Compliance and Regulatory Updates
California Cybersecurity Audit and Risk Assessment Regulations: A 2026 Readiness Guide

California’s final regulations on cybersecurity audits and privacy risk assessments became effective January 1, 2026. The rules do not require every organization in California to perform the same audit or assessment. Scope depends on the California Consumer Privacy Act’s definition of a business, the processing thresholds and activities in the regulations, and the organization’s facts.
The practical message is clear: organizations that may be covered should determine scope now, preserve defensible evidence, separate audit independence from remediation work, and build risk-assessment review into new processing decisions.
This article provides general cybersecurity and compliance information. It is not legal advice. Organizations should confirm applicability, interpretation, and legal obligations with qualified California privacy counsel.
Executive summary
- The California Privacy Protection Agency states that the rulemaking is complete and that the regulations took effect January 1, 2026.
- Cybersecurity-audit scope is tied to specified CCPA business and processing thresholds; it is not a requirement for every California business.
- Initial cybersecurity-audit reporting deadlines phase in on April 1 of 2028, 2029, or 2030, depending on the revenue bands and periods specified in the final regulation.
- Businesses subject to the privacy risk-assessment requirements began compliance January 1, 2026. Information for assessments conducted in 2026 and 2027 is due to the CPPA by April 1, 2028.
- The cybersecurity audit must be performed by a qualified, objective, independent professional. The regulations allow an internal or external auditor, but impose independence requirements.
- Audit findings cannot rely primarily on management assertions; the regulation calls for specific evidence, including documents, testing, sampling, and interviews considered appropriate by the auditor.
- Executive management has certification and attestation responsibilities.
What changed
The California Privacy Protection Agency’s rulemaking page states that the Board adopted regulations covering CCPA updates, cybersecurity audits, risk assessments, automated decisionmaking technology, and insurance on July 24, 2025. The Office of Administrative Law approved the rules on September 22, 2025, and they took effect January 1, 2026.
The controlling detail is in the CPPA’s approved regulations text, not a marketing summary or checklist.
Cybersecurity-audit scope
Section 7120 requires a cybersecurity audit when a business’s processing of consumers’ personal information presents significant risk to consumers’ security under the rule’s criteria.
The final text identifies two scope paths:
- the business meets the CCPA threshold referenced in Civil Code section 1798.140(d)(1)(C) in the preceding calendar year; or
- the business meets the threshold referenced in Civil Code section 1798.140(d)(1)(A) and, in the preceding calendar year, processed either:
- personal information of 250,000 or more consumers or households; or
- sensitive personal information of 50,000 or more consumers.
These criteria depend on incorporated statutory definitions and the organization’s processing. Do not decide applicability from revenue alone or from an informal summary. Document the legal analysis, the data counts, the relevant period, and who approved the conclusion.
Cybersecurity-audit timing
The CPPA’s September 23, 2025 announcement summarizes the phased first certification dates:
- April 1, 2028 for a business in the regulation’s over-$100 million band;
- April 1, 2029 for a business in the $50 million-to-$100 million band; and
- April 1, 2030 for a business in the under-$50 million band.
Section 7121 of the final text provides the specific revenue years, qualification dates, and audit periods for those bands. The deadline is not an invitation to wait. The first audit covers an operating period before the filing date, so evidence, ownership, testing, and independence should exist during that period.
Independence is an operating requirement
Section 7122 requires a qualified, objective, independent professional using procedures and standards accepted in the auditing profession.
The auditor may be internal or external, but must exercise objective and impartial judgment and remain free from influence. The regulation restricts the auditor from participating in activities that compromise independence, including certain work the auditor may later assess.
For an internal auditor, the highest-ranking auditor must report to a member of executive management who does not have direct responsibility for the cybersecurity program. Performance evaluation and compensation must also be handled by an executive without direct cybersecurity-program responsibility.
A practical separation model
| Activity | Management / control owner | Independent auditor |
|---|---|---|
| Design security controls | Responsible | Does not design controls being audited |
| Operate and monitor controls | Responsible | Evaluates evidence |
| Prepare management documentation | Responsible | Requests and assesses it |
| Select audit criteria and procedures | Provides context | Exercises independent judgment |
| Test samples and configurations | May perform operational testing | Performs or directs audit testing |
| Remediate findings | Responsible | Validates status without becoming implementer |
| Approve risk | Executive/business owner | Reports evidence and conclusions |
The exact arrangement should be reviewed against the final rule and professional requirements. A company should not label the same work “independent audit” and “implementation” without addressing the conflict.
Evidence must support findings
Section 7122 says no audit finding may rely primarily on management assertions or attestations. Findings must rely primarily on specific evidence the auditor considers appropriate, including documents reviewed, sampling and testing performed, and interviews conducted.
That makes evidence readiness a continuous discipline. Useful evidence may include:
- asset and data-flow inventories;
- identity and privileged-access records;
- authentication and access-control configuration;
- security policies and approved standards;
- vulnerability and patch records;
- endpoint, network, cloud, and application configuration;
- logging and monitoring evidence;
- incident-response plans and exercises;
- backup, restoration, and continuity tests;
- vendor and service-provider records;
- workforce training and access-review evidence;
- risk decisions and exception approvals;
- prior findings and remediation validation; and
- change records showing the control remained in operation.
