Program Management

Virtual Compliance Management
Blog About Contact
Schedule Consultation →
August 19, 2026 · Concerto Compliance

CCPA Cybersecurity Audit Requirements: Who's Covered, What Gets Tested, and When It's Due

CCPA CPRA Cybersecurity Audit Privacy
CCPA Cybersecurity Audit Requirements: Who's Covered, What Gets Tested, and When It's Due

What Changed

In 2025 the California Privacy Protection Agency (CPPA) adopted regulations requiring certain businesses to complete an independent cybersecurity audit each year and certify that it was done. Those rules took effect on January 1, 2026. They sit in Cal. Code Regs. tit. 11, §§ 7120–7124, often called Article 9.

This is not a new privacy notice, and it is not a DPIA. It is a security audit of the program that protects California consumers’ personal information: whether that program reasonably protects PI from unauthorized access, destruction, use, modification, or disclosure, and from unauthorized activity that results in a loss of availability.

Not every CCPA business has to do it. The ones that do have a staggered first deadline, a 12-month audit period, and a written certification to the CPPA. The rest of this post is the requirement itself. How you satisfy it with the program you already run is a separate question.

Who Is In Scope

The audit applies to businesses whose processing of consumers’ personal information presents a “significant risk.” That threshold is met if either of the following is true in the prior calendar year:

  1. The business derived 50% or more of annual revenue from selling or sharing consumers’ personal information.
  2. The business had annual gross revenue above the CCPA revenue threshold (currently $26,625,000, adjusted for inflation) and either:
    • processed the personal information of 250,000 or more consumers or households, or
    • processed the sensitive personal information of 50,000 or more consumers.

Those volume numbers are not “California customers only” in the way many teams hope. If you are a covered CCPA business, you need a defensible count of consumers, households, and sensitive PI. B2B SaaS is not exempt. Employee, prospect, and end-user data of California residents counts.

If you are under the threshold today, keep measuring. Crossing it starts a clock, and the first audit period is a full year, not a scramble in Q1.

When the First Audit Is Due

The regulations took effect on January 1, 2026. That is when covered businesses were expected to maintain a cybersecurity program that reasonably protects personal information. The first certification dates are later, and they are staggered by revenue.

CCPA cybersecurity audit first certification timeline by revenue group, from January 2026 rules in effect through April 2030

Revenue (as of the relevant January 1)First audit periodCertification due
More than $100 million (2026 revenue, as of Jan 1, 2027)Jan 1, 2027 through Jan 1, 2028April 1, 2028
$50 million to $100 million (2027 revenue, as of Jan 1, 2028)Jan 1, 2028 through Jan 1, 2029April 1, 2029
Less than $50 million (2028 revenue, as of Jan 1, 2029)Jan 1, 2029 through Jan 1, 2030April 1, 2030

After the first filing, the audit is annual. There is no gap year.

A common misread is treating April 2028 as the start date. For a Group 1 company, the auditor has to cover calendar 2027. Controls that go live in November 2027 will not carry a 12-month period. A clean first audit requires the program to be operating when the period opens, not when the certification is due.

What the Auditor Examines

The auditor evaluates 18 components “to the extent applicable,” considering the business’s size, complexity, and the nature of its processing. That phrase matters. This is not PCI. Not every control is a universal mandate. The auditor still has to look at each area and document why it applies or does not.

The 18 components group into a familiar security program:

Identity and access. Phishing-resistant MFA, strong passwords, least privilege, privileged account limits, physical access to PI.

Data protection. Encryption in transit and at rest, California PI and sensitive PI inventories, classification, retention, and secure disposal.

System hygiene. Hardware and software inventories, secure configuration, patching, change management, masking of sensitive PI where appropriate.

Detection. Vulnerability scanning, penetration testing, a vulnerability disclosure process, centralized audit logging, network monitoring, anti-malware.

Architecture. Segmentation, control of ports, services, and protocols.

People. Cybersecurity awareness (how the business stays current on threats) as a distinct component from education and training.

Build and vendors. Secure development, code review and testing, oversight of service providers, contractors, and third parties.

Resilience. Incident response (including tests) and business continuity, backups, and recovery.

The auditor must support conclusions with evidence, not management assertions. Two report items catch teams off guard: sample copies or descriptions of any data breach notifications sent to consumers or California agencies during the audit period, and a signed statement from the highest-ranking auditor that the review was independent.

The final report also has to describe the systems in scope, the criteria used, the testing performed, gaps found, the remediation plan, and the people responsible for the cybersecurity program.

What You File, and What You Keep

You do not file the audit report with the CPPA.

An executive who is responsible for audit compliance, has knowledge of the audit, and has authority to bind the business submits a written certification that the audit was completed. That certification is due by April 1 following the audit period.

The business and the auditor retain the report and supporting evidence for at least five years.

Who Can Conduct the Audit

The auditor can be internal or external. Independence is not optional either way.

The auditor must be a qualified professional with cybersecurity and audit expertise, using recognized auditing standards such as those from AICPA, PCAOB, ISACA, or ISO. They cannot have participated in developing or maintaining the program they are reviewing. They cannot rely primarily on management’s assertions.

Internal audit is allowed if the highest-ranking internal auditor reports to an executive who is not responsible for the cybersecurity program, and that executive also handles the auditor’s performance evaluation and compensation. Many growth-stage SaaS companies cannot meet that test. In practice, most covered businesses will engage an external auditor.

This is not a CPA-only engagement. CCPA is not SOC 2. A qualified professional working under ISACA or ISO auditing standards can be the auditor of record. What you cannot do is have the same people build the program and then attest to it.

What This Audit Is Not

Privacy risk assessments (Article 10) and automated decision-making technology rules are separate CPPA obligations with their own deadlines. A cybersecurity audit is not a DPIA, and a DPIA is not a cybersecurity audit. Consumer rights, notices, and opt-out mechanisms remain CCPA requirements. They are not a substitute for this audit.

What to Do Next

Confirm whether you meet the threshold. Document how you counted. Identify who will sign the certification. Decide whether the auditor will be internal or external before the audit period opens.

If you already run SOC 2, ISO 27001, or NIST CSF, you are not starting from zero. The next post covers how to map the 18 components to the program you already have, and where even mature programs still need supplementation.

If you need help determining scope or completing the audit, see our CCPA Cybersecurity Audit service.

Related articles

Glenn Chamberlain

Want expert guidance on this?

Our team lives and breathes compliance. Book a free call and we'll help you turn these insights into action.

Talk to Our Team →

I've never met a team who could make compliance as easy, and dare I say FUN!

Cailey Ryckman, VP of Finance

Rainforest Pay