CCPA Cybersecurity Audit Requirements 2026: Thresholds, Deadlines & ADMT Rules
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
Quick answer
California’s 2026 CCPA regulations (effective January 1, 2026) require qualifying businesses to run annual cybersecurity audits and certify them to the CPPA, plus complete ADMT risk assessments. Who is covered and when:
- Applies if you have $25M+ annual revenue and process 250,000+ consumers (or 50,000+ sensitive), or derive 50%+ of revenue from selling or sharing data.
- Audit certifications are staggered by revenue: April 1, 2028 ($100M+), then April 2029, then April 2030.
- Audits must cover access controls, data integrity, disclosure controls, availability, and program governance.
- Conduct ADMT risk assessments before automated decision-making that significantly affects consumers.
New Cybersecurity Audit Regulations Under the CCPA
On September 23, 2025, the California Office of Administrative Law approved final regulations that add significant new requirements under the CCPA: mandatory cybersecurity audits, automated decision-making technology (ADMT) risk assessments, and expanded consumer rights around algorithmic processing. These regulations took effect on January 1, 2026, and mark a major shift from the CCPA’s original focus on transparency and opt-out rights to deeper accountability and security obligations (see the CPPA’s Regulations page and the official September 23, 2025 OAL approval announcement, retrieved May 20, 2026).
If your business processes personal information of California consumers, you need to understand whether these new requirements apply to you and what steps you must take. Use our Privacy Law Calculator to determine which state privacy laws apply to your business overall.
Who Must Conduct Cybersecurity Audits?
The cybersecurity audit requirement applies to businesses whose processing activities present “significant risk to consumers’ privacy.” The regulations define two categories of businesses that meet this threshold:
Category 1: Large-Scale Processors
Businesses that meet all three of the following criteria:
- Annual gross revenue exceeding $25 million
- Process personal data of 250,000 or more consumers, or sensitive personal information of 50,000 or more consumers
- Processing presents significant risk to consumer privacy (as defined by the regulations)
Category 2: Data-Driven Revenue Businesses
Businesses that derive 50% or more of annual revenue from selling or sharing consumers’ personal information, regardless of their total revenue or processing volume.
CCPA Cybersecurity Audit Applicability Worksheet
As of June 11, 2026, the practical scope test is a three-part worksheet: first confirm that the CCPA applies to the business, then test whether section 7120’s cybersecurity-audit triggers are met, then map the business to the first audit year. That sequencing matters because a company can be a CCPA business without being large enough, or risky enough, to owe an annual cybersecurity audit.
| Question | Threshold to Check | Why It Matters |
|---|---|---|
| Are you already a CCPA business? | Annual gross revenue over $25 million, or another CCPA applicability threshold. | The cybersecurity-audit article builds on the CCPA business definition; it is not a stand-alone security law for every company. |
| Do you process enough California personal information? | Personal information of 250,000+ consumers or households, or sensitive personal information of 50,000+ consumers. | This is the large-scale processing trigger most likely to pull high-growth consumer businesses into the audit requirement. |
| Do you sell or share data as a revenue model? | 50% or more of annual revenue from selling or sharing personal information. | This trigger can apply even when the business is smaller than the 250,000-consumer processing threshold. |
| Which certification tier applies? | Over $100M, $50M-$100M, or under $50M annual gross revenue. | The revenue tier controls the first CPPA certification date, but the audit work starts during the prior calendar-year audit period. |
Source check: Last verified June 11, 2026 against the CPPA’s completed rulemaking page and approved regulation text for Cal. Code Regs. tit. 11, §§ 7120–7124 (date_retrieved: 2026-06-11).
Not sure if your business meets these thresholds? Our compliance calculator can help you assess your obligations across all state privacy laws, including California’s enhanced requirements.
What Must the Cybersecurity Audit Cover?
At a high level, the audit must assess how your cybersecurity program protects personal information against unauthorized access, destruction, use, modification, or disclosure, and against loss of availability. That overall objective breaks down into five areas:
- Unauthorized access prevention — controls that prevent unauthorized access to personal information
- Data integrity — protections against unauthorized destruction, use, or modification of personal data
- Disclosure controls — safeguards against unauthorized disclosure of personal information
- Availability protections — measures to prevent loss of availability of personal information
- Program governance — organizational structure, policies, and procedures supporting the cybersecurity program
What sets California’s rule apart from generic “assess your security” mandates is how prescriptive it is about specific controls. Under Cal. Code Regs. tit. 11, § 7123, the audit must evaluate the business’s implementation of each of the following components — or document why a component is not necessary given the business’s size, complexity, and processing activities:
- Phishing-resistant multi-factor authentication across accounts
- Encryption of personal information at rest and in transit
- Access controls — least-privilege and privileged-access management
- Data inventories — data maps, flows, and access methods
- Secure configuration — patch management and change management
- Vulnerability management — scanning and penetration testing
- Audit logging — centralized storage, retention, and monitoring
- Network monitoring and defense — intrusion detection / prevention (IDS/IPS)
- Anti-malware protections
- Segmentation — properly configured firewalls, routers, and switches
- Limitation and control of ports, services, and protocols
- Cybersecurity threat awareness and current threat-intelligence practices
- Security education and training for all personnel
- Secure development — code review and testing practices
- Service-provider, contractor, and third-party oversight, including CCPA contract terms
- Secure data disposal — shredding, erasing, or de-identifying personal information
- Incident response — a documented, tested response plan
- Business continuity and disaster recovery — data recovery and backups
For each component the auditor must describe how it is applied, identify any gaps or weaknesses, and note corrections planned or made — the audit cannot simply mark items “compliant” without supporting analysis (see the CPPA’s approved regulation text, § 7123, retrieved May 27, 2026).
