Document the section 7120 calculation for each CCPA business before planning the audit. Preserve the preceding calendar year, annual gross revenue, percentage derived from sale or sharing, consumer-or-household count, sensitive-personal-information consumer count, calculation method, source systems, and evidence owner. Meeting the general CCPA 100,000-consumer threshold alone does not trigger this audit; section 7120 uses its own 250,000 and 50,000 processing-volume tests unless the 50-percent revenue branch applies.
If the business is in scope, appoint an auditor with cybersecurity and audit knowledge. The auditor may be internal or external but must exercise objective and impartial judgment, remain free from business influence, and avoid designing, documenting, implementing, or maintaining activities the auditor may assess. The highest-ranking internal auditor must report to an executive who does not directly own the cybersecurity program.
The audit must assess the cybersecurity program's protection against unauthorized access, destruction, use, modification, disclosure, and loss of availability. Findings must rely primarily on specific evidence such as documents, samples, tests, and interviews, not management assertions. Give the report to the executive directly responsible for the cybersecurity program, obtain the separate executive certification, submit it to the Agency, and retain relevant audit documents for at least five years.