Artifact GuideUSRisk and Cyber Audits

US CCPA Risk and Cyber Audits

Determine separately whether a processing activity triggers a pre-use privacy risk assessment, whether the business triggers an annual independent cybersecurity audit, and whether significant-decision ADMT creates notice, access, appeal, or opt-out duties.

These are binding regulations effective January 1, 2026, with different thresholds and staged dates. A business can trigger one duty without triggering the others.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Apply three separate tests. A attaches to each listed processing activity before it starts. A attaches to a business that meets the regulation's revenue-and-volume or sale-or-sharing-revenue test. Article 11 duties attach to specified uses of automated decisionmaking technology (). One activity or business may trigger any combination of the three, and each regime has its own evidence and compliance dates.

Section 1

What should teams decide about Risk and Cyber Audits under the US CCPA?

For a covered business, risk assessments attach to listed processing activities without a separate company-size threshold. Complete one before selling or sharing personal information, processing sensitive personal information outside the narrow listed employment-administration purposes, using for a significant decision, carrying out specified extensive profiling, or processing personal information to train specified ADMT or identity technologies.

Cybersecurity audits use a different test. They apply when the business derived 50 percent or more of its annual revenue from selling or sharing consumers' personal information in the preceding calendar year. They also apply when the business met the CCPA gross-revenue threshold and processed at least 250,000 consumers' or households' personal information, or at least 50,000 consumers' sensitive personal information, in the preceding calendar year.

  • Inventory each sale, sharing flow, sensitive-PI use, significant-decision use, profiling activity, and covered training activity before launch.
  • Calculate cybersecurity-audit eligibility annually using the preceding year's revenue and processing volumes; do not reuse the general CCPA applicability test as the audit test.
  • Record whether the activity also triggers Article 11 notices and consumer rights.
  • Treat the completed 2025 rulemaking as binding regulation, not as the earlier draft or consultation material still present in historical source files.
Section 2

Who should own Risk and Cyber Audits, and what evidence should prove the decision?

Privacy should own the processing inventory and assessment method; security should own cybersecurity-program evidence; product and HR owners should identify significant-decision ; and legal should review scope and narrow exceptions. The cybersecurity auditor may be internal or external, but must be qualified, objective, and independent from the activities being audited.

Keep each risk-assessment report, specific purpose, minimum necessary data, sources, processing method, retention, benefits, negative impacts, safeguards, contributors, approval, update history, and CPPA submission record. For cybersecurity audits, retain the scope, criteria, evidence, tests, findings, remediation status, auditor statement, executive review, certification, and all relevant documents for at least five years.

  • Assign a processing owner, privacy reviewer, security owner, product owner, and independent auditor where the respective duty applies.
  • Obtain the facts needed from service providers and contractors; the 2026 regulations expressly require their cooperation with cybersecurity audits and risk assessments.
  • Review risk assessments at least every three years and within 45 days after a material change that creates or increases impacts or weakens safeguards.
  • Preserve the evidence supporting threshold calculations and exclusions, not only the final conclusion.
Section 3

Which edge cases should teams check before relying on a Risk and Cyber Audits decision?

Do not collapse the three regimes into a single 'high-risk processing' label. A sale or sharing flow triggers a for a covered business, but the annual cybersecurity-audit test still depends on the audit thresholds. Conversely, a business may meet an audit threshold even when a particular new use does not involve .

Employment administration has a narrow sensitive-personal-information risk-assessment exception for compensation, employment authorization, benefits, legally required accommodation, and wage reporting when the data is processed solely and specifically for those purposes. It is not a general employee-data exception. Significant-decision in use before January 1, 2027 must meet Article 11 by that date. Article 11 generally requires a pre-use notice and access method; it requires an opt-out method unless an exception applies, including a qualifying human appeal process.

  • Check the precise processing trigger and any narrow exception before reusing an assessment across activities. One assessment may cover a comparable set only when the activities are similar and present similar privacy risks.
  • Do not cite the March 2024 drafts as the current rule; use the final regulations effective January 1, 2026.
  • Reopen the assessment when purpose, data category, retention, affected population, model, recipient, or safeguards materially change.
  • Separate CPPA's authority to audit CCPA compliance generally from a business's Article 9 duty to complete its own annual .
Section 4

How should teams operationalize Risk and Cyber Audits with proportionate controls?

For covered processing started before January 1, 2026 and continuing afterward, complete and document the required by December 31, 2027. Submit the prescribed summary information for assessments conducted in 2026 and 2027 by April 1, 2028. For later years, submit by April 1 following a year in which the business conducted or updated an assessment. The Agency or Attorney General may separately demand full reports, which must be provided within 30 calendar days.

First cybersecurity-audit reports are phased by revenue: April 1, 2028 for a qualifying business with more than $100 million in 2026 revenue; April 1, 2029 for a qualifying business with $50 million to $100 million in 2027 revenue; and April 1, 2030 for a qualifying business with less than $50 million in 2028 revenue. Each first audit covers the stated one-year period in section 7121; later qualifying audits follow the annual cycle.

  • Create separate registers for risk-assessment activities, cybersecurity-audit eligibility, and significant-decision .
  • Gate new covered processing on a completed and required pre-use notice or control.
  • Schedule assessment reviews, CPPA submissions, audit periods, executive sign-off, certifications, and document-retention dates.
  • Link each assessment and audit finding to the responsible control, remediation ticket, vendor evidence, and approval record.
  • Reuse an assessment, audit, or certification prepared for another law or framework only after documenting that it meets every CCPA requirement or has been supplemented to fill each gap.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Sections 7121, 7124, 7155, and 7157 establish the phased audit reports, annual certifications, transition assessment, assessment submissions, and regulator-request deadline.
cppa.ca.gov
Referenced sections
  • CPPA index confirming that the 2025 rulemaking is complete and the current regulation text is effective.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.