The company will be required to have its information security program evaluated by a certified third party every other year for the next 20 years.