Most CCPA checklists stop at the privacy policy and the “Do Not Sell” link. California’s regulator does not. Enforcement has focused on advertising tags that count as sharing, opt-out signals that are ignored, and vendor contracts missing the required terms. Since 1 January 2026 the regulations also require risk assessments, independent cybersecurity audits and, from 2027, rules for automated decision-making.
This assessment scores the CCPA as amended by the CPRA, and the regulations in force now, requirement by requirement. It asks what you could evidence today rather than what your policy says. It is free, it saves as you go, and you can stop and come back to it.
Premium report
See what the premium CCPA/CPRA gap assessment report looks like
A worked sample for a fictional organization: readiness by area, every open gap in a remediation plan, an AI-assisted analysis with priorities and a 30/60/90-day roadmap, plus the live Excel workbook.
What is a CCPA gap assessment?
A CCPA gap assessment compares how you handle California consumers’ personal information with what the California Consumer Privacy Act and its regulations require, and records the distance. It turns “we think we are compliant” into a list of gaps with owners, and it is the evidence you would want if the California Privacy Protection Agency or the Attorney General asked.
Start with applicability. You are a covered business if you meet any one of three thresholds: annual gross revenue above $26,625,000 (the inflation-adjusted figure since 1 January 2025), buying, selling or sharing the personal information of 100,000 or more California consumers or households, or earning half or more of your revenue from selling or sharing it.
What this assessment covers
46 assessable requirements across eleven areas.
| Area | Items | What it asks about |
|---|---|---|
| Applicability and governance | 5 | The three thresholds, your role in each relationship, programme ownership, legal change, privacy by design |
| Data inventory and purpose limitation | 4 | Inventory, reasonably necessary and proportionate use, retention, de-identified data |
| Notices and privacy policy | 4 | Notice at collection, the annual privacy policy update, accessible notices, request methods |
| Requests to know, delete and correct | 7 | The 10-day and 45-day clocks, verification, authorised agents, each right, dark patterns |
| Opt-out of sale and sharing | 5 | Identifying sale and sharing, the opt-out link, Global Privacy Control, 15 business days, re-asking |
| Sensitive personal information | 2 | Identifying it, and the right to limit its use |
| Service providers, contractors and third parties | 4 | Required contract terms, due diligence and monitoring, offshore processing |
| Minors, incentives and non-discrimination | 3 | Opt-in for under-16s, financial incentive notices, non-discrimination |
| Risk assessments and automated decisions | 4 | When a risk assessment is required, its content, submissions to the Agency, ADMT |
| Security, breaches and cybersecurity audits | 4 | Reasonable security, breach exposure, the 30-day notice rule, the annual cybersecurity audit |
| Training, records and assurance | 4 | Training, 24-month request records, metrics, internal audit |
The 2026 to 2030 deadlines
| Date | What applies |
|---|---|
| 1 January 2026 | New regulations take effect; risk assessments are required for new in-scope processing |
| 1 January 2027 | Automated decision-making technology rules apply to significant decisions; browsers must offer an opt-out preference signal |
| 31 December 2027 | Risk assessments due for in-scope processing that started before 2026 |
| 1 April 2028 | First risk assessment submissions to the Agency; first cybersecurity audit certifications for revenue over $100 million |
| 1 April 2029 | Cybersecurity audit certifications for revenue of $50 million to $100 million |
| 1 April 2030 | Cybersecurity audit certifications for revenue under $50 million |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records a regulator could inspect |
| Not applicable | — | A justified exclusion, removed from the score |
The requirements that fail most often
- Advertising pixels and SDKs that count as sharing for cross-context behavioural advertising, at businesses that believe they do not sell data.
- Global Privacy Control signals that are received but not honoured, so the tags keep firing.
- Vendor contracts written for the GDPR that miss the CCPA’s required terms, which can turn a service provider into a third party.
- Loyalty programmes with no notice of financial incentive or value calculation.
- Opt-out requests routed through identity verification, which the regulations do not allow.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every requirement with your status and notes, the score broken down by area, a prioritised gap list, an AI-assisted analysis with a 30/60/90-day roadmap, and the CCPA/CPRA Toolkit documents that close each gap, as a PDF and a working Excel file.
How long does it take?
About 35 minutes if you know your data flows. Answers save as you go, so you can bring in marketing for the tags and procurement for the contracts.
Frequently asked questions
Is this assessment really free?
Yes. Every requirement, your area breakdown and your overall score cost nothing. The $39 full report is optional.
Does the CCPA apply to businesses outside California?
Yes, if you do business in California and meet one of the thresholds. Where you are based does not matter, and the revenue test uses your total revenue, not California revenue.
What is the difference between the CCPA and the CPRA?
The CPRA is the 2020 ballot measure that amended the CCPA. It added the right to correct, sensitive personal information, “sharing”, the Agency and the risk assessment and audit rules. There is one law, usually called the CCPA.
What are the penalties?
Administrative fines of $2,663 per violation and $7,988 per intentional violation or violation involving a minor, as adjusted from 1 January 2025. There is no longer an automatic 30-day cure period. Consumers can also sue after certain data breaches for $107 to $799 per consumer per incident.
Is a high score the same as being compliant?
No. It is a structured self-assessment, not legal advice or a certification. It tells you where the documented gaps are.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.
