Skip links

How to Comply with SB 553: A Step-by-Step Guide for California Employers

HomeSafety ComplianceWVPP › How to Comply

How to Comply with SB 553: A Step-by-Step Guide for California Employers

If you have just realized your facility is not in compliance with SB 553, you are not alone.

If you have just realized your facility is not in compliance with SB 553, you are not alone. The deadline passed on July 1, 2024, and Cal/OSHA has had authority to cite covered employers ever since. Most of the calls we take on this still open with some version of “we don’t have anything in place.” The path back to compliance is well-defined, and the steps run in a specific order.

This page walks through that sequence. It is written for a California employer who knows the requirement exists and wants to know what to actually do, in what order, and where the work tends to break down. For the full overview of the law, the service, and how CDMS handles each piece, see our California Workplace Violence Prevention Plan (SB 553) guide.

The SB 553 compliance sequenceConfirm coverage, assess hazards, write the plan, set up the log and reporting form, deliver initial training, schedule annual review and refresher training, and maintain records.The SB 553 compliance sequence1Confirmcoverage2Assesshazards3Writeplan4Set up log& form5Initialtraining6Annual review/ refresher7MaintainrecordsEach step supports the complete site-specific program.The SB 553 compliance sequenceSeven steps from confirming coverage through maintaining records.Compliance sequence1Confirm coverage2Assess hazards3Write the plan4Set up the logand reporting form5Deliver initial training6Schedule annual review andrefresher training7Maintain records

What SB 553 Compliance Requires

SB 553 created California Labor Code §6401.9, the enforceable requirement that Cal/OSHA cites today. The statute applies to nearly every California employer with 10 or more employees, or any workplace open to the public regardless of headcount. Enforcement runs through Cal/OSHA, not federal OSHA. Federal OSHA has only voluntary guidance on workplace violence; California has a citable standard with penalty exposure.

Compliance has three moving parts that have to be in writing and in place: a site-specific written plan, initial and annual training, and a working violent incident log. Each of the steps below maps to one of those parts.

The SB 553 Compliance Sequence

These seven steps are the order we work in when CDMS builds a plan for a client, and the order Cal/OSHA expects the work to have happened in when an inspector reviews your file.

1

Step 1: Confirm You Are Covered

Before writing anything, confirm the law applies. The coverage trigger is 10 or more employees at the workplace, or any workplace open to the public regardless of size. A 6-person back-office operation with no walk-in traffic is not covered. A 4-person retail counter is. There are four exceptions: employers already under the Cal/OSHA Workplace Violence Prevention in Health Care standard, teleworkers in locations not controlled by the employer, workplaces under 10 employees with no public access, and CDCR and law enforcement facilities. If your situation is borderline, our coverage and exemptions page breaks down each category.

2

Step 2: Assess Hazards Across the Four Violence Types

The hazard assessment is what makes the plan site-specific. Cal/OSHA defines four types of workplace violence: criminal intent by a stranger (Type 1), customer or client violence (Type 2), worker on worker (Type 3), and personal relationship violence brought into the workplace (Type 4). Each type has its own criteria and its own controls. A manufacturing floor with no public access is mostly a Type 1 and Type 3 environment. A retail showroom adds Type 2. A facility with night shifts and parking-lot exposure typically picks up Type 4 risk for at least some employees.

The assessment is a walkthrough of the facility against those four categories. Access points, lighting, parking-lot security, alarm systems, lone-worker scenarios, after-hours operations, public-facing counters, and shift transitions are the elements we examine when we walk a site. The output is a written list of hazards with the controls already in place and the controls that are missing.

3

Step 3: Write the Plan and Assign Responsible Persons by Name

The written plan addresses all the required §6401.9 elements. Those include: responsible persons, employee involvement, coordination with outside employers, reporting and anti-retaliation procedures, employee communication, emergency response, hazard identification and evaluation, hazard correction, post-incident response and investigation, training, and plan review. The full requirements checklist covers each element in detail.

The element that catches in-house drafts most often is responsible persons. The plan has to name individuals, by name, for the statutory responsibilities. “The Safety Manager” is not a name. The plan also has to name a backup or alternate for each role, because compliance does not pause when somebody is on vacation. When we write a plan, we sit with the client and assign each role to a specific person, with a documented alternate.

4

Step 4: Set Up the Violent Incident Log and Reporting Form

The violent incident log is a separate document from the written plan, required by §6401.9. It is also separate from the Cal/OSHA Form 300 log. It captures incidents even when nobody was injured: threats, acts of aggression, near misses. Personally identifying information of victims, witnesses, and other employees has to be omitted from the log.

You also need a reporting form so employees have a defined way to surface incidents that feed into the log. The log fields, the PII omission rule, and the 5-year retention requirement are covered in a separate piece. Set both documents up before initial training, because training has to walk employees through how to report and where the log lives.

