
Short answer: A CCPA cybersecurity audit is an annual, independent review of a business's security program that California's privacy regulations require when its processing of personal information presents significant risk. Large businesses must certify their first completed audit by April 1, 2028, with smaller in-scope businesses following in 2029 and 2030.
Related guides:
- Keep your business golden with CCPA compliance
- US data privacy compliance checklist
- CCPA and TPRM: third-party risk requirements
- Cybersecurity audit
- CCPA audit checklist
Key takeaways
- The California Privacy Protection Agency (CPPA) finalized regulations on cybersecurity audits, risk assessments and automated decision-making technology in September 2025. They took effect on January 1, 2026.
- The dates and thresholds in this guide reflect those final regulations as we read them. Check the CPPA regulations page for amendments before you plan around them.
- Not every business subject to the CCPA needs a cybersecurity audit. Scope depends on revenue from selling or sharing personal information, or on a revenue threshold combined with the volume of consumer data you process.
- First certifications are phased by annual gross revenue: April 1, 2028, April 1, 2029 or April 1, 2030. After that, the audit is annual.
- The audit must be performed by a qualified, objective and independent auditor, internal or external, and an executive must certify completion to the CPPA.
- Existing audits such as SOC 2 or ISO 27001 can be reused only if they meet every CCPA requirement. Expect to supplement them rather than rely on them as is.
What is a CCPA cybersecurity audit?
It is a yearly assessment of how well your cybersecurity program protects the personal information you hold, carried out against a list of safeguards defined in the CCPA regulations.
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, directed the CPPA to write rules requiring certain businesses to perform annual cybersecurity audits. Those rules are in Article 9 of the CCPA regulations (California Code of Regulations, title 11, sections 7120 to 7124), and they sit alongside two related obligations: privacy risk assessments and rules for automated decision-making technology (ADMT).
Three features set the CCPA audit apart from voluntary frameworks:
- It is mandatory for in-scope businesses. You do not choose to pursue it the way you might choose SOC 2.
- It focuses on personal information. The question is whether your program protects consumers' personal information from unauthorized access, destruction, use, modification or disclosure.
- It ends in a filing with a regulator. A member of executive management certifies to the CPPA that the audit was completed. Under the regulations, the full audit report is retained by the business rather than filed with the certification.
Which businesses need a CCPA cybersecurity audit?
You need one if you are a CCPA "business" and your processing presents significant risk to consumers' security, which section 7120 of the regulations defines with two tests. Treat the table below as a summary and check the regulation text and the CPPA regulations page for the current figures.
| Test | You are in scope if, in the preceding calendar year, you... |
|---|---|
| Data-broker style revenue | Derived 50% or more of annual revenue from selling or sharing consumers' personal information |
| Size plus data volume | Had annual gross revenue above the CCPA revenue threshold ($26,625,000 after the CPPA's 2025 inflation adjustment; the figure is adjusted periodically, so check the current amount) and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers |
A few practical notes for SMBs and HealthTech companies:
- Sensitive personal information has a lower threshold. Health data, precise geolocation, account log-in credentials and government identifiers are all sensitive personal information under the CCPA. A digital health company can cross the 50,000-consumer line much sooner than the 250,000 line.
- HIPAA-covered data is treated separately. The CCPA exempts protected health information collected by a HIPAA covered entity or business associate. The exemption follows the data, not the company, so many HealthTech companies still hold in-scope data, such as marketing leads, app analytics or wellness data collected outside a covered relationship. Ask counsel how the exemption applies to your data flows.
- Check every year. Scope is based on the preceding calendar year, so a growing company can move into scope after a strong year.
When is the first audit certification due?
The first deadline depends on your annual gross revenue, and each certification covers the previous calendar year.
| Annual gross revenue | Audit period | Certification due |
|---|---|---|
| Over $100 million (based on 2026 revenue) | January 1 to December 31, 2027 | April 1, 2028 |
| $50 million to $100 million (based on 2027 revenue) | January 1 to December 31, 2028 | April 1, 2029 |
| Under $50 million (based on 2028 revenue) | January 1 to December 31, 2029 | April 1, 2030 |
After the first certification, the audit repeats every year with a certification due each April 1. The tiers and dates come from section 7121 of the regulations. Check that section for how revenue exactly at $50 million or $100 million is treated and which year's revenue sets your tier, because this table summarizes it.
The related obligations run on their own timelines. Under the final regulations, ADMT requirements apply from January 1, 2027, and for in-scope processing that began before January 1, 2026 and continues afterward, businesses must complete risk assessments by December 31, 2027 and submit information about them to the CPPA by April 1, 2028. Confirm current dates on the CPPA website before you plan around them, because regulators can amend schedules.
What does the audit have to cover?
The audit must assess your cybersecurity program as a whole, then examine a defined list of safeguards and explain any that are not applicable.
The regulations list components that the auditor should evaluate where applicable. Grouped into themes, they look like this:
- Identity and access: authentication, including multi-factor authentication and strong passwords; account management; least-privilege access; restricting privileged accounts.
- Data protection: encryption of personal information at rest and in transit; retention schedules; secure disposal.
- Asset and configuration management: inventories of personal information and of the hardware and software that process it; secure configuration of systems; limiting and controlling ports and services.
- Vulnerability management: internal and external vulnerability scans; penetration testing; patching.
- Monitoring and defenses: network monitoring; audit-log management; antivirus and anti-malware; network segmentation; zero trust architecture.
