California requires covered businesses to complete an independent cybersecurity audit of 18 control areas and certify it to the CPPA. We perform that audit under recognized ISACA and ISO standards, or we get your existing SOC 2, ISO 27001, or NIST CSF program ready for someone else to sign.
The CPPA's cybersecurity audit rules took effect on January 1, 2026. Covered businesses must complete an independent audit of the program that protects California personal information, then have an executive certify completion to the agency. First certifications are due April 1, 2028 for companies over $100 million in revenue, April 1, 2029 for $50 to $100 million, and April 1, 2030 below that. The audit period is a full year. Waiting until the certification year is how you fail a period that already started.
This is not a CPA-only engagement. The regulation requires a qualified, objective, independent professional with cybersecurity and audit expertise, working under recognized auditing standards such as AICPA, PCAOB, ISACA, or ISO. Our auditors hold CISA and ISO Lead Auditor credentials and already perform independent ISO 27001 internal audits. The same competency applies here. The difference is that for CCPA there is no certification body behind us. If we perform the audit, we are the auditor of record, and we sign the report your executive certifies to the CPPA.
The audit reuses what you already have. NIST CSF 2.0 is the closest official nod. SOC 2 Type II and ISO 27001:2022 cover most of the same ground. The California-specific layer still has to be there: a PI and sensitive PI inventory tied to CCPA definitions, phishing-resistant MFA across the people who can reach that data, a vulnerability disclosure process, PI retention and disposal, and third-party audit cooperation.
Ideal For
Every engagement starts with a free call. No pitch, just an honest assessment of where you stand.
Book a Free Call →How we deliver results.
Independence & Scoping
We confirm whether you are in scope, which revenue-tier deadline applies, and whether we can serve as the independent auditor. If we designed or currently maintain the program, we take the readiness track. If we did not, we scope systems, vendors, and processing activities for a signed audit.
Mapping & Evidence Request
We map the 18 components to your current SOC 2, ISO 27001, or NIST CSF controls and issue a PBC list. You see what existing evidence will carry, what is California-specific, and what still has to be tested over the 12-month period.
Fieldwork or Remediation
On the audit track, we test design and operating effectiveness the way the regulation requires: evidence, not management assertions. On the readiness track, we close gaps, stand up the PI inventory, and build an evidence calendar so a different auditor can sign.
Report & Certification
The audit report includes system description, criteria, testing, findings, remediation plan, responsible parties, breach-notification samples, and a signed auditor statement. We then package the executive certification for CPPA submission and set five-year retention.
Why clients trust our team.
Deep framework knowledge, cloud-native architecture expertise, and auditor relationships that get you clean reports.
Auditors Who Already Sign Independent Work
Our team holds CISA and ISO Lead Auditor credentials and conducts independent ISO 27001 internal audits today. CCPA accepts ISACA and ISO auditing standards. You do not need a CPA firm for this engagement. You do need someone who can test a cybersecurity program and put their name on the report.
One Program, Two Roles, Never Both
If we built or run the program, we prepare it. If we did not, we can audit it. That split is how the regulation's independence rule actually works, and it is the same discipline we already apply when a certification body audits an ISMS we internally audited.
SaaS and California PI in the Same Conversation
We work in multi-tenant, cloud-native environments where California PI lives in product databases, logs, analytics, support tools, and subprocessors. The inventory and access story has to match that architecture, not a generic on-prem checklist.
From our blog
How to Satisfy the CCPA Cybersecurity Audit With the Program You Already Have
California did not mandate a single security framework for the CCPA cybersecurity audit. Here is how to map the 18 components to SOC 2, ISO 27001, and NIST CSF, where mature programs still have gaps, and how we audit without standing up a parallel program.
CCPA Cybersecurity Audit Requirements: Who's Covered, What Gets Tested, and When It's Due
California now requires certain businesses to complete an annual independent cybersecurity audit and certify it to the CPPA. Here is who is in scope, what the 18 components cover, who can audit, and when the first certifications are due.
From One Audit to Eight Frameworks: How We Scaled a Global SaaS Company's Compliance Program
What started as a single ISO 27001 internal audit engagement grew into a comprehensive compliance program spanning SOC 2, ISO 27018, DPST, IRAP, StateRAMP, and Privacy. Here's how trust and deep expertise turned a narrow scope into a global program.
Ready to move forward?
Book a free consultation with Glenn Chamberlain, Managing Principal. We'll scope out your engagement: timeline, deliverables, and what audit-ready looks like for your team.
Book Your Free Consultation →