The CCPA, as amended by the CPRA, gives California consumers significant rights over their personal information. We help organizations understand their obligations and build compliance programs that address California's requirements alongside other privacy frameworks.
The California Consumer Privacy Act (CCPA), significantly amended by the California Privacy Rights Act (CPRA), establishes comprehensive privacy rights for California residents and obligations for businesses that meet certain thresholds. If your organization has annual gross revenue over the inflation-adjusted threshold (currently $26,625,000), processes data of 100,000+ California consumers, or derives 50%+ of revenue from selling or sharing personal information, the CCPA/CPRA applies to you.
The CPRA amendments, fully effective since January 2023, strengthened the CCPA significantly. They created the California Privacy Protection Agency (CPPA) as a dedicated enforcement body, introduced the concept of 'sensitive personal information' with additional restrictions, expanded consumer rights to include correction and limitation of sensitive data use, and added requirements for data minimization, purpose limitation, and storage limitation that echo GDPR principles.
In 2025 the CPPA adopted regulations requiring certain businesses whose processing presents a 'significant risk' to complete an annual independent cybersecurity audit and certify it to the agency. Those rules took effect January 1, 2026. First certifications are due April 1, 2028 for businesses over $100 million in revenue, with later dates for smaller covered companies. The audit evaluates 18 security components and can reuse an existing NIST CSF 2.0, SOC 2, or ISO 27001 program if every required component is covered.
Key consumer rights under CCPA/CPRA include the right to know what personal information is collected and how it's used, the right to delete personal information, the right to opt out of the sale or sharing of personal information, the right to correct inaccurate personal information, and the right to limit the use of sensitive personal information. Businesses must respond to consumer requests within 45 days and cannot discriminate against consumers who exercise their rights. We design programs that satisfy those rights alongside the cybersecurity audit, GDPR, and other state privacy laws rather than treating each obligation in isolation.
Key areas of CCPA/CPRA.
Consumer Rights Management
Implementing processes to receive, verify, and respond to consumer rights requests - know, delete, correct, opt-out, and limit use of sensitive data - within the 45-day timeframe.
Privacy Notices & Disclosures
Drafting and maintaining privacy notices that meet CCPA/CPRA's specific disclosure requirements, including categories of information collected, purposes, and third-party sharing.
Opt-Out Mechanisms
Implementing 'Do Not Sell or Share My Personal Information' mechanisms, including recognizing Global Privacy Control signals and managing opt-out preferences.
Sensitive Personal Information
Identifying processing of sensitive personal information (Social Security numbers, financial accounts, geolocation, etc.) and implementing required disclosures and limitation mechanisms.
Service Provider Management
Establishing contractual requirements for service providers and contractors that process personal information, including data use restrictions and audit rights.
Cybersecurity Audit
Determining whether the annual independent cybersecurity audit applies, mapping the 18 required components to existing SOC 2 / ISO 27001 / NIST CSF controls, and either performing the audit or preparing the evidence and executive certification.
How we help with CCPA/CPRA.
Hands-on expertise from practitioners who've guided dozens of organizations through CCPA/CPRA compliance.
Applicability Assessment
We determine whether CCPA/CPRA applies to your organization, identify which provisions are relevant to your processing activities, and assess your current compliance posture.
Consumer Request Workflows
We design and implement workflows for receiving, verifying identity, and responding to consumer rights requests within regulatory timelines across all applicable request types.
Multi-State Privacy Program
We design your privacy program to satisfy CCPA/CPRA alongside other state privacy laws (Virginia, Colorado, Connecticut, and others), avoiding redundant compliance efforts.
Cybersecurity Audit
We perform the independent 18-component audit when we did not build the program, or we prepare you for a different auditor when we did. Either way, the CPPA certification is a filing, not a rebuild.
CPPA Readiness
We prepare your organization for potential CPPA enforcement actions and audits, ensuring your practices, documentation, and response procedures meet the agency's expectations.
Ideal For
Every engagement starts with a free call. No pitch, just an honest assessment of where you stand with CCPA/CPRA.
Book a Free Call →How we can help
CCPA Cybersecurity Audit
Independent cybersecurity audits against California's 18-component rule, mapped to the program you already run.
Privacy Compliance
Navigate the global privacy landscape with confidence.
Virtual Compliance Management
Your dedicated compliance team, without the full-time headcount.
From our blog
How to Satisfy the CCPA Cybersecurity Audit With the Program You Already Have
California did not mandate a single security framework for the CCPA cybersecurity audit. Here is how to map the 18 components to SOC 2, ISO 27001, and NIST CSF, where mature programs still have gaps, and how we audit without standing up a parallel program.
CCPA Cybersecurity Audit Requirements: Who's Covered, What Gets Tested, and When It's Due
California now requires certain businesses to complete an annual independent cybersecurity audit and certify it to the CPPA. Here is who is in scope, what the 18 components cover, who can audit, and when the first certifications are due.
CCPA and CPRA: What SaaS Companies Need to Know About California Privacy Law
California's privacy laws apply to more SaaS companies than you'd expect, even if you're not based in California. Here's what CCPA and CPRA require, who's in scope, and how to build a practical compliance program.
Interactive Guide
Compare CCPA/CPRA with other frameworks
See how control areas overlap, what's unique to each standard, and which frameworks complement each other.
Ready to move forward?
Book a free consultation with Glenn Chamberlain, Managing Principal. We'll scope out your CCPA/CPRA engagement: timeline, deliverables, and what audit-ready looks like for your team.
Book Your Free Consultation →
“I've never met a team who could make compliance as easy, and dare I say FUN!”
Cailey Ryckman, VP of Finance
