Artifact GuideUSCyber Audit Readiness Workflow

US CPRA Cyber Audit Readiness Workflow

Use the section 7120 entity-level calculation to decide whether an annual CPPA cybersecurity audit is required, then prepare the independent auditor, control evidence, report, executive certification, and submission.

The final regulations became effective January 1, 2026, but first audit periods and report deadlines phase in by revenue tier from 2027 through 2030.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is mandatory when a CCPA business meets either section 7120 branch in the preceding calendar year: it derived at least 50 percent of annual revenue from selling or sharing consumers' personal information, or it exceeded the CCPA's $26,625,000 annual-gross-revenue threshold effective January 1, 2025 and processed personal information of at least 250,000 consumers or households or sensitive personal information of at least 50,000 consumers. The first audit report is due April 1, 2028, 2029, or 2030 under the regulation's revenue-tier phase-in.

Section 1

How should a Cyber Audit Readiness Workflow run under the US CPRA?

Document the section 7120 calculation for each CCPA business before planning the audit. Preserve the preceding calendar year, annual gross revenue, percentage derived from sale or sharing, consumer-or-household count, sensitive-personal-information consumer count, calculation method, source systems, and evidence owner. Meeting the general CCPA 100,000-consumer threshold alone does not trigger this audit; section 7120 uses its own 250,000 and 50,000 processing-volume tests unless the 50-percent revenue branch applies.

If the business is in scope, appoint an auditor with cybersecurity and audit knowledge. The auditor may be internal or external but must exercise objective and impartial judgment, remain free from business influence, and avoid designing, documenting, implementing, or maintaining activities the auditor may assess. The highest-ranking internal auditor must report to an executive who does not directly own the cybersecurity program.

The audit must assess the cybersecurity program's protection against unauthorized access, destruction, use, modification, disclosure, and loss of availability. Findings must rely primarily on specific evidence such as documents, samples, tests, and interviews, not management assertions. Give the report to the executive directly responsible for the cybersecurity program, obtain the separate executive certification, submit it to the Agency, and retain relevant audit documents for at least five years.

  • Fix the first report and audit period from the regulation: over $100 million revenue for 2026, report due April 1, 2028 for January 1, 2027 through January 1, 2028; $50 million to $100 million for 2027, due April 1, 2029; below $50 million for 2028, due April 1, 2030.
  • Map the applicable section 7123 areas to tests and evidence: authentication, encryption, access, inventories, secure configuration, vulnerability testing, logs, network defenses, malware protection, segmentation, ports and protocols, awareness and training, secure development, vendor oversight, retention and disposal, incident response, business continuity, and governance.
  • Give the auditor all requested relevant information in the business's possession, custody, or control; make good-faith efforts to disclose relevant facts and record any service-provider or contractor evidence included in that response.
  • Track the audit criteria and period, applicable and inapplicable control areas, evidence sampled, findings, remediation plan and timeline, prior-audit status, auditor relationship and independence safeguards, report delivery, executive certification, Agency receipt, retention end, and next audit period.
Section 2

What fields should the Cyber Audit Readiness Workflow template capture?

The security or audit-readiness owner should maintain the record, while the independent auditor controls audit procedures and findings. Connect the threshold decision to the audit period, auditor independence, tested control areas, findings, remediation, certification, submission, and retention.

  • Legal entity, preceding-year revenue, sale-or-sharing revenue percentage, processing counts, threshold conclusion, calculation evidence, and reviewer.
  • Audit period, first certification deadline, auditor identity and qualifications, independence disclosures, and conflict safeguards.
  • Control objective, system owner, test procedure, sample or evidence, result, finding severity, remediation owner, and due date.
  • Final report, executive certification, Agency submission receipt, retained workpapers, and the next annual audit period.
Section 3

How should teams review and improve the Cyber Audit Readiness Workflow?

As a readiness practice, review evidence at least annually and after an acquisition, major system or vendor change, security incident, or new sensitive-data use. The legal audit remains annual once required. A control inventory is not an audit: confirm that the independent auditor assessed the program, based findings primarily on specific evidence, and recorded the status of prior findings and remediation.

  • Recalculate section 7120 from the preceding year's facts every January and preserve the source data, methodology, reviewer, and resulting audit period.
  • Test independence before appointment and whenever reporting lines, compensation, consulting work, or cybersecurity ownership changes.
  • Reconcile every applicable section 7123 area to evidence and a test result; explain inapplicability rather than leaving a blank field.
  • Submit the executive certification by April 1 following each required audit year and preserve the Agency receipt with the report and five-year evidence set.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA regulations source for the baseline CCPA operational rules that cyber-audit readiness should connect to notices, requests, and governance evidence.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed them with the Secretary of State."
cppa.ca.gov
Referenced sections
  • CPPA FAQ context for the CPRA amendments to the CCPA and the broader business-obligation framework that audit readiness supports.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses."
nist.gov
Referenced sections
  • NIST privacy-governance framework used as non-legal support for organizing audit evidence, privacy risk controls, and review ownership.
"A Tool for Improving Privacy through Enterprise Risk Management"
cppa.ca.gov
Referenced sections
  • Confirms the $26,625,000 annual-gross-revenue amount used by the section 7120 revenue-plus-volume branch, effective January 1, 2025.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.