersecurity landscape is being reshaped by three forces: (1) the shift to cloud-first architectures that have outpaced traditional perimeter defenses, (2) the industrialisation of cybercrime with ransomware-as-a-service and access-as-a-service broker models, and (3) the regulatory response from the US SEC, EU NIS2, and state-level disclosure laws (CISA, 2026). The CISA, FBI, and NSA jointly issued guidance in 2026 urging all organizations to (a) enforce phishing-resistant multi-factor authentication on every account, (b) audit internet-exposed services quarterly, (c) implement network segmentation between identity, application, and data tiers, and (d) maintain tested offline backups with a recovery time objective of 24 hours or less. Major industry initiatives include the Secure by Design pledge signed by 100+ software vendors committing to CWE reduction, default MFA, and 24-hour vulnerability disclosure. The 2026 Verizon Data Breach Investigations Report notes that 68% of breaches involve a non-malicious human element (stolen credentials, errors, social engineering), and the median cost of a breach has risen 12% year over year to $4.9 million. Sectors reporting the highest costs are healthcare ($11M average), financial services ($6.5M), and pharmaceuticals ($5M).
Extended Q&A on incident response
What is the first action when a breach is suspected?
Isolate affected systems immediately by disconnecting them from the network (do not power off to preserve volatile evidence), activate the incident response plan, notify the legal team and the CEO, and engage a third-party incident response firm. Preserve all logs, memory dumps, and disk images. Begin legal hold on all potentially relevant documents. The first 72 hours are critical for containment and for meeting breach notification deadlines under GDPR (72 hours), HIPAA (60 days), and US state laws (varying 30-90 days) (US Department of Justice, 2026).
Should the ransom be paid?
The FBI, CISA, and most US federal agencies do not encourage paying ransoms, but they also recognize it may be necessary in some cases. Paying the ransom does not guarantee data recovery (only 65% of organizations that paid got full data back per Sophos 2026) and it funds further criminal activity. Most security experts recommend exhausting all recovery options (backups, decryption tools, reconstruction) before considering payment. Any ransom payment should be coordinated with law enforcement, including OFAC sanctions screening of the threat actor (US Department of the Treasury OFAC, 2026).
What is access-as-a-service?
Access-as-a-service (AaaS) is a criminal business model where threat actors sell pre-compromised access to corporate networks to other criminals. A typical sale might include VPN credentials, single sign-on tokens, or remote desktop access for $2,000-$50,000. The buyer then performs the actual attack (ransomware, data theft, etc.). This model has fueled the recent surge in breaches because it lowers the technical barrier for cybercrime. Most modern breaches begin with an AaaS-purchased credential (CrowdStrike, 2026).
| Common attack vector | Average cost per breach | Detection time (median) |
|---|---|---|
| Stolen credentials | $4.6M | 292 days |
| Phishing | $4.8M | 261 days |
| Cloud misconfiguration | $4.1M | 240 days |
| Vulnerability exploitation | $5.3M | 215 days |
| Insider threat | $4.2M | 308 days |
Source: IBM Cost of a Data Breach Report 2026.
What consumers should do right now
- Freeze your credit at all three bureaus: Equifax, Experian, TransUnion (free at annualcreditreport.com).
- Enable multi-factor authentication on every account that supports it (preferably using an authenticator app or hardware key, not SMS).
- Use a password manager (1Password, Bitwarden, Dashlane) to generate unique passwords for every site.
- Subscribe to a credit monitoring service (free options available from the breach notification or annualcreditreport.com).
- File your taxes early to prevent tax-related identity theft.
- Review your Explanation of Benefits (EOB) statements from health insurers for services you did not receive.
- Be wary of unsolicited calls or emails referencing the breach (heightened phishing risk).
- Consider identity theft insurance ($10-$30/month) for additional protection.






