The CCPA cybersecurity audit requirements are now moving from regulatory discussion to operational reality. A substantial number of companies will be required to complete an annual cybersecurity audit in 2027, with executive management certifying to the California Privacy Protection Agency, or Cal Privacy, that the audit has been completed.
For organizations meeting defined thresholds, the first CCPA cybersecurity audit certification is due on April 1, 2028. While that deadline may seem distant, compliance efforts must begin much sooner. The audit period underlying the initial certification spans January 1, 2027 through January 1, 2028, meaning your controls, processes, and evidence will be subject to evaluation throughout that timeline.
As a result, the remaining months of 2026 can represent a critical pre-assessment and/or remediation window. Organizations should use this time to identify and address control gaps, mature cybersecurity capabilities, and strengthen documentation before formal testing begins. Therefore, waiting until 2027 may significantly reduce the opportunity to remediate deficiencies before they are considered gaps in the first audit period.
Organizations that use the NIST Cybersecurity Framework, CIS Security Controls, ISO 27001, SOC reporting, or other established cybersecurity frameworks may have controls, assessments, workpapers, and evidence that can support the CCPA cybersecurity audit rule. The more important question is whether existing work performed addresses the regulation’s scope and independence requirements, applies to the appropriate systems and personal information, and provides sufficient evidence that relevant controls are operating effectively.
The biggest risk applicable to the cybersecurity audit requirements may not be the absence of key cybersecurity controls. It may be the inability to connect the cybersecurity work an organization has completed to what the CCPA cybersecurity audit requires, forcing organizations into an unnecessary assessment and placing avoidable burdens on business and technology stakeholders.
What is a CCPA Cybersecurity Audit?
A CCPA cybersecurity audit is an annual, independent evaluation of the cybersecurity program of a business whose processing of consumers’ personal information presents significant risk to the consumers’ data. Cal Privacy is responsible for implementing and enforcing the CCPA, and the final CCPA regulations define the annual cybersecurity audit requirements for businesses that meet the applicability criteria. For additional context on the regulatory requirements, applicability criteria, phase-in deadlines, and audit approach considerations, see BDO’s California CCPA Cybersecurity Audit Requirement article.
The cybersecurity audit is not limited to a review of policies. Its scope includes systems that collect, use, disclose, retain, or otherwise process California consumers’ personal information, along with the governance, controls, and supporting evidence associated with auditing those systems.
The audit assesses areas including authentication, encryption, access management, personal information inventories, vulnerability management, logging, network defenses, security training, third-party oversight, incident response, and business continuity.
This breadth is why CCPA cybersecurity audit responsibilities should not sit exclusively with the privacy, legal, or cybersecurity function. Preparation may require coordination across the teams that understand personal information, enterprise systems, third-party relationships, system-level controls, and business risk.
Who May Be Required to Complete a CCPA Cybersecurity Audit?
The audit requirement applies for-profit entities that process California consumers’ personal information and meet certain revenue and data-processing thresholds. This may include businesses that derive 50% or more of annual revenue from selling or sharing consumers’ personal information, or businesses that meet the applicable revenue threshold and process personal information or sensitive personal information at volumes identified in the regulation.
Organizations should also consider that employee data and the systems that house employee data may be within scope because the CCPA’s definition of consumer can include workforce-related personal information. This can expand planning beyond customer-facing platforms to human resources, identity, payroll, benefits, collaboration, and other internal systems.
The Audit Deadline Is Not the Date to Start Preparing
The CCPA cybersecurity audit certification deadlines are being phased in over three years based on annual gross revenue. The required audit report completion dates are:
- April 1, 2028 for businesses with annual gross revenue greater than $100 million
- April 1, 2029 for businesses with annual gross revenue from $50 million through $100 million
- April 1, 2030 for businesses with annual gross revenue below $50 million [cppa.ca.gov]
Organizations that wait until the certification deadline to assess their environment for alignment with the cybersecurity audit rule may leave insufficient room to define scope, resolve control deficiencies, strengthen documentation, and build an evidence trail for the applicable audit period.
