California CCPA: Cybersecurity Audit Deadline for Businesses Under 50 Million Dollars in Revenue
The final phase-in wave of California cybersecurity audits falls due. Under section 7121(a)(3) of the California Privacy Protection Agency regulations, a business whose annual gross revenue for 2028 was less than 50 million dollars must complete its first cybersecurity audit report by April 1, 2030, covering January 1, 2029 through January 1, 2030. From this point the regulations settle into an annual cycle: under section 7121(b), a business that meets the section 7120 criteria on 1 January of any year audits the following twelve months and files its report by 1 April of the year after that.
Key Analytics
Impact Analysis
Revenue under 50 million dollars does not exempt a business here. The audit duty attaches to what the business does with personal information, not to its size: deriving half or more of annual revenue from selling or sharing personal information pulls a business in regardless of revenue, and so does meeting the CCPA revenue threshold while processing the personal information of 250,000 or more consumers or the sensitive personal information of 50,000 or more consumers. Data brokers and ad-tech intermediaries are the clearest examples of small companies with large obligations. The phase-in ends here, and what replaces it is a recurring annual audit with a rolling twelve-month period, so the operational question shifts from preparing for a first audit to sustaining evidence continuously.
Recommended Actions
- Check the 50 percent selling or sharing revenue test before assuming the smaller tier means a smaller obligation, because that trigger ignores revenue entirely.
- Count consumers and sensitive-data subjects against the 250,000 and 50,000 thresholds annually, since crossing either in a year pulls the following year into scope.
- Begin evidence generation from January 1, 2029, the start of the audit period for this wave.
- Plan for the recurring cycle in section 7121(b) rather than a one-off project, because after this date the audit repeats every year the criteria are met.
- Reassess scope each 1 January, since the criteria are tested against the preceding calendar year and a business can move in and out of scope.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment against current controls
- ›Readiness assessment
- ›Remediation sprint to date
- ›Attestation or filing preparation
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 60 to 165 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.