Artifact GuideUSRisk Assessments and Cybersecurity Audits
US CPRA Risk Assessments and Cybersecurity Audits
Run the processing-level risk-assessment test and the entity-level cybersecurity-audit test separately; one result never establishes the other.
This guide maps the final CPPA regulations effective January 1, 2026 to their different scope facts, owners, approvals, reports, phase-in dates, submissions, and retained evidence.
A is an annual, independent assessment for a CCPA business that meets a significant-security-risk branch. A risk assessment is a separate, business-approved analysis required before a processing activity starts. The final CPPA regulations became effective January 1, 2026; different transition dates apply, and a processing activity can trigger one duty without triggering the other.
1
Section 1
How should a Risk Assessments and Cybersecurity Audits workflow run under the US CPRA?
Run two independent tests. attaches to six activity categories: sale or sharing; sensitive-information processing, subject to a narrow employment-purpose exception; ADMT for a significant decision; specified applicant, student, employee, or independent-contractor profiling; specified inference from presence in a sensitive location; and processing personal information intended to train ADMT for a significant decision or to train facial-recognition, emotion-recognition, or other technology that verifies identity or conducts physical or biological identification or profiling. Complete the report before new processing; assess covered processing begun before January 1, 2026 by December 31, 2027.
attaches at entity level when the preceding year's facts show either at least 50 percent of revenue from selling or sharing personal information, or annual gross revenue above $26,625,000 effective January 1, 2025 plus processing of at least 250,000 consumers or households or sensitive information of at least 50,000 consumers. First reports are due April 1, 2028, 2029, or 2030 under the revenue-tier phase-in.
A DPIA prepared for another law can satisfy the risk-assessment duty only when it contains every California field or is paired with the missing information. A security review does not become the required audit unless a qualified, objective, independent auditor uses accepted procedures, bases findings primarily on specific evidence, and produces the section 7123 report.
For each processing activity, record every branch, exception, source evidence, assessment owner, launch hold, approval, three-year review, 45-day material-change update, and April 1 summary-submission tracking.
For each CCPA business, calculate scope from the preceding year's annual gross revenue, sale-or-sharing revenue percentage, personal-information consumer-or-household count, and sensitive-information consumer count.
Keep assessment approval separate from audit independence: the business approves its risk assessment, while the cybersecurity auditor must exercise objective and impartial judgment.
Require service providers and contractors to supply relevant facts and audit evidence that are in their possession, custody, or control.
Retain original and updated risk assessments while processing continues or for five years after completion, whichever is later; retain all documents relevant to each for at least five years after that audit.
What fields should the Risk Assessments and Cybersecurity Audits template capture?
Privacy and audit owners should maintain separate linked records. The risk-assessment record follows one processing activity or a comparable set with similar risks; the cybersecurity-audit record follows one covered business and audit period.
How should teams review and improve the Risk Assessments and Cybersecurity Audits workflow?
Review risk assessments at least once every three years, not annually, and update them within 45 calendar days after a material change. Recalculate audit scope every year and run successive annual audits without gaps once required. Track submissions separately: section 7157 risk-assessment summaries for 2026 and 2027 are due April 1, 2028, while section 7124 audit certifications follow the revenue-tier phase-in and then recur by April 1 after each required audit year.
Reopen the risk record when a change creates or increases a negative impact or weakens a safeguard; preserve the material-change date and 45-day deadline.
Recalculate the audit record from source-system counts and finance evidence each January; do not carry last year's result forward without testing it.
Keep assessment approval separate from auditor independence, report delivery, executive certification, and Agency-submission receipts.
Prepare full risk-assessment reports for a possible Agency or Attorney General demand within 30 calendar days, even though routine section 7157 submission is summary information.