The CCPA regulations, which took effect on January 1, 2026, introduced an annual cybersecurity audit requirement for certain businesses. The most common misunderstanding we hear is that it applies to every business with revenue above a certain threshold. It does not. Here is who needs it, when, what it covers, and how audits you already have can help.
The two tests
A CCPA-covered business must complete an annual cybersecurity audit if either of the following was true in the preceding calendar year:
- It derived 50% or more of its annual revenue from selling or sharing consumers’ personal information.
- Its annual gross revenue exceeded the CCPA revenue threshold (currently $26,625,000), and it processed either the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more consumers.
Revenue alone is not enough. For example, a $500 million business that does not meet the 50% test, and that in the preceding year processed personal information of 200,000 consumers or households and sensitive personal information of fewer than 50,000 consumers, would not meet either test. By contrast, a $30 million business that processed personal information of 300,000 consumers or households would meet the second test.
Count your workforce too. Employees and job applicants who are California residents are consumers under the CCPA, so their personal information, including sensitive personal information such as Social Security numbers, can count toward these figures unless a statutory or data-specific exemption applies.
When the first audits are due
Each audit covers a 12-month period, and the first deadline depends on annual gross revenue. By the April 1 due date, the business must complete its audit report and submit to CalPrivacy a certification, signed by a member of executive management, that the audit was completed.
- Over $100 million: if 2026 annual gross revenue was more than $100 million as of January 1, 2027, the first audit covers January 1, 2027, to January 1, 2028, and is due April 1, 2028.
- $50 million to $100 million: if 2027 annual gross revenue was at least $50 million but no more than $100 million as of January 1, 2028, the first audit covers January 1, 2028, to January 1, 2029, and is due April 1, 2029.
- Under $50 million: if 2028 annual gross revenue was less than $50 million, the first audit covers January 1, 2029, to January 1, 2030, and is due April 1, 2030.
After its first audit, a business that continues to meet section 7120 must complete audits annually under section 7121(b).
What the audit covers
The audit assesses how the business’s cybersecurity program protects personal information and how the business implements and enforces the program. Of the 18 components listed in the regulation, the audit covers those the auditor deems applicable to the business’s information system, and it may cover additional components where appropriate:
- Authentication, including phishing-resistant multi-factor authentication, and password standards
- Encryption of personal information at rest and in transit
- Account management and access controls, including least privilege and privileged access
- Inventories of personal information, hardware, and software
- Secure configuration, including patch and change management
- Vulnerability scanning, penetration testing, and vulnerability disclosure
- Audit log management
- Network monitoring and defenses
- Antivirus and antimalware protections
- Segmentation
- Limitation and control of ports, services, and protocols
- Cybersecurity threat awareness
- Cybersecurity education and training
- Secure development and code review
- Oversight of service providers, contractors, and third parties
- Data retention schedules and secure disposal
- Incident response management
- Business continuity and disaster recovery, including backups
Who can perform it
The auditor must be qualified, objective, and independent. An internal auditor is permitted if the reporting structure and safeguards satisfy section 7122. The auditor must not participate in activities that compromise independence, including developing procedures, preparing documents, implementing or maintaining the cybersecurity program, or making cybersecurity-program recommendations other than communicating audit findings.
Using the audits you already have
There is no framework safe harbor, but existing work can be reused. Section 7123(f) allows a business to use a cybersecurity audit, assessment, or evaluation prepared for another purpose if it meets all Article 9 requirements, either on its own or through supplementation. The regulation gives the NIST Cybersecurity Framework 2.0 as an example.
PCI DSS, SOC 2, or ISO 27001 evidence may be reusable, but only after gaps in scope, period, applicable components, independence, and report content are addressed. CalPrivacy’s economic analysis modeled approximately 30% lower cybersecurity audit costs for businesses already using a cybersecurity framework. That figure was a modeling assumption, not a guarantee of savings or a legal safe harbor.
Plan backward from your date
If you are in the first group, your audit period begins January 1, 2027. That leaves little time to close gaps in components such as business continuity, retention and disposal, or vendor oversight before the period starts.
How ControlCase helps
ControlCase provides cybersecurity-audit readiness assessments and, where independence requirements are satisfied, the independent Article 9 cybersecurity audit. Before accepting an audit, ControlCase performs an independence review. If our advisory work for a client would compromise the objectivity or independence required of the auditor for the current or a subsequent audit, ControlCase would not perform that audit. Readiness and audit services are scoped and contracted with independence safeguards from the outset.
Frequently asked questions
Can our internal audit team perform the audit?
Yes, if the auditor is qualified, objective, and independent, and the highest-ranking auditor reports directly to a member of executive management who does not have direct responsibility for the cybersecurity program. That executive also conducts the auditor’s performance evaluation and, if applicable, sets the auditor’s compensation.
Does a SOC 2 Type II report satisfy the requirement?
Only if it meets all applicable Article 9 cybersecurity-audit requirements, on its own or through supplementation. Scope, period, applicable components, evidence, independence, and required report content all need to be checked.
What does the business certify?
A member of executive management who is directly responsible for cybersecurity-audit compliance certifies to CalPrivacy, under penalty of perjury, that the business completed the cybersecurity audit as required.
Key takeaways
- The audit applies to businesses that earn 50% or more of their revenue from selling or sharing personal information, or that exceed the revenue threshold and, in the preceding year, processed either the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more consumers.
- First audit reports and certifications are due April 1, 2028 (2026 revenue over $100 million), April 1, 2029 (2027 revenue of $50 million to $100 million), and April 1, 2030 (2028 revenue under $50 million).
- Existing audits can be reused only where they meet all Article 9 requirements, on their own or through supplementation.
This article provides general information and is not legal advice. Content validated through October 6, 2026. It reflects laws enacted and regulations in effect as of that date.
Sources
- CCPA Regulations, Cal. Code Regs. tit. 11, §§ 7120–7124 (effective January 1, 2026): CCPA Regulations
- CalPrivacy, approved regulations text and Final Statement of Reasons (September 2025): CalPrivacy CCPA Updates
- CalPrivacy, Standardized Regulatory Impact Assessment (Initial Statement of Reasons, Appendix A, 2024), cost assumptions: CalPrivacy Regulatory Impact Assessment
- California Civil Code § 1798.140 (definitions of business, consumer, and sensitive personal information): California Legislative Information
See Also
- California 2026 Privacy Bills: What Changed for the CCPA
- CCPA Privacy Risk Assessment: What It Is, With an Example
- Download page for CCPA/CCRA Cheat Sheet
- Download page for CCPA/CCRA Data Sheet