The audit must be conducted by a qualified, independent auditor who operates independently and relies on their own analyses. Companies cannot simply self-certify — the auditor must be external or have sufficient organizational independence.
Certification Submission Deadlines
One of the most important details is the tiered submission schedule for cybersecurity audit certifications to the California Privacy Protection Agency (CPPA). The deadlines are based on your business’s annual gross revenue:
| Annual Gross Revenue | First Certification Due | Audit Period Covered |
|---|---|---|
| Over $100 million | April 1, 2028 | Jan 1, 2027 – Jan 1, 2028 |
| $50 million – $100 million | April 1, 2029 | Jan 1, 2028 – Jan 1, 2029 |
| Under $50 million | April 1, 2030 | Jan 1, 2029 – Jan 1, 2030 |
The audit-period column is the detail most summaries skip: each first certification reports on the prior 12-month window, so a business over $100 million in revenue is effectively auditing its 2027 program even though the certification is not due until April 2028. Plan your gap-remediation timeline against the audit period, not the filing deadline. After the initial cycle, a covered business must submit a certification by April 1 of each following year it meets the criteria, and both the company and the auditor must retain all documents relevant to each audit for a minimum of five years (CPPA cybersecurity audit regulations, Cal. Code Regs. tit. 11, §§ 7120–7124, retrieved May 27, 2026).
Evidence File: What to Collect Before the Audit Year Starts
The CCPA audit is evidence-driven. Section 7122 says audit findings cannot rely primarily on management assertions; the auditor must rely on evidence such as documents reviewed, sampling, testing, and interviews. That means the workstream should produce a standing evidence file before the first audit period begins, not a scramble after the certification deadline is close.
| Evidence Category | Examples to Preserve | Retention Note |
|---|---|---|
| Governance and scope | Data inventory, system inventory, audit scope memo, processor and service-provider list. | Keep the version used to scope each annual audit. |
| Control operation | MFA configuration evidence, encryption settings, access-review samples, vulnerability scans, penetration-test reports, patch records. | Preserve enough samples to show controls operated during the audit period. |
| Third-party oversight | Vendor risk reviews, CCPA contract terms, security questionnaires, remediation tracking. | Useful where personal information is processed by service providers or contractors. |
| Incident and recovery readiness | Incident-response tabletop notes, breach-notification decision records, backup and recovery tests. | Section 7123 requires sample breach or agency notifications when applicable. |
A business may reuse an audit, assessment, or evaluation prepared for another purpose, including one based on NIST Cybersecurity Framework 2.0, but only if that work satisfies all CCPA cybersecurity-audit requirements on its own or through supplementation. Treat SOC 2, ISO 27001, and NIST CSF 2.0 as starting frameworks, then build a CCPA gap matrix against sections 7120 through 7124. Source check: verified June 11, 2026 against the CPPA approved regulation text, including §§ 7122–7124, and NIST CSF 2.0 (date_retrieved: 2026-06-11).
ADMT Risk Assessments: The Other New Requirement
Alongside cybersecurity audits, the new regulations also require businesses that use automated decision-making technology (ADMT) to conduct risk assessments and provide consumers with expanded rights. Key requirements include:
- Pre-use notice — consumers must be informed when ADMT is being used to make decisions that produce legal or similarly significant effects
- Opt-out right — consumers can opt out of ADMT processing for significant decisions
- Access to logic — consumers can request meaningful information about the logic used in ADMT decisions
- Risk assessments — businesses must assess ADMT processing activities for risks to consumer privacy and submit assessments to the CPPA
For a broader look at how states handle automated decision-making, see our guide on automated decision-making and profiling under state privacy laws.
