Skip to content
    Back to Regulatory Radar
    CriticalDeadlineApril 1, 2028

    California CCPA: First Cybersecurity Audit Reports, Certifications, and Risk Assessment Filings Due

    Three California Privacy Protection Agency obligations converge on April 1, 2028. Under section 7121(a)(1), a business whose annual gross revenue for 2026 exceeded 100 million dollars as of January 1, 2027 must complete its first cybersecurity audit report by this date, covering January 1, 2027 through January 1, 2028. Under section 7124, a member of executive management directly responsible for audit compliance must submit a written certification of completion to the Agency through its website by the same date. Under section 7157(a)(1), a business that conducted risk assessments in 2026 or 2027 must submit the section 7157(b) risk assessment information by the same date: its name and point of contact, the period covered, the number of assessments conducted or updated in total and per section 7150(b) activity, which Civil Code section 1798.140 categories of personal information were involved, and an executive attestation under penalty of perjury. The assessment reports themselves are not filed on this date; under section 7157(e) the Agency or the Attorney General may require them at any time, and a business then has 30 calendar days to produce them.

    CCPAState PrivacySaaSFinTechHealthcare

    Key Analytics

    April 1, 2028
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    2
    Frameworks Affected

    Impact Analysis

    This is the first California privacy deadline that asks for an independent audit rather than a self-declaration, and the audit period has already opened by the time most programs start planning: it runs from January 1, 2027, so evidence has to exist contemporaneously rather than be assembled in early 2028. The audit scope named in the regulations is a recognizable security program review covering authentication including phishing-resistant multi-factor authentication, encryption of personal information at rest and in transit, account management and access control, and the rest of the enumerated components, assessed by a qualified, objective, and independent auditor applying professional auditing standards. The certification requirement adds named executive accountability, which changes who needs to be briefed and when. A business that already maintains SOC 2 or ISO 27001 evidence is well placed on the control side but should not assume either report satisfies the regulation, because the scope, the independence test, and the filing are defined by the California rules rather than by the attestation standard.

    Recommended Actions

    • Determine now whether you meet the section 7120(b) significant-risk trigger for the relevant year, since the audit duty follows the threshold rather than a one-time determination.
    • Confirm the audit period start of January 1, 2027 and make sure evidence for the enumerated components is being generated and retained from that date rather than reconstructed later.
    • Select an auditor who meets the qualification, objectivity, and independence tests in the regulations, and settle whether internal audit can meet them in your reporting structure.
    • Map your existing SOC 2 or ISO 27001 evidence against the component list in the regulations and close the gaps, rather than assuming an existing report transfers.
    • Identify the executive who will sign the certification of completion and brief them well before the filing, because the regulations require direct responsibility and sufficient knowledge, not a delegated signature.
    • Sequence the section 7157(b) risk assessment submission alongside the audit filing, since it falls on the same date, and note that it is a metadata filing with an attestation rather than a transmittal of the assessments; keep the reports themselves ready to produce within the 30 days section 7157(e) allows.

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Modeled estimate
    Significant65-175 hours
    Key Workstreams
    • Gap assessment against current controls
    • Readiness assessment
    • Remediation sprint to date
    • Attestation or filing preparation

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 65-175 hours
    Start cold under pressureSignificant · 130-450 hours

    Roughly 65 to 275 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events