Cannabis is the only consumer industry where the government tells you where to point your cameras. Every legalized or medicalized market on earth mandates physical security in statute or licence condition — and almost none of them mandate the same physical security.

For single-market operators that’s a checklist. For anyone running two or more jurisdictions, it’s an architecture problem, because the requirements don’t merely differ in strictness — they differ in kind. One regulator specifies retention in days. Another specifies vault construction. A third specifies who is legally allowed to stand in your doorway. A fourth barely specifies anything but expects a documented risk assessment you can defend.

Here is the comparison, and then the control set that satisfies all of them at once.

What Regulators Actually Regulate

Strip the jurisdictional language away and physical-security mandates cluster into six levers:

  1. Surveillance coverage — which zones must be on camera, at what resolution and frame rate
  2. Footage retention — how long, in what form, and how quickly producible to an inspector
  3. Storage/vault standards — construction, locking, and after-hours consolidation of product
  4. Access control and logging — who enters restricted areas, and whether the log is auditable
  5. Alarm and monitoring — intrusion detection, monitoring service, response expectations
  6. Personnel — guard licensing, badging, background screening, visitor escort

Every regime pulls some subset of those levers hard and leaves others slack. The slack is where operators get complacent and where inspectors get interested.

The Jurisdiction Comparison

United States (State by State)

There is no federal standard — an absence we’ve covered in the outlook for federal cybersecurity standards in cannabis — so the strictest states become the de facto baseline for multi-state operators.

California’s DCC is the most prescriptive on surveillance: 24/7 digital video covering all entry and exit points, every area where cannabis goods are weighed, packed, stored, or moved, and all point-of-sale areas, with defined retention and inspector access. California also regulates people: every guard needs a valid BSIS Guard Card, and armed guards need a separate firearms permit — a licensing requirement operators routinely discover mid-audit. The details are in our California cannabis security compliance guide.

Colorado leans harder on limited-access areas, badging, and alarm requirements; the specifics for cannabis and psilocybin facilities alike are in our Colorado compliance guide and the detailed Colorado/Oregon facility security regulations. Newer East Coast markets tend to specify armed or licensed guard presence during cash-handling hours in higher-risk locations.

The structural driver behind all of it is cash. Federal banking limits keep dispensaries cash-heavy, which is why the sector absorbs a disproportionate share of armed robberies and smash-and-grabs — a takeover robbery at gunpoint at a Berkeley dispensary in July 2026 being a routine data point rather than an outlier. Physical risk here is not theoretical, and it’s the same economics driving the insider-theft numbers that dwarf external loss.

Canada

Health Canada’s physical security directive for licence holders is the closest thing the world has to a federal cannabis security standard: defined perimeter and storage-area requirements, intrusion detection, visual monitoring and recording of operations areas, and record retention keyed to the Cannabis Regulations. The difference in flavour versus the US is that Canada regulates the licence holder’s site as a controlled facility with tiered zones, rather than regulating retail floor cameras. Export-oriented producers stack international customer requirements on top, per Canada’s export boom and its supply-chain risks.

Germany

Germany runs two parallel physical-security worlds. Medical cannabis flows through pharmacy and wholesale channels governed by narcotics-law storage requirements — certified safes, documented custody, pharmacist accountability. Cultivation associations under the Cannabis Act carry their own siting, fencing, and youth-protection distance rules. Neither world was designed around retail surveillance, so German operators are typically over-specified on storage and under-specified on video, the mirror image of a California dispensary. Documentation expectations are covered in our Germany Cannabis Act security documentation guide.

Australia

Australian medicinal cannabis physical security is narcotics-control security: ODC licence conditions on cultivation and manufacture sites, with storage, access restriction, and record-keeping requirements enforced through licence compliance rather than retail rules. Because supply reaches patients through pharmacies and telehealth prescribing rather than dispensaries, the physical attack surface is concentrated at cultivation, manufacture, and distribution — while the data attack surface has migrated almost entirely online. See Australia’s TGA-side cybersecurity compliance picture.

Israel

The IMC regime is the most security-forward medical framework in the world by design, with GMP/GSP-derived requirements, perimeter and area controls, and documented custody at every transfer. Israeli operators are often the least surprised by foreign audits, because the IMC baseline already exceeds most of them.

Netherlands and Switzerland

The Dutch controlled-supply experiment and the Swiss pilot trials share a trait that makes them instructive: they are research-grade programs, so physical security is written to protect study integrity and participant confidentiality, not just product. Chain-of-custody documentation and participant-data segregation carry weight that a retail regulator would never think to specify — see the Netherlands experiment’s compliance and data-security setup and Switzerland’s pilots under the nFADP.

Where the Mandates Quietly Agree

Read all seven regimes side by side and a small set of controls appears in every one, sometimes explicitly and sometimes as the only defensible way to meet a general obligation:

  • Continuous recorded video of product-handling and transfer points, producible on demand
  • A restricted-access zone with an auditable entry log — badge, biometric, or attended
  • After-hours consolidation of product into a locked, alarmed store
  • Monitored intrusion detection with a documented response path
  • Personnel screening and a current, revocable credential per individual
  • Written custody records at every hand-off, retained on the regulator’s clock

If your program delivers those six things with evidence, you are compliant nearly everywhere and can close the local delta with paperwork rather than construction.

The Part Almost Every Regime Under-Specifies

Here is the gap that should worry you more than any retention-period mismatch: regulators specify the cameras and ignore the computer the cameras run on.

Surveillance mandates are written as physical requirements, so they get satisfied with physical thinking — lens coverage, storage days, sightlines. Meanwhile the NVR, the access-control server, and the workstation an operator logs into to pull footage for an inspector sit on the network, frequently unpatched, frequently sharing a VLAN with the POS, frequently reachable with a default credential. Compromise that host and you don’t just lose video, you gain the ability to edit the evidentiary record your licence depends on.

That is the converged failure mode we’ve written about in physical-cyber convergence for cannabis operations and in more depth in the surveillance attack surface. The hardening specifics for the box itself — the machine that watches the cameras — are in securing the surveillance and access-control stack, and the network design that keeps it away from payments is the cannabis network segmentation blueprint.

No regulator on this list will fail you for an unpatched NVR. Every regulator on this list will fail you for footage you cannot produce — and an unpatched NVR is the most common reason footage cannot be produced.

Building One Program Instead of Seven

The practical approach for multi-jurisdiction operators:

  1. Adopt the strictest lever in each of the six categories across your footprint as your internal standard. Strictest-of-each is one program; per-market minimums are seven.
  2. Separate the mandate from the implementation. Regulators ask “is the vault area recorded?” Your architecture answers with the same camera platform, same retention engine, same access-log store everywhere. Local deltas become configuration values, not projects.
  3. Treat the security stack as IT infrastructure under change control, with patching, credential rotation, network isolation, and logging — because that’s what it is, regardless of which chapter of the regulations it appears in. Our physical/cyber integration guide is the mapping.
  4. Rehearse footage production against the clock. Pick a random 48-hour window and a random camera, and time how long it takes to hand over clean, timestamped video. That drill catches more real failures than any documentation review.
  5. Keep credentials revocable and per-person across badges, keys, and consoles. High-turnover retail plus shared logins is how insider incidents become unattributable.

Bottom Line

The mandates differ; the physics don’t. Product gets stored, moved, and handed off; people enter restricted spaces; cameras record it; someone must produce the record later. Build to the strictest version of that reality and jurisdiction becomes a paperwork exercise instead of a re-architecture.

And whichever market you’re in, remember which half of the requirement is fragile. The vault door is fine. The machine holding the footage is the one nobody in the regulations is watching.