Artifact GuideUSRisk and Cyber Audits

US CCPA Risk and Cyber Audits

Risk assessments and cybersecurity audits have separate triggers. A covered processing activity needs a pre-use risk assessment, while only businesses meeting the cybersecurity thresholds need an annual audit.

The regulations took effect January 1, 2026. First audit reports and initial risk-assessment submissions follow phased deadlines beginning in 2028.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start with two separate tests. Section 7150 identifies processing that requires a before it begins. Section 7120 applies annual cybersecurity audits only when a business meets specified revenue and processing thresholds. The same business may meet one test, both tests, or neither.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

Which activities trigger a risk assessment or cybersecurity audit?

A business must conduct a before selling or sharing personal information; processing sensitive personal information; using automated decisionmaking technology (ADMT) for a significant decision; carrying out specified systematic-observation or sensitive-location profiling; or processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, or physical or biological identification or profiling technology. A narrow exception covers sensitive personal information processed solely for listed employment-administration purposes.

A cybersecurity audit is required if the business derived at least 50 percent of its annual revenue from selling or sharing consumers' personal information in the preceding year. It is also required when the business meets the CCPA revenue threshold and, in the preceding year, processed either the personal information of at least 250,000 consumers or households or the sensitive personal information of at least 50,000 consumers.

The first audit report is due April 1, 2028 for a qualifying business with more than $100 million in 2026 annual gross revenue; April 1, 2029 for a qualifying business with 2027 revenue between $50 million and $100 million; or April 1, 2030 for a qualifying business with 2028 revenue below $50 million. The regulations specify a one-year audit period for each phase. After April 1, 2030, a business that meets section 7120 on January 1 based on the preceding year must audit the next 12 months and complete its report by April 1 of the following year.

Processing started before January 1, 2026 and continuing after that date must have its documented by December 31, 2027. Information for assessments conducted in 2026 and 2027 is due to the Agency by April 1, 2028; later submissions are due by April 1 following a year in which assessments were conducted. The routine submission is specified information and an executive attestation, not the full assessment report.

  • Inventory each processing activity and record the exact section 7150 trigger or the reason no trigger applies.
  • Calculate the cybersecurity test from the correct preceding-year revenue and consumer or household counts; do not use the general CCPA business threshold as the audit test by itself.
  • Assign an executive with the knowledge and authority required for the Agency submission, while keeping the auditor's review independent and objective.

What processing requires a CCPA ?

Section 7150 covers sale or sharing; processing sensitive personal information; covered ADMT for significant decisions; specified profiling involving systematic observation or sensitive locations; and personal-information processing used to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, or physical or biological identification or profiling technology. Assess each activity before it begins.

Which businesses must complete an annual CCPA cybersecurity audit?

A business qualifies if it derived at least 50 percent of annual revenue from selling or sharing personal information in the preceding year. It also qualifies when it meets the CCPA revenue threshold and processed, in the preceding year, personal information of at least 250,000 consumers or households or sensitive personal information of at least 50,000 consumers.

When are the first CCPA cybersecurity audit reports due?

The deadline is April 1, 2028 for a qualifying business with more than $100 million in 2026 gross revenue; April 1, 2029 for a qualifying business with 2027 revenue from $50 million through $100 million; and April 1, 2030 for a qualifying business with 2028 revenue below $50 million. Each phase has the one-year audit period stated in section 7121.

When must a CCPA be completed and updated?

Complete it before new covered processing begins. For covered processing started before January 1, 2026 and continuing after that date, document the assessment by December 31, 2027. Review each assessment at least every three years and update it as soon as feasibly possible, no later than 45 calendar days after a material change creates or increases negative impacts or weakens safeguards.

Can an existing audit or privacy assessment satisfy the CCPA?

An existing cybersecurity assessment can be used only if it covers every CCPA audit requirement or is supplemented. A privacy assessment prepared for another law can be used when it contains all section 7152 information or is paired with the missing information. One may cover comparable activities only when the activities are similar and present similar privacy risks.

What does a business submit to the CPPA?

For cybersecurity audits, the routine annual filing is an executive certification of completion, not the full audit report. For risk assessments, section 7157 requires specified business, period, count, category, and executive-attestation information, not the full reports. The Agency or Attorney General may separately demand the underlying assessments, which must be provided within 30 calendar days.

How long must audit and risk-assessment records be kept?

The business and auditor must retain documents relevant to a cybersecurity audit for at least five years after completion. Keep original and updated risk assessments for as long as the processing continues or five years after completion, whichever is later.

Citations
CCPA Regulations effective January 1, 2026

Sections 7120-7121 establish cybersecurity-audit thresholds and phased report dates; sections 7150 and 7155 establish risk-assessment triggers and timing, including the transition for existing processing.

Question 2

What evidence should teams keep for Risk and Cyber Audits under the US CCPA?

For a cybersecurity audit, keep the scope, criteria, evidence examined, testing and sampling, findings, gaps, remediation plan and dates, auditor qualifications, signed auditor statement, and any required breach-notification material. The business and auditor must retain all documents relevant to each audit for at least five years after completion.

For a , preserve the specific processing purpose, data categories and minimum necessary data, sources, retention, affected consumers, technology and participants, benefits, negative impacts, safeguards, residual risks, and the decision-maker's name and position. Keep original and updated versions for as long as the processing continues or five years after completion, whichever is later.

The Agency receives a cybersecurity-audit completion certification, not the full audit report as the routine annual filing. Risk-assessment submissions contain the information listed in section 7157, including counts, categories, and an executive attestation; the Agency or Attorney General may separately demand the assessment reports, which must then be provided within 30 calendar days.

  • Cybersecurity file: threshold calculation, audit period, auditor independence review, report, remediation tracking, executive certification, and submission receipt.
  • Risk file: trigger analysis, report and updates, stakeholder inputs, benefit-risk decision, executive submission, and Agency receipt.
  • Calendar: annual audit cycle, three-year risk-assessment review, material-change review, filing dates, and retention end dates.
Citations
CCPA Regulations effective January 1, 2026

Sections 7122-7124 specify audit independence, report content, five-year retention, and executive certification; sections 7152 and 7155-7157 specify assessment content, retention, submissions, and regulator requests.

Question 3

Which mistakes create risk when handling Risk and Cyber Audits under the US CCPA?

Do not combine the two threshold tests. High-risk privacy processing can require a even when the business does not meet the cybersecurity-audit thresholds. Conversely, a business subject to annual audits must still test each activity separately under section 7150.

The auditor may be internal or external, but must use objective and impartial judgment, be free to report findings without influence, and not rely primarily on management assertions. A must be reviewed at least once every three years and updated as soon as feasibly possible, no later than 45 calendar days after a material change that creates or increases negative impacts or weakens safeguards.

  • Do not treat a security framework assessment as sufficient unless it covers every requirement in the CCPA audit article or is supplemented.
  • Do not submit the audit report as the routine certification or mistake the risk-assessment summary filing for the underlying report.
  • Do not reuse one assessment across activities unless the activities and privacy risks are comparable.
Citations
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Sections 7122-7124 and 7155-7157 establish independence, reuse conditions, update triggers, distinct filings, and regulator access to reports.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.