The CCPA cybersecurity audit is the obligation in Article 9 of the California Privacy Protection Agency’s regulations that behaves least like privacy compliance and most like security assurance: an annual audit of the business’s cybersecurity programme by a qualified, independent auditor, against 18 named components, producing a report with ten required contents and a certification to the Agency signed under penalty of perjury by an executive. It applies to businesses that derive half their revenue from selling or sharing personal information, and to businesses over the revenue threshold that processed the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more.
The first reports are due on 1 April 2028, 2029 or 2030 by revenue size — and the first audit period for the largest businesses began on 1 January 2027, so the evidence has to exist from then. This guide sets out who must audit and when, the independence rules that decide who can perform it, the 18 components and the ten report contents, the certification, what an ISO 27001 or SOC 2 programme does and does not cover, and the six gaps auditors will find.

Who must complete a CCPA cybersecurity audit (section 7120)
A business’s processing presents significant risk to consumers’ security, and an annual audit is required, if either of two tests is met: the business derives 50% or more of its annual revenue from selling or sharing personal information (the Civil Code section 1798.140(d)(1)(C) threshold); or it meets the revenue threshold in 1798.140(d)(1)(A) — $26,625,000 since the 2025 inflation adjustment — and in the preceding calendar year processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers. The second test catches most mid-sized consumer businesses; the first catches data brokers and ad-tech regardless of size. Our guide to CCPA compliance covers the thresholds in context.
When the CCPA cybersecurity audit is due (section 7121)
| First audit report due | Who | Audit period covered |
|---|---|---|
| 1 April 2028 | Annual gross revenue for 2026 above $100 million, as of 1 January 2027 | 1 January 2027 to 1 January 2028 |
| 1 April 2029 | Revenue for 2027 between $50 million and $100 million, as of 1 January 2028 | 1 January 2028 to 1 January 2029 |
| 1 April 2030 | Revenue for 2028 below $50 million | 1 January 2029 to 1 January 2030 |
| Thereafter | Any business meeting section 7120 on 1 January of a year | The following 12 months, with the report due by 1 April of the year after |
The middle column is the operational point: the audit covers a calendar year that begins before the report is commissioned. A business in the first tier is being audited on evidence from 1 January 2027 onward, whether or not it has appointed an auditor by then.
Who can perform it (section 7122)
The CCPA cybersecurity audit must be performed by an auditor who is qualified — with knowledge of cybersecurity and of how to audit a cybersecurity programme — objective and independent, using procedures and standards accepted in the auditing profession; the regulation names those of the AICPA, the PCAOB, ISACA and ISO. The auditor may be internal or external, but must exercise impartial judgement free of influence from owners, managers or employees, and must not take part in activities they may later assess: developing procedures, preparing the business’s documents, making recommendations about the programme beyond stating findings, or implementing or maintaining it.
An internal audit function qualifies only if its highest-ranking auditor reports to an executive who does not have direct responsibility for the cybersecurity programme, and that executive conducts the auditor’s performance evaluation and sets their compensation. The business must give the auditor everything it requests as relevant, including information about service providers and contractors, and the auditor must not rely primarily on management’s assertions.
The 18 CCPA cybersecurity audit components (section 7123(c))
| # | Component | What the regulation specifies |
|---|---|---|
| 1 | Authentication | Multi-factor authentication, including phishing-resistant MFA for personnel, service providers and contractors; strong unique passwords where used |
| 2 | Encryption | Personal information at rest and in transit |
| 3 | Account management and access controls | Least privilege for personnel, service providers, contractors and third parties; restricted and monitored privileged accounts with a PAM solution; controlled account creation; physical access |
| 4 | Inventory and management | Personal information inventories with classification and tagging; hardware and software inventories with allowlisting; approval processes for hardware and devices |
| 5 | Secure configuration | Updates and upgrades, securing on-premises and cloud environments, masking, and related hardening |
| 6 | Vulnerability management | Internal and external vulnerability scans, penetration testing and vulnerability disclosure |
| 7 | Audit-log management | Centralised storage, retention and monitoring of logs |
| 8 | Network monitoring and defences | |
| 9 | Antivirus and antimalware | |
| 10 | Segmentation | Of the information system |
| 11 | Ports, services and protocols | Limitation and control |
| 12 | Cybersecurity awareness | How the business maintains current knowledge of threats and countermeasures |
| 13 | Education and training | For each employee, contractor and other personnel |
| 14 | Secure development | Coding best practices, code review and testing |
| 15 | Oversight of service providers, contractors and third parties | To ensure compliance with the business’s requirements |
| 16 | Retention and disposal | Schedules and proper disposal of personal information no longer required |
| 17 | Incident response | How the business manages responses to security incidents |
| 18 | Business continuity and disaster recovery | Including data-recovery capabilities |
The audit assesses each component the auditor deems applicable, the written programme that governs them, and how the business implements and enforces compliance with it — and where a component is not applicable, the report says why. Section 7123(f) allows an audit prepared for another purpose to be used if it meets every requirement of the Article, alone or with supplementation, and gives an audit against the NIST Cybersecurity Framework 2.0 as an example.