A more practical starting point is an applicability and readiness analysis. Organizations should determine whether they meet the relevant revenue and data-processing criteria, identify when their first certification is due, and understand which systems process personal information that fall within the audit scope.
NIST CSF Can Provide a Path Forward, but Not a Shortcut
The regulation allows businesses to leverage various cybersecurity frameworks if they meet the 18 CCPA cybersecurity components and requirements. BDO has worked with companies to use the NIST Cybersecurity Framework (“CSF”) as the basis for both the readiness assessment and the annual audit, since the CCPA regulations specifically mention this framework and the components do map neatly to the CSF functions, categories, and subcategories. Other frameworks, such as the Center for Internet Security (CIS) Controls, is another example for consideration if an organization has implemented the CIS framework.
For organizations already using one of these frameworks, this may be a key head start. Instead of developing a disconnected compliance structure and regulatory reporting mechanism, an organization can use a common control framework to serve multiple purposes.
To be noted, the existence of a prior assessment does not automatically establish that an organization is prepared for a CCPA cybersecurity audit. Organizations still need to evaluate whether:
- The assessment covers the systems that process relevant personal information.
- The applicable CCPA cybersecurity components are addressed.
- Testing, not just management interviews, supports the conclusions reached.
- Evidence is current, complete, and traceable.
- The qualification of the professional conducting the audit and processes performed satisfy the independence requirements.
- Identified gaps are documented and appropriately addressed, as applicable.
NIST CSF and other frameworks can provide the structure. Readiness depends on how that structure is applied.
The regulation is specific about requirements, but not prescriptive about the report format
The CCPA regulations identify the cybersecurity program components that must be addressed, but they do not require every business to produce the same type of audit report. The regulation references recognized frameworks and standards, including the NIST CSF, AICPA, ISACA, ISO, and PCAOB procedures and standards. This gives organizations an opportunity to evaluate which reporting approach may be most appropriate based on their existing cybersecurity program, prior assessments, control environment, business obligations, and independence considerations.
For some organizations, a SOC 2 Type 2 plus report that includes the CCPA cybersecurity requirements as additional criteria may cover a large portion of the requirements. For others, a custom report based on NIST CSF, ISO 27001, or SOC for Cybersecurity may be more appropriate. Some companies may also consider an internal independent assessment, provided the internal auditor is qualified, objective, independent, free from management influence, and separate from the activities being audited.
Cybersecurity Maturity Is Not the Same as Audit Readiness
Organizations with mature cybersecurity programs may still encounter gaps pertaining to the requirements.
A previous cybersecurity assessment may have been performed for a different purpose, covered a narrower system population, or used procedures that do not fully address the CCPA audit requirements. Even when a control has already been tested, the available evidence may not demonstrate that it operated effectively throughout the relevant audit period.
Organizations should review existing assessments, workpapers, control matrices, policies, narratives, and testing results before initiating another broad evidence request. That review can help determine what may be reused, what needs to be refreshed, and where additional work is necessary.
The distinction between cybersecurity maturity and cybersecurity audit readiness is important:
Cybersecurity maturity reflects how well an organization’s cybersecurity capabilities are developed and managed.
Cybersecurity audit readiness reflects whether the organization can demonstrate, through appropriate scope, testing, documentation, and evidence, that applicable controls meet the audit requirements.
An organization may have strong controls but fragmented evidence. It may also have extensive audit documentation without a reliable inventory of the systems processing California consumer personal information. Neither position provides complete readiness.
Four Questions That Can Reveal Readiness Gaps
Organizations do not need to wait for the formal audit to identify potential weaknesses. Four questions can help leaders determine where additional preparation may be required.
Do we know where California consumer personal information resides?
A technology asset inventory may not provide a complete view of personal information. Organizations should identify which systems collect, process, retain, transmit, or otherwise use California consumers’ personal information and sensitive personal information.
This inventory can affect audit scope, control ownership, third-party review, testing, and evidence collection. It may also identify business applications or data repositories that were not included in previous cybersecurity assessments.
Have we considered workforce personal information?