- People and process: cybersecurity awareness training; secure software development; oversight of service providers and contractors.
- Resilience: incident response management; business continuity and disaster recovery planning.
If the auditor decides a component does not apply to your environment, the report must explain why. The report also has to describe gaps and weaknesses that were found, along with the business's plan and timeframe to address them.
Evidence to start collecting now
- Access review records and MFA enforcement reports from your identity provider
- Encryption configuration exports for databases, storage and endpoints
- Asset and data inventories that show where personal information lives
- Vulnerability scan results, pentest reports and remediation tickets
- Training completion records
- Vendor reviews for service providers that touch personal information
- Incident response and disaster recovery test results
Who is allowed to perform the audit?
A qualified, objective and independent professional must perform it, using procedures and standards accepted in the auditing profession.
The auditor can be external or internal:
- External auditors are the simpler choice for smaller companies, since independence is easier to show. CPA firms and specialist security assessors are both common candidates.
- Internal auditors are allowed, but independence rules apply. The auditor cannot assess activities they were responsible for, and must report audit issues directly to the board or governing body, or, if there is none, to the highest-ranking executive who is not responsible for the cybersecurity program.
Whoever performs it, the business must give the auditor the information they need and must not misrepresent facts. Audit documentation has to be retained for at least five years.
Can a SOC 2 or ISO 27001 audit count?
Yes, but only if the existing audit meets every requirement in the CCPA regulations. Otherwise you can use it as a base and supplement it.
The overlap is large. Most CCPA components map to controls you already test for SOC 2 or ISO 27001. The differences usually show up in scope and reporting:
| Area | SOC 2 or ISO 27001 | CCPA cybersecurity audit |
|---|---|---|
| Scope | The system or ISMS you define | The cybersecurity program protecting personal information |
| Control list | Trust Services Criteria or Annex A, chosen by applicability | Specific components listed in the regulations, with reasons required for exclusions |
| Gap reporting | Exceptions or nonconformities | Gaps, weaknesses and a remediation plan with timeframes |
| Output | Report shared with customers or a certificate | Executive certification filed with the CPPA, plus a retained report |
A practical approach is to align your SOC 2 or ISO 27001 period with the calendar year, extend scope to every system that holds California consumers' personal information, and ask your auditor to produce a CCPA-specific section that addresses each listed component.
How should you prepare for your first audit?
Confirm scope first, then run a gap assessment against the regulation's component list so remediation finishes before your first audit period begins. If you are in the over-$100 million tier, that period starts on January 1, 2027, so your preparation window is a matter of months. A compressed plan for that tier:
- Weeks 1 to 2: confirm scope and engage an auditor, since auditor availability is often the bottleneck.
- Weeks 2 to 6: run the gap assessment and prioritize fixes that must be in place for the whole audit year, such as MFA, encryption and logging.
- By January 1, 2027: start collecting evidence continuously, and keep remediating anything left with documented timelines the auditor can assess.
Everyone else can follow the steps below at a steadier pace.
- Confirm scope. Pull last year's revenue, the number of California consumers and households in your systems, and how much sensitive personal information you process.
- Find your deadline. Use the revenue table above to identify your audit period and certification date.
- Map existing controls. Compare each CCPA component with your current SOC 2, ISO 27001 or HIPAA controls and mark gaps.
- Close gaps early. MFA coverage, encryption, data inventories and vendor oversight are common gaps and take the longest to fix.
- Choose an auditor. Decide between internal and external, and confirm independence and reporting lines in writing.
- Set up continuous evidence. Collect evidence across the full calendar year, not just before fieldwork.
- Name the certifying executive. Agree who will sign the certification and how they will get comfortable with it.
How SecureSlate helps
SecureSlate helps you track the SOC 2, ISO 27001 and HIPAA controls you already run, so your team can compare them manually against the CCPA audit components and see which areas need extra work. SecureSlate does not perform the audit; that has to be done by a qualified, independent auditor. Where you connect supported tools, such as an identity provider or MDM, integrations help collect evidence like MFA enforcement and device encryption throughout the year, and access reviews are tracked in SecureSlate. Vendor risk management tracks the service providers that handle personal information, and policy management keeps incident response, retention and training policies current.
Start your free SecureSlate trial
FAQ
Do all businesses covered by the CCPA need a cybersecurity audit?
No. Only businesses whose processing presents significant risk to consumers' security need one. That means earning 50% or more of revenue from selling or sharing personal information, or exceeding the revenue threshold while processing personal information of 250,000 or more consumers or households, or sensitive personal information of 50,000 or more consumers.
Do we submit the full audit report to the CPPA?
Under the regulations, the business submits a certification of completion signed by a member of executive management, not the full report. You retain the report and supporting documentation for at least five years and should be ready to produce them if the CPPA asks.
Can our internal audit team perform the CCPA cybersecurity audit?
Yes, if the auditor is qualified, objective and independent. Internal auditors cannot assess work they were responsible for, and they must report audit issues directly to the board or governing body, or to the highest-ranking executive not responsible for the cybersecurity program.
How is the CCPA cybersecurity audit different from a CCPA risk assessment?
The cybersecurity audit examines whether your security program protects personal information. A risk assessment examines whether a specific processing activity, such as selling data or using ADMT for significant decisions, creates privacy risks that outweigh its benefits. Both come from the same set of regulations but have separate scopes and deadlines.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds