The CCPA Cybersecurity Audit: Does It Apply to You, and When?
California now requires an annual cybersecurity audit from a defined slice of covered businesses, and the first reports are due on one of three dates: April 1, 2028, April 1, 2029, or April 1, 2030, set by revenue tier. The regulations were adopted by the California Privacy Protection Agency board on July 24, 2025, approved by the Office of Administrative Law, and took effect January 1, 2026 (CPPA rulemaking page). The counterintuitive part, and the reason most readers of this page do not have a 2028 problem: being a "business" under the CCPA does not put you in scope. The audit rule uses a narrower test than the statute does, and one of the three ways to become a CCPA business is not a trigger at all.
Source note: everything below is quoted from the Agency's own approved regulation text and from the California Civil Code, not from a vendor summary. The Agency has no product to sell, which makes it the cleanest source available here; our own bias is the opposite, since we sell readiness work, and the independence rule in section 7122 is where that bias cuts against us. This piece covers who is in scope, when, what the audit actually examines, who may perform it, and what to do in the eighteen months before the first tier lands.
Key takeaways
- Scope turns on section 7120, not on the CCPA definition of a business. Meeting the 100,000-consumer buy, sell or share threshold alone does not put you in scope.
- Three deadlines, by revenue tier: April 1, 2028, April 1, 2029, and April 1, 2030 for the first report. After that it is annual.
- The audit assesses 17 named components where applicable, including multi-factor authentication, encryption, and penetration testing.
- The auditor may be internal or external, but must not have developed, implemented or maintained the program being audited. That disqualifies the firm that built it.
- A separate executive certification goes to the Agency by April 1 each covered year, signed under penalty of perjury, including an attestation that nobody tried to influence the auditor.
Are you in scope? Read section 7120, not the statute
Section 7120 says that "Every business whose processing of consumers' personal information presents significant risk to consumers' security" must complete a cybersecurity audit, and then defines that phrase exhaustively. Processing presents significant risk if either of the following is true (approved regulation text, section 7120):
- The business meets the threshold in Civil Code section 1798.140, subdivision (d)(1)(C) in the preceding calendar year; or
- The business meets the threshold in subdivision (d)(1)(A) and either processed the personal information of 250,000 or more consumers or households in the preceding calendar year, or processed the sensitive personal information of 50,000 or more consumers in the preceding calendar year.
Now decode the cross-references. Civil Code section 1798.140(d)(1) defines a business by three alternative thresholds: (A) annual gross revenues in excess of twenty-five million dollars in the preceding calendar year, "as adjusted pursuant to subdivision (d) of Section 1798.199.95"; (B) annually buying, selling or sharing the personal information of 100,000 or more consumers or households; and (C) deriving 50 percent or more of annual revenues from selling or sharing consumers' personal information (California Civil Code section 1798.140).
Notice what section 7120 did with that list. Subdivision (B), the 100,000-consumer route into CCPA coverage, appears nowhere in the audit trigger. A company that became a CCPA business purely on record count, with modest revenue and no data-sale revenue, is not caught by the audit rule. That is the single most common misreading we encounter, and it is the difference between a compliance project and no project at all.
On the revenue figure itself, be careful. The statute says twenty-five million dollars as adjusted for inflation, and the Agency has adjusted it: the CPPA announced an adjusted threshold of $26,625,000 effective January 1, 2025 (CPPA announcement, December 17, 2024). As of August 2026 that is the last adjustment the Agency has announced. Test against the Agency's current published figure rather than against the number in the statute, and re-check it before you rely on the answer, because this is exactly the kind of value that goes stale quietly. Our survey of US state privacy laws carries the same figure and the wider multi-state picture.
The three deadlines, and which one is yours
Section 7121 sets the first-report deadline by revenue tier, and it also fixes the period each first audit has to cover:
- April 1, 2028, if annual gross revenue for 2026 was more than 100 million dollars as of January 1, 2027. The audit covers January 1, 2027 through January 1, 2028.