How to Prepare: A Practical Compliance Roadmap
Even though certification deadlines are in 2028–2030, businesses should start preparing now. Here is a practical roadmap:
Step 1: Determine Applicability (Now)
- Calculate whether your business meets the revenue and processing volume thresholds
- Inventory all personal information processing activities involving California consumers
- Identify whether you use any ADMT for decisions with legal or significant effects
Step 2: Gap Assessment (Q2 2026)
- Evaluate your existing cybersecurity program against the regulation’s requirements
- Identify gaps in documentation, governance, technical controls, and incident response
- Map your ADMT use cases and assess consumer-facing disclosure obligations
Step 3: Remediation and Program Building (Q3–Q4 2026)
- Implement any missing technical controls identified in the gap assessment
- Develop or update written information security policies
- Establish audit governance procedures and select a qualified auditor
- Build ADMT risk assessment processes and consumer-facing opt-out mechanisms
Step 4: Mock Audit (2027)
- Conduct a preliminary internal or mock audit to identify remaining issues
- Remediate findings before the formal audit
- Document everything — the CPPA will expect thorough records
Step 5: Formal Audit and Certification (2028+)
- Engage your independent auditor for the formal cybersecurity audit
- Submit certification to the CPPA by your applicable deadline
- Retain all audit documentation for at least five years
How This Connects to Existing CCPA Obligations
The cybersecurity audit requirements build on top of existing CCPA obligations. Businesses must still comply with all existing requirements including:
- Honoring consumer rights (access, delete, correct, opt-out) — see our DSAR guide
- Honoring Global Privacy Control (GPC) signals
- Providing required privacy policy disclosures
- Meeting data broker registration requirements under the California Delete Act
The new audit requirements add a security and accountability layer on top of these existing transparency obligations. For a complete compliance picture, see our CCPA compliance guide and use our California compliance checklist.
What Happens If You Don’t Comply?
The CPPA can enforce the cybersecurity audit regulations using its standard enforcement powers under the CCPA. As of 2026, penalties are:
- $2,663 per unintentional violation
- $7,988 per intentional violation or violation involving a minor
Given that cybersecurity audit failures could affect entire databases of consumer information, the per-violation penalty structure means fines could scale quickly. The CPPA has demonstrated its willingness to enforce aggressively in 2026, with the PlayOn $1.1M fine, Disney $2.75M settlement, and Ford $375K penalty all coming in the first quarter alone. See our penalties and fines guide for more on enforcement trends.
Frequently Asked Questions
Do small businesses need to conduct CCPA cybersecurity audits?
Only if they meet the threshold criteria. Most small businesses with less than $25 million in annual revenue and fewer than 250,000 consumer records will not be required to conduct audits. However, businesses that derive 50% or more of revenue from selling personal information are covered regardless of size.
Can we use an internal auditor?
The regulations require the auditor to operate independently. While the regulations do not explicitly prohibit internal audit functions, the auditor must have sufficient organizational independence and rely on their own analyses. Most businesses will likely engage external audit firms to ensure independence requirements are met.
How do the cybersecurity audit requirements interact with other state laws?
California’s cybersecurity audit requirement is currently the most prescriptive among US state privacy laws. However, several other states require risk assessments for high-risk processing. If you operate in multiple states, use our state comparison tool to understand overlapping requirements. A robust cybersecurity audit program for CCPA compliance will likely satisfy or exceed requirements in other states.
What specific security controls does a CCPA cybersecurity audit assess?
Section 7123 of the regulations enumerates roughly 18 controls the audit must cover: phishing-resistant multi-factor authentication, encryption of personal information at rest and in transit, least-privilege access management, data inventories and flow maps, patch and change management, vulnerability scanning and penetration testing, centralized audit logging, intrusion detection/prevention, anti-malware, network segmentation, control of ports and protocols, threat awareness, security training, secure development, third-party oversight, secure data disposal, a tested incident response plan, and backup/disaster recovery. For each control the auditor must document how it is implemented and any gaps found — you cannot simply self-certify that you are “compliant.”
What time period does the first CCPA cybersecurity audit cover?
Each certification reports on a 12-month audit period ending shortly before its April deadline. For the first cycle, a business over $100 million in revenue audits January 1, 2027 to January 1, 2028 and certifies by April 1, 2028; the $50–$100 million tier audits 2028 and certifies by April 1, 2029; and the under-$50 million tier audits 2029 and certifies by April 1, 2030. Because the audit window precedes the deadline, your remediation work should be finished before the audit period begins, not before the filing date.
Can an existing SOC 2, ISO 27001, or NIST CSF audit satisfy the CCPA audit rule?
Possibly, but not automatically. The CPPA regulations allow a cybersecurity audit, assessment, or evaluation prepared for another purpose to be used if it meets all CCPA Article 9 requirements on its own or through supplementation. In practice, map the existing report to sections 7120 through 7124, then add CCPA-specific evidence for consumer personal information, service-provider oversight, breach-notification samples, certification language, and five-year record retention.
What frameworks can guide our cybersecurity audit?
The regulations do not mandate a specific framework, but established standards like NIST Cybersecurity Framework, ISO 27001, and SOC 2 provide strong foundations. The key is ensuring your program addresses all areas specified in the regulations: access controls, data integrity, disclosure safeguards, availability, and governance.
Published: March 30, 2026. Last verified: June 11, 2026. Primary sources: CPPA approved regulation text (§§ 7120–7124), the CPPA Regulations page, and NIST Cybersecurity Framework 2.0, retrieved June 11, 2026.
Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.