What is CCPA cybersecurity audit?
An annual, independent cybersecurity audit that California’s privacy regulations require of businesses whose processing presents significant risk to consumers’ security.
How it works
Regulations from the California Privacy Protection Agency took effect on 1 January 2026. Businesses that meet the thresholds must have an independent auditor assess their cybersecurity program each year and certify completion to the agency.
The first certifications are phased by revenue: April 2028 for businesses over $100 million, April 2029 for $50–100 million, and April 2030 for the rest. The auditor must be independent of the program they audit.
Key points
- Annual and independent
- Phased deadlines from April 2028
- The auditor must not have built or run the program
- Report goes to a named cybersecurity executive
Common questions
Can our security provider audit us?
Not if they built or run the program being audited. The regulations require independence.
Can an existing audit be reused?
Yes, if it covers everything the regulations require.
Talk to someone who does this every day
Questions about CCPA audit? Our team will give you a straight answer.