Skip to content
    Back to Regulatory Radar
    ImportantDeadlineApril 1, 2030

    California CCPA: Cybersecurity Audit Deadline for Businesses Under 50 Million Dollars in Revenue

    The final phase-in wave of California cybersecurity audits falls due. Under section 7121(a)(3) of the California Privacy Protection Agency regulations, a business whose annual gross revenue for 2028 was less than 50 million dollars must complete its first cybersecurity audit report by April 1, 2030, covering January 1, 2029 through January 1, 2030. From this point the regulations settle into an annual cycle: under section 7121(b), a business that meets the section 7120 criteria on 1 January of any year audits the following twelve months and files its report by 1 April of the year after that.

    CCPAState PrivacySaaSFinTechHealthcare

    Key Analytics

    April 1, 2030
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    2
    Frameworks Affected

    Impact Analysis

    Revenue under 50 million dollars does not exempt a business here. The audit duty attaches to what the business does with personal information, not to its size: deriving half or more of annual revenue from selling or sharing personal information pulls a business in regardless of revenue, and so does meeting the CCPA revenue threshold while processing the personal information of 250,000 or more consumers or the sensitive personal information of 50,000 or more consumers. Data brokers and ad-tech intermediaries are the clearest examples of small companies with large obligations. The phase-in ends here, and what replaces it is a recurring annual audit with a rolling twelve-month period, so the operational question shifts from preparing for a first audit to sustaining evidence continuously.

    Recommended Actions

    • Check the 50 percent selling or sharing revenue test before assuming the smaller tier means a smaller obligation, because that trigger ignores revenue entirely.
    • Count consumers and sensitive-data subjects against the 250,000 and 50,000 thresholds annually, since crossing either in a year pulls the following year into scope.
    • Begin evidence generation from January 1, 2029, the start of the audit period for this wave.
    • Plan for the recurring cycle in section 7121(b) rather than a one-off project, because after this date the audit repeats every year the criteria are met.
    • Reassess scope each 1 January, since the criteria are tested against the preceding calendar year and a business can move in and out of scope.

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Modeled estimate
    Moderate45-115 hours
    Key Workstreams
    • Gap assessment against current controls
    • Readiness assessment
    • Remediation sprint to date
    • Attestation or filing preparation

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 45-115 hours
    Start cold under pressureSignificant · 105-280 hours

    Roughly 60 to 165 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events