What should teams do about Cybersecurity Audits under the US CPRA?
The annual cybersecurity-audit duty applies only when section 7120's objective trigger is met. A business qualifies if it derived at least 50% of its preceding-year revenue from selling or sharing consumers' personal information. It also qualifies if it met the CCPA's gross-revenue threshold and, in the preceding year, processed personal information of at least 250,000 consumers or households or sensitive personal information of at least 50,000 consumers. The gross-revenue threshold is $26.625 million for calendar years beginning January 1, 2025, but the Agency adjusts it over time, so record the threshold that applied to the year being tested.
A qualifying business must use a . The first report is phased by revenue: April 1, 2028 for a business above $100 million using 2026 revenue, April 1, 2029 for a business between $50 million and $100 million using 2027 revenue, and April 1, 2030 for a business below $50 million using 2028 revenue. These are first-report deadlines, not a claim that every covered business already owed a completed audit on January 1, 2026.
The audit must assess how the business's cybersecurity program protects personal information and availability, including the applicable section 7123 components. Those components cover authentication, encryption, access control, inventories, secure configuration, vulnerability testing, logging, network defense, training, secure development, vendor oversight, disposal, incident response, business continuity, and backups. The report must describe the information system, audit criteria, evidence examined, findings, gap status, and remediation timeframes. An audit prepared for another purpose, including one using NIST Cybersecurity Framework 2.0, can be reused only if it meets every California requirement on its own or through supplementation.
The auditor may be internal or external but must be a who exercises impartial judgment and does not rely primarily on management assertions. An internal auditor's highest-ranking auditor must report to an executive who does not directly run the cybersecurity program; the auditor also cannot develop, implement, or maintain activities that the same auditor may assess.
Each year an audit is required, an executive with direct responsibility, sufficient knowledge, and submission authority must certify completion to the CPPA by April 1 following the audit year. The business and auditor must retain all audit-relevant documents for at least five years after completion.
- Document which section 7120 trigger applies and the preceding-year revenue and processing counts used.
- Use a and keep the auditor free from management influence.
- Retain the audit report and all relevant documents for at least five years, and submit only the required completion certification to the Agency by the section 7124 deadline.
Direct CPPA regulations text for the annual cybersecurity audit requirement, timing, scope, and certification requirements in sections 7120 through 7124.
Official CPPA FAQ supporting the $26.625 million gross-revenue threshold effective January 1, 2025 and the warning that the threshold is adjusted over time.