Artifact GuideUSRisk Assessments and Cybersecurity Audits

US CPRA Risk Assessments and Cybersecurity Audits

Run the processing-level risk-assessment test and the entity-level cybersecurity-audit test separately; one result never establishes the other.

This guide maps the final CPPA regulations effective January 1, 2026 to their different scope facts, owners, approvals, reports, phase-in dates, submissions, and retained evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is an annual, independent assessment for a CCPA business that meets a significant-security-risk branch. A risk assessment is a separate, business-approved analysis required before a processing activity starts. The final CPPA regulations became effective January 1, 2026; different transition dates apply, and a processing activity can trigger one duty without triggering the other.

Section 1

How should a Risk Assessments and Cybersecurity Audits workflow run under the US CPRA?

Run two independent tests. attaches to six activity categories: sale or sharing; sensitive-information processing, subject to a narrow employment-purpose exception; ADMT for a significant decision; specified applicant, student, employee, or independent-contractor profiling; specified inference from presence in a sensitive location; and processing personal information intended to train ADMT for a significant decision or to train facial-recognition, emotion-recognition, or other technology that verifies identity or conducts physical or biological identification or profiling. Complete the report before new processing; assess covered processing begun before January 1, 2026 by December 31, 2027.

attaches at entity level when the preceding year's facts show either at least 50 percent of revenue from selling or sharing personal information, or annual gross revenue above $26,625,000 effective January 1, 2025 plus processing of at least 250,000 consumers or households or sensitive information of at least 50,000 consumers. First reports are due April 1, 2028, 2029, or 2030 under the revenue-tier phase-in.

A DPIA prepared for another law can satisfy the risk-assessment duty only when it contains every California field or is paired with the missing information. A security review does not become the required audit unless a qualified, objective, independent auditor uses accepted procedures, bases findings primarily on specific evidence, and produces the section 7123 report.

  • For each processing activity, record every branch, exception, source evidence, assessment owner, launch hold, approval, three-year review, 45-day material-change update, and April 1 summary-submission tracking.
  • For each CCPA business, calculate scope from the preceding year's annual gross revenue, sale-or-sharing revenue percentage, personal-information consumer-or-household count, and sensitive-information consumer count.
  • Keep assessment approval separate from audit independence: the business approves its risk assessment, while the cybersecurity auditor must exercise objective and impartial judgment.
  • Require service providers and contractors to supply relevant facts and audit evidence that are in their possession, custody, or control.
  • Retain original and updated risk assessments while processing continues or for five years after completion, whichever is later; retain all documents relevant to each for at least five years after that audit.
Section 2

What fields should the Risk Assessments and Cybersecurity Audits template capture?

Privacy and audit owners should maintain separate linked records. The risk-assessment record follows one processing activity or a comparable set with similar risks; the cybersecurity-audit record follows one covered business and audit period.

  • Risk assessment: activity, trigger, purpose, data, operations, benefits, negative impacts, safeguards, balance, contributors, approver, and review dates.
  • Audit scope: entity, threshold calculation, audit period, systems, personal information, cybersecurity program, auditor, qualifications, and independence safeguards.
  • Audit testing: control area, procedure, evidence, result, gap, remediation owner, timetable, and residual risk.
  • Governance: executive certification, Agency submission receipt, assessment summary, retained evidence, exceptions, and next due date.
Section 3

How should teams review and improve the Risk Assessments and Cybersecurity Audits workflow?

Review risk assessments at least once every three years, not annually, and update them within 45 calendar days after a material change. Recalculate audit scope every year and run successive annual audits without gaps once required. Track submissions separately: section 7157 risk-assessment summaries for 2026 and 2027 are due April 1, 2028, while section 7124 audit certifications follow the revenue-tier phase-in and then recur by April 1 after each required audit year.

  • Reopen the risk record when a change creates or increases a negative impact or weakens a safeguard; preserve the material-change date and 45-day deadline.
  • Recalculate the audit record from source-system counts and finance evidence each January; do not carry last year's result forward without testing it.
  • Keep assessment approval separate from auditor independence, report delivery, executive certification, and Agency-submission receipts.
  • Prepare full risk-assessment reports for a possible Agency or Attorney General demand within 30 calendar days, even though routine section 7157 submission is summary information.
Primary sources

References and citations

csrc.nist.gov
Referenced sections
  • NIST privacy source for protecting personal information when the CPRA risk assessment and cybersecurity audit workflow involves PII.
"PII should be protected from inappropriate access, use, and disclosure"
csrc.nist.gov
Referenced sections
  • NIST control catalog context for documenting control evidence and assessment scope in the CPRA risk assessment and cybersecurity audit workflow.
"The controls are flexible and customizable"
csrc.nist.gov
Referenced sections
  • Nonbinding NIST assessment procedures for planning tests and evidence; the California regulations control review and submission timing.
cppa.ca.gov
Referenced sections
  • Confirms the $26,625,000 annual-gross-revenue amount used in the cybersecurity-audit revenue-plus-volume branch, effective January 1, 2025.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.