Artifact GuideUSCybersecurity Audits

US CPRA Cybersecurity Audits

The annual audit rule applies only to businesses that meet a section 7120 revenue-and-processing trigger; first reports are phased from April 1, 2028 through April 1, 2030.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is an annual, evidence-based review required by Article 9 of the California Consumer Privacy Act (CCPA) regulations, as amended to implement the California Privacy Rights Act (CPRA), only when a business meets a section 7120 threshold. This page explains the threshold calculation, phased first-report dates, audit scope, auditor independence, evidence retention, and the completion certification submitted to the California Privacy Protection Agency.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about Cybersecurity Audits under the US CPRA?

The annual cybersecurity-audit duty applies only when section 7120's objective trigger is met. A business qualifies if it derived at least 50% of its preceding-year revenue from selling or sharing consumers' personal information. It also qualifies if it met the CCPA's gross-revenue threshold and, in the preceding year, processed personal information of at least 250,000 consumers or households or sensitive personal information of at least 50,000 consumers. The gross-revenue threshold is $26.625 million for calendar years beginning January 1, 2025, but the Agency adjusts it over time, so record the threshold that applied to the year being tested.

A qualifying business must use a . The first report is phased by revenue: April 1, 2028 for a business above $100 million using 2026 revenue, April 1, 2029 for a business between $50 million and $100 million using 2027 revenue, and April 1, 2030 for a business below $50 million using 2028 revenue. These are first-report deadlines, not a claim that every covered business already owed a completed audit on January 1, 2026.

The audit must assess how the business's cybersecurity program protects personal information and availability, including the applicable section 7123 components. Those components cover authentication, encryption, access control, inventories, secure configuration, vulnerability testing, logging, network defense, training, secure development, vendor oversight, disposal, incident response, business continuity, and backups. The report must describe the information system, audit criteria, evidence examined, findings, gap status, and remediation timeframes. An audit prepared for another purpose, including one using NIST Cybersecurity Framework 2.0, can be reused only if it meets every California requirement on its own or through supplementation.

The auditor may be internal or external but must be a who exercises impartial judgment and does not rely primarily on management assertions. An internal auditor's highest-ranking auditor must report to an executive who does not directly run the cybersecurity program; the auditor also cannot develop, implement, or maintain activities that the same auditor may assess.

Each year an audit is required, an executive with direct responsibility, sufficient knowledge, and submission authority must certify completion to the CPPA by April 1 following the audit year. The business and auditor must retain all audit-relevant documents for at least five years after completion.

  • Document which section 7120 trigger applies and the preceding-year revenue and processing counts used.
  • Use a and keep the auditor free from management influence.
  • Retain the audit report and all relevant documents for at least five years, and submit only the required completion certification to the Agency by the section 7124 deadline.
Citations
Question 2

What evidence should teams keep for Cybersecurity Audits under the US CPRA?

Keep the section 7120 threshold calculation, auditor qualifications and independence record, audit scope and criteria, evidence reviewed, findings and remediation plan, final report, governing-body or executive review, annual certification, and submission receipt. Retain the audit-relevant documents for at least five years after completion and record which phased first-report deadline applies.

  • Threshold file: the tested legal entity, applicable $26.625 million or later adjusted revenue threshold, preceding-year revenue source, consumer and household counts, sensitive-personal-information count, and sale-or-sharing revenue percentage.
  • Audit file: system boundary, policies and controls assessed, accepted audit standard, samples, tests, interviews, findings, remediation owners and dates, prior-report corrections, and breach or regulator-notification material required by section 7123.
  • Governance file: auditor qualifications and conflict review, internal-auditor reporting line if used, executive receipt of the report, five-year retention dates, signed annual certification, and Agency submission receipt.
Citations
Question 3

Which mistakes create risk when handling Cybersecurity Audits under the US CPRA?

Common failures include using a stale gross-revenue threshold, mixing the audit trigger with the separate risk-assessment trigger, assuming the regulations required every business to finish an audit on January 1, 2026, relying mainly on management attestations, omitting a remediation plan, or sending the audit report when section 7124 calls for a completion certification.

  • Using the separate risk-assessment trigger as the cybersecurity-audit trigger.
  • Treating an auditor as independent while management controls findings or the auditor relies mainly on management assertions.
  • Submitting a certification without retaining the report and supporting audit documents for five years.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Official CPPA FAQ supporting the $26.625 million gross-revenue threshold effective January 1, 2025 and the warning that the threshold is adjusted over time.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.