The CCPA regulations note that consumers include employees. Organizations should therefore consider relevant workforce personal information and systems when establishing the potential audit scope.
This could broaden the readiness discussion beyond customer-facing platforms to systems supporting human resources, identity, payroll, benefits, collaboration, and other functions that process employee personal information.
Can we prove that our controls operate effectively throughout an entire audit period?
A policy explains what should happen. Audit evidence helps demonstrate what happened during a particular timeframe.
Organizations should evaluate whether control owners can produce current documentation, testing results, approvals, reports, logs, tickets, or other evidence supporting the operation of relevant controls. That evidence should be connected to the system, control, audit period, and conclusion it is intended to support.
Are privacy and cybersecurity teams working from the same scope?
Privacy teams may understand processing activities and consumer obligations, while cybersecurity teams understand systems, controls, and threats. Legal, compliance, internal audit, procurement, and technology teams may hold other parts of the readiness picture.
If these functions use different inventories, definitions, or risk assumptions, establishing a consistent and defensible audit scope may become significantly more difficult.
How Should Organizations Prepare for a CCPA Cybersecurity Audit?
A practical CCPA cybersecurity audit readiness process can begin with five actions:
- Evaluate applicability. Review the regulatory criteria against current revenue and personal information processing activities and volumes.
- Define the relevant system population. Identify systems and supporting processes that collect, use, disclose, retain, transmit, or otherwise process California consumers’ personal information.
- Map current frameworks and controls to the audit requirements. Use an established framework, such as NIST CSF 2.0, to connect existing controls to the applicable CCPA cybersecurity components.
- Review existing evidence before requesting more. Determine which prior assessments, workpapers, control matrices, narratives, and testing results may be reused or updated. Be mindful of assessment scope and timing.
- Prioritize remediation. Create a practical roadmap that sequences control gaps, evidence weaknesses, ownership issues, and scope concerns according to risk and audit impact.
This approach can help organizations focus resources on genuine gaps rather than treating every requirement as new.
Readiness should also be considered alongside related CCPA obligations, including risk assessments for high-risk processing activities and governance over automated decision-making technology. While this article focuses on the cybersecurity audit requirement, organizations may benefit from coordinating these efforts so privacy, cybersecurity, legal, compliance, and internal audit teams are working from a consistent view of data, systems, risks, and evidence.
Key Questions About CCPA Cybersecurity Audit Readiness
An existing cybersecurity audit may be leveraged if it satisfies the regulation’s requirements. Organizations should evaluate its scope, coverage, testing procedures, evidence, auditor qualifications, and independence before relying on it.
No. NIST CSF and other frameworks can provide a strong foundation for organizing and assessing cybersecurity controls, but the assessment must still address the applicable CCPA requirements and relevant systems.
The biggest mistake may be launching an entirely new assessment before determining what existing controls, evidence, and audit work can be leveraged. A detailed review of prior work can help reduce duplication and focus resources on areas that require additional attention.
No. A coordinated readiness process can also improve visibility into cybersecurity risk, clarify control ownership, strengthen privacy and cybersecurity governance, and create more repeatable processes for future audit cycles.
Compliance Is the Requirement. Operational Efficiency Is the Opportunity.
The organizations that prepare most effectively will not necessarily be those that create the most documentation or launch the largest compliance projects.
They will be the organizations that can answer three questions clearly:
- What California personal information and systems are in scope?
- Which existing controls, assessments, and evidence can support the audit?
- Where are stronger controls or better evidence still needed?
For many organizations, CCPA cybersecurity audit readiness does not need to begin with a blank page.
It should begin with a closer look at the cybersecurity investments they have already made.
Questions About CCPA Cybersecurity Audit Readiness?
BDO can help organizations assess applicability, evaluate potential reporting approaches, map existing cybersecurity controls to the CCPA audit requirements, and identify readiness activities based on their privacy and cybersecurity program. For a broader overview of the CCPA cybersecurity audit requirement, read BDO’s California CCPA Cybersecurity Audit Requirement article or connect with our team to understand where your organization stands today and what may need attention before the applicable audit period begins.