Determine separately whether a processing activity triggers a pre-use privacy risk assessment, whether the business triggers an annual independent cybersecurity audit, and whether significant-decision ADMT creates notice, access, appeal, or opt-out duties.
These are binding regulations effective January 1, 2026, with different thresholds and staged dates. A business can trigger one duty without triggering the others.
Apply three separate tests. A attaches to each listed processing activity before it starts. A attaches to a business that meets the regulation's revenue-and-volume or sale-or-sharing-revenue test. Article 11 duties attach to specified uses of automated decisionmaking technology (). One activity or business may trigger any combination of the three, and each regime has its own evidence and compliance dates.
1
Section 1
What should teams decide about Risk and Cyber Audits under the US CCPA?
For a covered business, risk assessments attach to listed processing activities without a separate company-size threshold. Complete one before selling or sharing personal information, processing sensitive personal information outside the narrow listed employment-administration purposes, using for a significant decision, carrying out specified extensive profiling, or processing personal information to train specified ADMT or identity technologies.
Cybersecurity audits use a different test. They apply when the business derived 50 percent or more of its annual revenue from selling or sharing consumers' personal information in the preceding calendar year. They also apply when the business met the CCPA gross-revenue threshold and processed at least 250,000 consumers' or households' personal information, or at least 50,000 consumers' sensitive personal information, in the preceding calendar year.
Inventory each sale, sharing flow, sensitive-PI use, significant-decision use, profiling activity, and covered training activity before launch.
Calculate cybersecurity-audit eligibility annually using the preceding year's revenue and processing volumes; do not reuse the general CCPA applicability test as the audit test.
Record whether the activity also triggers Article 11 notices and consumer rights.
Treat the completed 2025 rulemaking as binding regulation, not as the earlier draft or consultation material still present in historical source files.
Who should own Risk and Cyber Audits, and what evidence should prove the decision?
Privacy should own the processing inventory and assessment method; security should own cybersecurity-program evidence; product and HR owners should identify significant-decision ; and legal should review scope and narrow exceptions. The cybersecurity auditor may be internal or external, but must be qualified, objective, and independent from the activities being audited.
Keep each risk-assessment report, specific purpose, minimum necessary data, sources, processing method, retention, benefits, negative impacts, safeguards, contributors, approval, update history, and CPPA submission record. For cybersecurity audits, retain the scope, criteria, evidence, tests, findings, remediation status, auditor statement, executive review, certification, and all relevant documents for at least five years.
Assign a processing owner, privacy reviewer, security owner, product owner, and independent auditor where the respective duty applies.
Obtain the facts needed from service providers and contractors; the 2026 regulations expressly require their cooperation with cybersecurity audits and risk assessments.
Review risk assessments at least every three years and within 45 days after a material change that creates or increases impacts or weakens safeguards.
Preserve the evidence supporting threshold calculations and exclusions, not only the final conclusion.
Which edge cases should teams check before relying on a Risk and Cyber Audits decision?
Do not collapse the three regimes into a single 'high-risk processing' label. A sale or sharing flow triggers a for a covered business, but the annual cybersecurity-audit test still depends on the audit thresholds. Conversely, a business may meet an audit threshold even when a particular new use does not involve .
Employment administration has a narrow sensitive-personal-information risk-assessment exception for compensation, employment authorization, benefits, legally required accommodation, and wage reporting when the data is processed solely and specifically for those purposes. It is not a general employee-data exception. Significant-decision in use before January 1, 2027 must meet Article 11 by that date. Article 11 generally requires a pre-use notice and access method; it requires an opt-out method unless an exception applies, including a qualifying human appeal process.
Check the precise processing trigger and any narrow exception before reusing an assessment across activities. One assessment may cover a comparable set only when the activities are similar and present similar privacy risks.
Do not cite the March 2024 drafts as the current rule; use the final regulations effective January 1, 2026.
Reopen the assessment when purpose, data category, retention, affected population, model, recipient, or safeguards materially change.
Separate CPPA's authority to audit CCPA compliance generally from a business's Article 9 duty to complete its own annual .
How should teams operationalize Risk and Cyber Audits with proportionate controls?
For covered processing started before January 1, 2026 and continuing afterward, complete and document the required by December 31, 2027. Submit the prescribed summary information for assessments conducted in 2026 and 2027 by April 1, 2028. For later years, submit by April 1 following a year in which the business conducted or updated an assessment. The Agency or Attorney General may separately demand full reports, which must be provided within 30 calendar days.
First cybersecurity-audit reports are phased by revenue: April 1, 2028 for a qualifying business with more than $100 million in 2026 revenue; April 1, 2029 for a qualifying business with $50 million to $100 million in 2027 revenue; and April 1, 2030 for a qualifying business with less than $50 million in 2028 revenue. Each first audit covers the stated one-year period in section 7121; later qualifying audits follow the annual cycle.
Create separate registers for risk-assessment activities, cybersecurity-audit eligibility, and significant-decision .
Gate new covered processing on a completed and required pre-use notice or control.
Link each assessment and audit finding to the responsible control, remediation ticket, vendor evidence, and approval record.
Reuse an assessment, audit, or certification prepared for another law or framework only after documenting that it meets every CCPA requirement or has been supplemented to fill each gap.