The ten report contents (section 7123(e))
- A description of the information system; the policies, procedures and practices assessed; the criteria; and the specific evidence examined — documents, sampling, testing, interviews — with an explanation of why they justify the findings.
- The applicable components and any additional ones, how the business implements and enforces compliance, and an explanation of their effectiveness against unauthorised access, destruction, use, modification, disclosure and loss of availability.
- The status of any gaps or weaknesses the auditor judged to increase those risks, described in detail.
- The business’s plan to address them, with timeframes.
- Corrections or amendments to prior audit reports.
- The titles of up to three qualified individuals responsible for the programme.
- The auditor’s name, affiliation and qualifications.
- A signed, dated statement by the highest-ranking auditor certifying an independent review, impartial judgement and no primary reliance on management’s assertions.
- A sample or description of any breach notification made to consumers under Civil Code section 1798.82(a) during the period.
- A sample or description of any notification made to a California privacy agency, with dates, details and remediation.
The certification (section 7124)
Each year an audit is required, the business submits a written certification to the Agency through its website by 1 April following that year, completed by a member of the executive management team who is directly responsible for cybersecurity-audit compliance, has sufficient knowledge of the audit and has authority to submit.
It states that the audit was completed, the period covered by month and year, a contact, and an electronically signed attestation under penalty of perjury that the information is true and that the business “has not made any attempt to influence the auditor’s decisions or assessments”. The report itself is not filed; the Agency’s power to obtain it sits in its enforcement authority. The structure mirrors the risk-assessment submission in section 7157; our guide to the CCPA risk assessment covers that one.
What ISO 27001 and SOC 2 cover — and do not
An ISO 27001 certificate or a SOC 2 report is evidence that many of the 18 components operate, and section 7123(f) explicitly allows reuse where the Article’s requirements are met. Three things usually stop either from being the CCPA cybersecurity audit on its own. The scope may exclude systems that hold consumers’ personal information. The auditor may not meet section 7122’s independence rules — a firm that also advises on the programme, or an internal function reporting to the CISO.
And neither produces the ten section 7123(e) contents as written, in particular the breach-notification samples and the highest-ranking auditor’s statement. The efficient route is one audit programme, scoped to personal information, run by an auditor who satisfies 7122, whose report is written to 7123(e) and whose evidence also serves the ISO or SOC 2 engagement.
Six gaps a CCPA cybersecurity audit will find
- Phishing-resistant MFA for contractors and service providers, not just employees.
- A personal-information inventory with tagging that actually controls use and disclosure.
- Privileged access management with just-in-time assignment, rather than standing admin rights.
- Third-party oversight with evidence, not contract clauses alone.
- Retention schedules that run, with disposal records.
- Logs retained and monitored centrally, not held per system.
Frequently asked questions
Who must complete a CCPA cybersecurity audit?
Under section 7120, businesses that derive 50% or more of revenue from selling or sharing personal information, and businesses over the CCPA revenue threshold that in the prior year processed the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more consumers.
When is the first report due?
1 April 2028 for businesses with 2026 revenue above $100 million (covering calendar 2027); 1 April 2029 for $50–100 million (covering 2028); 1 April 2030 for under $50 million (covering 2029); annually thereafter.
Can our internal audit team do it?
Yes, if the highest-ranking auditor reports to an executive without direct responsibility for cybersecurity, who evaluates and pays them, and the auditors have not built or run what they assess.
Does a SOC 2 or ISO 27001 audit count?
It can be used where it meets all of Article 9’s requirements, alone or supplemented — scope covering consumers’ personal information, an auditor meeting section 7122, and a report containing the ten section 7123(e) items.
What is filed with the Agency?
A certification of completion by 1 April each year, signed under penalty of perjury by a responsible executive, stating the audit was completed, the period, and that the business did not attempt to influence the auditor; not the report itself.
Where this leaves you
Plan the CCPA cybersecurity audit backwards from its first audit period, not its first due date: know your tier, appoint an auditor who meets section 7122 before the period begins, map the 18 components to the controls you run and the evidence they leave, write the report to the ten contents, and have the executive who will certify it read it before signing. The regulation names the standards, the components and the sentences; the work is in the evidence.
References
- California Privacy Protection Agency: CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT and Insurance Regulations — approved text — Article 9, sections 7120 to 7124: trigger, timing, independence, scope and report contents, certification.
- California Privacy Protection Agency: updated monetary thresholds in the CCPA — The $26,625,000 revenue threshold effective 1 January 2025.
More on the CCPA
- CCPA cybersecurity audit — you are here
- CCPA compliance in 2026: every new deadline
- CCPA risk assessment
- CCPA penalties
- CCPA vs GDPR
- CCPA service provider vs contractor
The Data Security Policy, the Data Breach Response Procedure, the Data Processing Inventory, the Privacy Internal Audit Procedure and the Audit Findings and Corrective Action Register are in the CCPA-CPRA Compliance Toolkit, or start with the free templates.