Which activities trigger a risk assessment or cybersecurity audit?
A business must conduct a before selling or sharing personal information; processing sensitive personal information; using automated decisionmaking technology (ADMT) for a significant decision; carrying out specified systematic-observation or sensitive-location profiling; or processing personal information to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, or physical or biological identification or profiling technology. A narrow exception covers sensitive personal information processed solely for listed employment-administration purposes.
A cybersecurity audit is required if the business derived at least 50 percent of its annual revenue from selling or sharing consumers' personal information in the preceding year. It is also required when the business meets the CCPA revenue threshold and, in the preceding year, processed either the personal information of at least 250,000 consumers or households or the sensitive personal information of at least 50,000 consumers.
The first audit report is due April 1, 2028 for a qualifying business with more than $100 million in 2026 annual gross revenue; April 1, 2029 for a qualifying business with 2027 revenue between $50 million and $100 million; or April 1, 2030 for a qualifying business with 2028 revenue below $50 million. The regulations specify a one-year audit period for each phase. After April 1, 2030, a business that meets section 7120 on January 1 based on the preceding year must audit the next 12 months and complete its report by April 1 of the following year.
Processing started before January 1, 2026 and continuing after that date must have its documented by December 31, 2027. Information for assessments conducted in 2026 and 2027 is due to the Agency by April 1, 2028; later submissions are due by April 1 following a year in which assessments were conducted. The routine submission is specified information and an executive attestation, not the full assessment report.
- Inventory each processing activity and record the exact section 7150 trigger or the reason no trigger applies.
- Calculate the cybersecurity test from the correct preceding-year revenue and consumer or household counts; do not use the general CCPA business threshold as the audit test by itself.
- Assign an executive with the knowledge and authority required for the Agency submission, while keeping the auditor's review independent and objective.
What processing requires a CCPA ?
Section 7150 covers sale or sharing; processing sensitive personal information; covered ADMT for significant decisions; specified profiling involving systematic observation or sensitive locations; and personal-information processing used to train specified ADMT, facial-recognition, emotion-recognition, identity-verification, or physical or biological identification or profiling technology. Assess each activity before it begins.
Which businesses must complete an annual CCPA cybersecurity audit?
A business qualifies if it derived at least 50 percent of annual revenue from selling or sharing personal information in the preceding year. It also qualifies when it meets the CCPA revenue threshold and processed, in the preceding year, personal information of at least 250,000 consumers or households or sensitive personal information of at least 50,000 consumers.
When are the first CCPA cybersecurity audit reports due?
The deadline is April 1, 2028 for a qualifying business with more than $100 million in 2026 gross revenue; April 1, 2029 for a qualifying business with 2027 revenue from $50 million through $100 million; and April 1, 2030 for a qualifying business with 2028 revenue below $50 million. Each phase has the one-year audit period stated in section 7121.
When must a CCPA be completed and updated?
Complete it before new covered processing begins. For covered processing started before January 1, 2026 and continuing after that date, document the assessment by December 31, 2027. Review each assessment at least every three years and update it as soon as feasibly possible, no later than 45 calendar days after a material change creates or increases negative impacts or weakens safeguards.
Can an existing audit or privacy assessment satisfy the CCPA?
An existing cybersecurity assessment can be used only if it covers every CCPA audit requirement or is supplemented. A privacy assessment prepared for another law can be used when it contains all section 7152 information or is paired with the missing information. One may cover comparable activities only when the activities are similar and present similar privacy risks.
What does a business submit to the CPPA?
For cybersecurity audits, the routine annual filing is an executive certification of completion, not the full audit report. For risk assessments, section 7157 requires specified business, period, count, category, and executive-attestation information, not the full reports. The Agency or Attorney General may separately demand the underlying assessments, which must be provided within 30 calendar days.
How long must audit and risk-assessment records be kept?
The business and auditor must retain documents relevant to a cybersecurity audit for at least five years after completion. Keep original and updated risk assessments for as long as the processing continues or five years after completion, whichever is later.
Sections 7120-7121 establish cybersecurity-audit thresholds and phased report dates; sections 7150 and 7155 establish risk-assessment triggers and timing, including the transition for existing processing.
Official status page confirming Office of Administrative Law approval, completion of rulemaking, and the January 1, 2026 effective date.