Trying to get compliant ahead of an inspection?Tell us your employee count, number of locations, and whether you need Spanish-language training, and we will quote the plan, training, and supporting documents as a fixed-price scope.
5

Step 5: Deliver Initial Training to All Employees

Initial training is delivered to every employee covered by the plan, on the day the plan goes into effect or as soon after as the schedule allows. The training has to be site-specific. That means it covers the actual plan you just wrote, your facility’s hazards, your reporting procedure, the responsible persons named in your plan, and the violent incident log. A generic online module by itself does not meet the rule, because it cannot reference any of those elements.

Delivery format is flexible. In-person sessions, webinars, and online LMS courses are all acceptable, as long as the content is site-specific and there is a verifiable training record for each employee. We deliver in all three formats and in both English and Spanish.

6

Step 6: Put the Annual Review and Refresher Training on the Calendar Before You Need Them

SB 553 requires the plan to be reviewed at least annually, after any workplace violence incident, and whenever a deficiency is identified. Refresher training is also annual. The order matters: the plan review has to happen first, so the refresher training references the current plan, not last year’s. This is where most of the compliance lapses we see start. The plan from 2024 gets shelved, the year passes, and nothing happens until somebody notices on a renewal. The annual review and refresher cycle gets its own page because the sequencing rule trips up so many facilities.

Schedule both before Year 1 ends. A calendar entry that triggers in month 10 of every plan year is the simplest control.

7

Step 7: Maintain Records on the Right Retention Schedule

Records under SB 553 have specific minimum retention periods under California law:

  • Violent incident logs: at least 5 years
  • Hazard identification, evaluation, and correction records: at least 5 years
  • Incident investigation records: at least 5 years
  • Training records: at least 1 year

Employees and their representatives may request to view or copy the violent incident log, and the employer has 15 calendar days to provide it with personally identifying information redacted. Build the recordkeeping system on day one. Trying to reconstruct a year of log entries during an inspection is not a position you want to be in.

What You Can Handle In-House and Where a Consultant Saves Rework

A capable in-house safety lead can build a defensible SB 553 program. We have clients who did exactly that. The pieces that transfer cleanly from a template are the procedural elements: the reporting procedure, the response procedure, the recordkeeping language, the training requirement language. Those follow the regulation closely enough that a careful in-house drafter can adapt them.

The pieces that do not transfer are the hazard assessment, the responsible-person assignments, and the training delivery. The hazard assessment is the most common reason in-house plans get reworked. A plan that says “Type 2 violence has been evaluated and is not applicable” with no documentation behind it, on a facility that has a customer-facing counter, is a deficiency on its face. The same is true of plans copied from a .edu sample published by a university with completely different operations.

Where CDMS most often saves rework is in the assessment, the bilingual training delivery, the annual review cadence, and the inspection-readiness of the file. If your facility has multiple locations, a Spanish-speaking workforce, off-hours shifts, or any history of incidents, the cost of getting any of those wrong on an in-house plan usually exceeds the cost of having the work done once and done correctly.

Common Compliance Gaps We See

When CDMS audits existing plans, the same gaps show up in plan after plan:

  • The hazard assessment treats workplace violence as one category instead of four
  • Responsible persons are named but have since left the company or changed roles
  • Coordination with outside employers (contractors, temp agencies, vendors) is left out entirely
  • A generic online training module was assigned but the records do not show site-specific delivery
  • The violent incident log either does not exist or is confused with the Form 300
  • The annual review obligation is in the plan but has never been performed or documented

Any one of these is a citable deficiency under Cal/OSHA. The compliance sequence above is built to address each of them in the right order.

Ready to put a compliant SB 553 program in place?We will scope the plan, training, and supporting documents based on your facility and give you a fixed-price quote with a delivery timeline.

Trusted throughout California

  • US Foods client logo
  • Azenta client logo
  • Brooks client logo
  • Element Critical client logo
  • Admedes client logo
  • FS Precision Tech client logo
  • Western Colloid client logo
  • Endevco client logo
  • StoreDot client logo
  • Advantage Metal Products client logo
  • Levlad client logo
  • E-Fab client logo
BSY started working with CDMS last year after our in-house EHS person departed the company. CDMS reviewed our existing operational permits as well as any additional Federal, State and Local regulations that could apply and helped us to create a comprehensive compliance calendar to track regulatory deadlines and submittal due dates. The CDMS team does an excellent job of tracking everything and can be relied upon to complete the forms accurately and assist with submittals, allowing me to focus on our business.
Gerona Goethe · General Manager · Bay Ship

Speak with a CDMS EHS expert

Tell us about your facility and your deadline. You’ll get a clear read on what applies and a scoped plan to handle it.