Screenshots without date, system identity, configuration context, or source may be weak evidence. Prefer exports, logs, configuration records, tickets, test results, and samples that can be traced to the applicable system and period.

Executive certification
Section 7124 requires a written annual certification in years when a business is required to complete a cybersecurity audit. The individual submitting it must be a member of executive management who is directly responsible for audit compliance, has sufficient knowledge to provide accurate information, and has authority to submit the certification.
Executive accountability should therefore begin before the certification date. Leaders need a reliable view of scope, auditor independence, material findings, open remediation, and the evidence supporting completion.
Privacy risk-assessment scope
Article 10 requires a risk assessment before a covered business initiates processing that presents significant risk to consumers’ privacy. Section 7150 lists covered processing activities, including selling or sharing personal information and processing sensitive personal information, subject to the rule’s details and exceptions. The final text also addresses other processing such as certain automated decisionmaking and systematic observation.
The assessment must evaluate whether privacy risks from the processing outweigh benefits to the consumer, the business, other stakeholders, and the public. Section 7152 requires specific documentation rather than generic statements such as “improve services” or “security purposes.”
Key components include:
- specific purpose;
- categories and minimum necessary personal information;
- collection, use, disclosure, retention, and processing methods;
- data sources;
- retention period or criteria;
- consumer interaction;
- approximate number of consumers;
- disclosures to consumers;
- benefits;
- negative privacy impacts and their causes;
- safeguards;
- residual risk; and
- the decision and responsible participants.
Risk-assessment timing and submission
The CPPA says businesses subject to risk-assessment requirements must begin compliance January 1, 2026. Under Section 7157, information for risk assessments conducted in 2026 and 2027 is due April 1, 2028. For later years, submission is generally due April 1 following the year in which assessments were conducted.
The regulation requires an executive-management attestation regarding the required assessments. It also provides that the CPPA or Attorney General may require the underlying risk-assessment reports, with the final text specifying the response period.
Organizations should not treat the submitted summary as the whole compliance record. The underlying assessment needs to be complete, specific, and retrievable.
A 2026 readiness plan
1. Obtain a legal scope determination
Confirm:
- whether the entity is a CCPA “business”;
- which statutory threshold paths apply;
- relevant consumer, household, and sensitive-information counts;
- sale, sharing, sensitive processing, ADMT, and observation activities;
- exemptions and special facts;
- affiliated-entity treatment; and
- the responsible reporting entity.
Retain the method, inputs, date, and approving counsel or decision owner.
2. Inventory information systems and processing
Map systems that process personal information or can provide access to it. The regulatory definition includes resources organized for processing regardless of ownership, so cloud services and service providers matter.
For risk assessments, connect each processing activity to its purpose, data, consumers, systems, recipients, retention, owner, and safeguards.
3. Establish audit independence
Decide whether the auditor is internal or external, document qualification, evaluate conflicts, define reporting, and separate remediation responsibility from audit judgment.
4. Select defensible criteria
Section 7122 refers to accepted professional auditing procedures and standards. Section 7123 also addresses the audit’s scope and criteria. The final text notes that another audit using NIST CSF 2.0 may help meet requirements if it contains or is supplemented with all required information.
A framework label alone is not enough. Create a control-to-requirement crosswalk and define evidence and test procedures.
5. Run a readiness review
A readiness review can identify missing ownership, incomplete evidence, untested controls, and conflicts before the formal audit period. Keep readiness consulting distinct from the independent audit where independence requires it.
6. Remediate and validate
Assign each gap:
- risk and business impact;
- accountable owner;
- approved action;
- target date;
- evidence of completion;
- independent validation where required; and
- documented residual risk.
7. Prepare executive reporting
Executives should receive:
- scope determination;
- auditor independence;
- material findings;
- overdue remediation;
- significant processing assessments;
- evidence limitations;
- third-party dependencies;
- certification calendar; and
- decisions requiring acceptance or funding.
Questions to ask now
- Can we prove whether we are in scope?
- Do data counts use consistent definitions and periods?
- Which processing activities began or changed after January 1, 2026?
- Is our auditor independent from the controls and documentation being assessed?
- Can findings be supported without relying mainly on interviews or assertions?
- Are service-provider systems and data flows in scope where required?
- Can executives trace an attestation to a complete evidence record?
- Does every material gap have an owner, due date, validation method, and accepted residual risk?
Prepare without blurring legal and technical roles
OC Security Audit can support cybersecurity readiness, evidence review, control testing, and independent assessment planning. The 90-Day Executive Cybersecurity Operating Plan provides a practical cadence for assigning owners, gathering evidence, validating remediation, and escalating decisions without treating the plan as legal guidance. Applicability and legal interpretation should be confirmed with qualified counsel. To discuss the cybersecurity side of readiness, contact OC Security Audit.
Prepared and reviewed by Ali Hassani, CISO.
Primary sources
- CPPA rulemaking page and final documents
- CPPA approved regulations text
- CPPA announcement: California finalizes privacy regulations
Last fact-checked July 2026. This is general information, not legal advice. The final regulations and incorporated law control.