Program Management

Virtual Compliance Management
Blog About Contact
Schedule Consultation →

CCPA/CPRA

California Consumer Privacy Act & California Privacy Rights Act - leading US state privacy law.

CCPA Cybersecurity AuditPrivacy ComplianceVirtual Compliance Management
Schedule Consultation →

The CCPA, as amended by the CPRA, gives California consumers significant rights over their personal information. We help organizations understand their obligations and build compliance programs that address California's requirements alongside other privacy frameworks.

The California Consumer Privacy Act (CCPA), significantly amended by the California Privacy Rights Act (CPRA), establishes comprehensive privacy rights for California residents and obligations for businesses that meet certain thresholds. If your organization has annual gross revenue over the inflation-adjusted threshold (currently $26,625,000), processes data of 100,000+ California consumers, or derives 50%+ of revenue from selling or sharing personal information, the CCPA/CPRA applies to you.

The CPRA amendments, fully effective since January 2023, strengthened the CCPA significantly. They created the California Privacy Protection Agency (CPPA) as a dedicated enforcement body, introduced the concept of 'sensitive personal information' with additional restrictions, expanded consumer rights to include correction and limitation of sensitive data use, and added requirements for data minimization, purpose limitation, and storage limitation that echo GDPR principles.

In 2025 the CPPA adopted regulations requiring certain businesses whose processing presents a 'significant risk' to complete an annual independent cybersecurity audit and certify it to the agency. Those rules took effect January 1, 2026. First certifications are due April 1, 2028 for businesses over $100 million in revenue, with later dates for smaller covered companies. The audit evaluates 18 security components and can reuse an existing NIST CSF 2.0, SOC 2, or ISO 27001 program if every required component is covered.

Key consumer rights under CCPA/CPRA include the right to know what personal information is collected and how it's used, the right to delete personal information, the right to opt out of the sale or sharing of personal information, the right to correct inaccurate personal information, and the right to limit the use of sensitive personal information. Businesses must respond to consumer requests within 45 days and cannot discriminate against consumers who exercise their rights. We design programs that satisfy those rights alongside the cybersecurity audit, GDPR, and other state privacy laws rather than treating each obligation in isolation.

Key areas of CCPA/CPRA.

01

Consumer Rights Management

Implementing processes to receive, verify, and respond to consumer rights requests - know, delete, correct, opt-out, and limit use of sensitive data - within the 45-day timeframe.

02

Privacy Notices & Disclosures

Drafting and maintaining privacy notices that meet CCPA/CPRA's specific disclosure requirements, including categories of information collected, purposes, and third-party sharing.

03

Opt-Out Mechanisms

Implementing 'Do Not Sell or Share My Personal Information' mechanisms, including recognizing Global Privacy Control signals and managing opt-out preferences.

04

Sensitive Personal Information

Identifying processing of sensitive personal information (Social Security numbers, financial accounts, geolocation, etc.) and implementing required disclosures and limitation mechanisms.

05

Service Provider Management

Establishing contractual requirements for service providers and contractors that process personal information, including data use restrictions and audit rights.

06

Cybersecurity Audit

Determining whether the annual independent cybersecurity audit applies, mapping the 18 required components to existing SOC 2 / ISO 27001 / NIST CSF controls, and either performing the audit or preparing the evidence and executive certification.

How we help with CCPA/CPRA.

Hands-on expertise from practitioners who've guided dozens of organizations through CCPA/CPRA compliance.

Applicability Assessment

We determine whether CCPA/CPRA applies to your organization, identify which provisions are relevant to your processing activities, and assess your current compliance posture.

Consumer Request Workflows

We design and implement workflows for receiving, verifying identity, and responding to consumer rights requests within regulatory timelines across all applicable request types.

Multi-State Privacy Program

We design your privacy program to satisfy CCPA/CPRA alongside other state privacy laws (Virginia, Colorado, Connecticut, and others), avoiding redundant compliance efforts.

Cybersecurity Audit

We perform the independent 18-component audit when we did not build the program, or we prepare you for a different auditor when we did. Either way, the CPPA certification is a filing, not a rebuild.

CPPA Readiness

We prepare your organization for potential CPPA enforcement actions and audits, ensuring your practices, documentation, and response procedures meet the agency's expectations.

Ideal For

SaaS companies meeting CCPA/CPRA thresholds that need to establish or mature their compliance program
Organizations that sell or share California consumers' personal information and need opt-out mechanisms
Companies managing privacy compliance across multiple US states and wanting a unified approach
Teams building consumer rights request processes and needing workflows that scale across jurisdictions
Organizations preparing for CPPA enforcement activity and wanting to demonstrate proactive compliance
Covered businesses that need to complete the annual cybersecurity audit and reuse an existing SOC 2, ISO 27001, or NIST CSF program
Talk to an expert

Every engagement starts with a free call. No pitch, just an honest assessment of where you stand with CCPA/CPRA.

Book a Free Call →

How we can help

CCPA Cybersecurity Audit

Independent cybersecurity audits against California's 18-component rule, mapped to the program you already run.

Privacy Compliance

Navigate the global privacy landscape with confidence.

Virtual Compliance Management

Your dedicated compliance team, without the full-time headcount.

From our blog

August 20, 2026 CCPACPRA

How to Satisfy the CCPA Cybersecurity Audit With the Program You Already Have

California did not mandate a single security framework for the CCPA cybersecurity audit. Here is how to map the 18 components to SOC 2, ISO 27001, and NIST CSF, where mature programs still have gaps, and how we audit without standing up a parallel program.

August 19, 2026 CCPACPRA

CCPA Cybersecurity Audit Requirements: Who's Covered, What Gets Tested, and When It's Due

California now requires certain businesses to complete an annual independent cybersecurity audit and certify it to the CPPA. Here is who is in scope, what the 18 components cover, who can audit, and when the first certifications are due.

November 14, 2025 CCPACPRA

CCPA and CPRA: What SaaS Companies Need to Know About California Privacy Law

California's privacy laws apply to more SaaS companies than you'd expect, even if you're not based in California. Here's what CCPA and CPRA require, who's in scope, and how to build a practical compliance program.

Interactive Guide

Compare CCPA/CPRA with other frameworks

See how control areas overlap, what's unique to each standard, and which frameworks complement each other.

Framework Navigator

Ready to move forward?

Book a free consultation with Glenn Chamberlain, Managing Principal. We'll scope out your CCPA/CPRA engagement: timeline, deliverables, and what audit-ready looks like for your team.

Book Your Free Consultation →
Glenn Chamberlain, Managing Principal

I've never met a team who could make compliance as easy, and dare I say FUN!

Cailey Ryckman, VP of Finance

Rainforest Pay