Skip to content
    Back to Regulatory Radar
    ImportantDeadlineApril 1, 2029

    California CCPA: Cybersecurity Audit Deadline for the 50 to 100 Million Dollar Revenue Tier

    The second wave of California cybersecurity audits falls due. Under section 7121(a)(2) of the California Privacy Protection Agency regulations, a business whose annual gross revenue for 2027 was between 50 million and 100 million dollars as of January 1, 2028 must complete its first cybersecurity audit report by April 1, 2029, covering the period from January 1, 2028 through January 1, 2029. The written certification of completion required by section 7124 is filed with the Agency by the same date. A third wave follows on April 1, 2030 for businesses whose 2028 annual gross revenue was under 50 million dollars.

    CCPAState PrivacySaaSFinTechHealthcare

    Key Analytics

    April 1, 2029
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    2
    Frameworks Affected

    Impact Analysis

    The audit scope does not scale down with revenue. A mid-market business in this tier is assessed against the same enumerated components as the first wave, including phishing-resistant multi-factor authentication, encryption at rest and in transit, account management, and the remainder of the list, by an auditor who meets the same independence test. What does change is the resourcing: organizations of this size are less likely to have an internal audit function that satisfies the objectivity requirement, and more likely to be discovering the obligation for the first time because the 2028 wave passed without touching them. The audit period starts on January 1, 2028, so the useful lesson from the first wave is that evidence generation has to begin a full fifteen months before the filing date.

    Recommended Actions

    • Test your 2027 annual gross revenue against the 50 to 100 million dollar band as of January 1, 2028, and confirm whether you also meet the section 7120(b) processing triggers.
    • Begin generating and retaining evidence from January 1, 2028, the start of the audit period, rather than treating 2029 as the point at which preparation starts.
    • Budget for an external auditor if you have no internal audit function that can meet the objectivity and independence tests in the regulations.
    • Use the published first-wave experience from April 1, 2028 to calibrate scope and effort before committing to a plan.
    • Watch the third-wave date of April 1, 2030 if your revenue could fall below 50 million dollars for 2028, because the tier is set by revenue in the measurement year, not by size today.

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Modeled estimate
    Moderate45-115 hours
    Key Workstreams
    • Gap assessment against current controls
    • Readiness assessment
    • Remediation sprint to date
    • Attestation or filing preparation

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 45-115 hours
    Start cold under pressureSignificant · 105-280 hours

    Roughly 60 to 165 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events