- April 1, 2029, if annual gross revenue for 2027 was between 50 million and 100 million dollars as of January 1, 2028. The audit covers January 1, 2028 through January 1, 2029.
- April 1, 2030, if annual gross revenue for 2028 was less than 50 million dollars. The audit covers January 1, 2029 through January 1, 2030.
After April 1, 2030 the rule settles into an annual rhythm: if on January 1 of a year you meet the section 7120 criteria for the preceding year, the audit covers the next twelve months and the report is due by April 1 of the year after that.
Read the covered periods rather than only the due dates, because they are where the real planning deadline hides. A business in the first tier is audited over calendar 2027. Controls that are not operating on January 1, 2027 are inside the audited period, not before it. That pulls the actual work into 2026, which is where you are standing now.
What the audit examines
Section 7123 requires the audit to assess how your cybersecurity program protects personal information from unauthorized access, destruction, use, modification or disclosure, and against unauthorized activity resulting in loss of availability. It then names 17 components that the audit must assess "if applicable", and the list is unusually concrete for a privacy regulation.
Among them: authentication including multi-factor authentication, with phishing-resistant multi-factor authentication called out for personnel, service providers and contractors; encryption of personal information at rest and in transit; account management and access controls, including restricting privileged accounts and revoking access when job functions end; inventory and management of personal information and the information system; secure configuration, including change management; "Internal and external vulnerability scans, penetration testing, and vulnerability disclosure and reporting"; audit-log management; network monitoring and defenses; segmentation; cybersecurity education and training; secure development and coding practices including code review and testing; oversight of service providers and contractors; retention schedules and disposal; and incident response management, including how you test that capability.
Two consequences follow immediately. First, this is a controls audit with a familiar shape. If you already run SOC 2 or ISO 27001, most of the evidence exists and the work is mapping rather than building, which is the same reuse logic as reusing evidence across frameworks. Second, penetration testing is named in the regulation text, so it is not an optional interpretation of a generic "testing" clause. If you have been treating testing cadence as discretionary, this is a regulator writing it down.
Section 7122 adds an evidentiary rule that changes how the engagement feels: "No finding of any cybersecurity audit may rely primarily on assertions or attestations by the business's management." Findings must rest primarily on specific evidence, meaning documents reviewed, sampling and testing performed, and interviews conducted. A questionnaire round trip will not produce a compliant audit. And both the business and the auditor must retain all documents relevant to each audit for a minimum of five years.
Who may perform it, and why that rules us out
This is the section that cuts against our own interest, so we will quote it in full rather than summarize it.
The auditor must be "a qualified, objective, independent professional" using "procedures and standards accepted in the profession of auditing", with the regulation naming the American Institute of Certified Public Accountants, the Public Company Accounting Oversight Board, ISACA and ISO as examples of the bodies whose procedures qualify. The auditor may be internal or external. But: the auditor "must not participate in activities that may compromise the auditor's independence. For example, the auditor must not participate in business activities that the auditor may assess in the current or subsequent cybersecurity audits, including developing procedures, preparing the business's documents, making recommendations regarding the business's cybersecurity program (separate from articulating audit findings), or implementing or maintaining the business's cybersecurity program."
Read that against how most consultancies, including this one, actually earn money. We develop procedures. We prepare documents. We make recommendations about cybersecurity programs. Every one of those activities is named. A firm that builds your program cannot then audit it, and a firm that offers to do both is either misreading the rule or hoping you will.
If you use an internal auditor, the independence machinery is structural rather than attitudinal: the highest-ranking auditor must report directly to a member of executive management who does not have direct responsibility for the cybersecurity program, and that same person must conduct the performance evaluation and determine compensation.
The certification nobody has budgeted for
Section 7124 is short and it catches people. Each year you are required to complete an audit, you must also submit a written certification to the Agency, through its website, no later than April 1. It is completed by a member of executive management who is directly responsible for audit compliance, has sufficient knowledge of the audit, and has authority to submit it.
The attestation language is prescribed, and it is signed "Under penalty of perjury under the laws of the state of California". It declares that the information is true and correct "and that the business has not made any attempt to influence the auditor's decisions or assessments regarding the cybersecurity audit."
That last clause is worth reading twice before you plan an engagement where your readiness advisor sits between you and the auditor. The certification is a personal statement by a named executive about the integrity of a process, filed with a regulator. It is not a checkbox.
The honest caveats
We are reading a regulation, not predicting enforcement. Nobody knows yet how the Agency will prioritize audit-rule enforcement, what an inadequate audit report looks like in practice, or how tolerant it will be of first-cycle imperfection. Anyone who tells you otherwise is guessing.
The scope test also depends on facts you may not currently measure. "Processed the personal information of 250,000 or more consumers or households" and "sensitive personal information of 50,000 or more consumers" are counts that most companies cannot produce on demand, and getting them wrong in either direction is expensive. That measurement is often the first real piece of work, ahead of any control remediation.
There is also a separate risk-assessment obligation in the same rulemaking package with its own timetable. It is adjacent, it shares evidence, and it is not the same thing as the audit. Do not let one project quietly absorb the other and then discover in 2028 that neither was finished.
Finally, if your revenue sits near a tier boundary, your deadline can move. The tiers are tested against a specific prior year as of a specific January 1, so a growth year can pull you forward a full twelve months.
Where Top Floor fits
Our CCPA work starts with the scope question, because for a large share of companies the correct and cheapest answer is that section 7120 does not reach you, and proving that carefully is worth more than a program you did not owe. Where it does reach you, the work is a readiness pass against the 17 components, the measurement of the consumer and sensitive-data counts, and the evidence discipline the "no reliance on management assertions" rule demands.
Because the same control set feeds several regimes at once, most of this belongs inside a compliance program that is already producing evidence for other frameworks rather than in a standalone California project. And when the audit itself approaches, our audit and readiness practice prepares the evidence and manages the auditor relationship. It does not become the auditor, and after reading section 7122 you now know why.
How to decide this week
Answer three questions on one page.
First, do you meet section 7120 at all? Check whether you derive 50 percent or more of annual revenue from selling or sharing personal information. If not, check the revenue threshold against the Agency's current adjusted figure, and only then check the 250,000 and 50,000 counts. If the revenue test fails, you are out, regardless of record count.
Second, if you are in, which tier are you in, and therefore which calendar year gets audited? Write the covered period on the plan, not the due date.
Third, who inside the company will sign the certification under penalty of perjury? Name that person now. Their answer to "can I sign this in 2028" is the most reliable early read on how much work the next eighteen months contain.
Frequently asked questions
Does every CCPA business need a cybersecurity audit?
No. The audit rule uses a narrower test than the statute. Section 7120 covers businesses that derive 50 percent or more of annual revenue from selling or sharing personal information, and businesses that meet the CCPA revenue threshold and also processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year. Qualifying as a CCPA business purely by buying, selling or sharing the data of 100,000 or more consumers does not by itself trigger the audit.
When is our first CCPA cybersecurity audit report due?
April 1, 2028 if 2026 annual gross revenue was more than 100 million dollars as of January 1, 2027; April 1, 2029 if 2027 revenue was between 50 million and 100 million dollars as of January 1, 2028; and April 1, 2030 if 2028 revenue was less than 50 million dollars. Each first audit covers a defined twelve-month period ending on the January 1 before the report is due, so the controls have to be operating a year before the deadline.
Can the consultants who built our security program audit it?
No. Section 7122 states the auditor must not participate in activities that may compromise independence, and it names developing procedures, preparing the business's documents, making recommendations about the cybersecurity program, and implementing or maintaining the program. A firm that did any of those for you is disqualified from auditing that work. The auditor may be internal or external, but an internal one needs a reporting line to an executive who does not own the cybersecurity program.
Do we have to file the audit report with the California Privacy Protection Agency?
The regulation requires a written certification of completion to be submitted to the Agency by April 1, signed by a qualifying member of executive management under penalty of perjury and including an attestation that the business made no attempt to influence the auditor. That certification is the filing. The business and the auditor must also retain all documents relevant to each audit for at least five years.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.