September 27, 2026 · 7 min read

CCPA Cybersecurity Audit 2026: Who Must Comply, Thresholds & Deadlines

On January 1, 2026, the California Privacy Protection Agency (CPPA) brought into force regulations that add a new layer to the CCPA/CPRA: certain businesses must now complete an annual cybersecurity audit, run risk assessments, and certify completion to the regulator. If you sell into California, it is worth knowing exactly where you stand — because the rule does not apply to every website, and the details matter.

The one-line summary: this is not a "get a badge on your site" requirement. It is a formal audit of your internal security program, performed by an independent professional auditor, for businesses above specific size and data-volume thresholds.

Are you even in scope?

Two things must be true at once. First, the business must be subject to the CCPA — meaning it does business in California and meets at least one CCPA coverage threshold. Simply having California visitors is not enough. Second, it must cross one of the audit-specific risk thresholds below.

Step 1 — CCPA coverage (any one of these)

Step 2 — Cybersecurity-audit thresholds (revenue AND one volume trigger)

The audit obligation itself targets businesses whose processing presents significant risk: annual revenue above ~$26M and at least one of:

TriggerThreshold
California residents / households whose data is processed250,000+
Consumers whose sensitive data is processed50,000+
Share of revenue from selling / sharing personal data50%+

Below every one of these thresholds, neither the audit nor the baseline CCPA obligations apply. Most small and mid-size stores will not be in scope — but fast-growing DTC brands and data-heavy platforms should check carefully.

What the audit actually covers

The cybersecurity audit assesses your internal security program: multi-factor authentication, encryption, access management, logging and monitoring, incident response, patch management, vendor oversight, and more. It must be carried out by an independent, objective professional auditor, backed by written risk-assessment reports, with a signed certification of completion sent to the CPPA and audit evidence retained for at least five years.

Important distinction: the cybersecurity audit is about internal controls that live behind your login — not the public features of your website. A privacy policy, a "Do Not Sell or Share" link, or an HTTPS certificate are useful, but they do not constitute or replace the CPPA audit, and their absence is not automatically an "audit gap."

Compliance timeline (first certification due)

Annual revenueFirst certification due
Over $100MApril 1, 2028
$50M – $100MApril 1, 2029
Under $50MApril 1, 2030

The deadlines are phased through 2028–2030, but the underlying program work — MFA everywhere, encryption, incident response, vendor due diligence — takes time to stand up. Waiting until the certification year is how businesses end up scrambling.

Where a readiness diagnostic fits

An automated scan cannot see inside your security program, so it cannot certify the CPPA audit — that requires the independent auditor. What it can do is give you a readiness diagnostic: a first, honest look at your privacy-rights posture (the parts that are observable), plus a structured checklist of what the formal audit will demand, so you walk into it prepared instead of surprised.

Selling into the US? Start with a readiness check.

Our automated audit gives you a plain-language readiness diagnostic for CCPA/CPRA and web security — what's observable today, and what the formal cybersecurity audit will require next. It prepares you for the independent audit; it does not replace it.

🔍 Run my readiness check

Related articles

This article is general information, not legal advice. Coverage and thresholds depend on your specific business facts; confirm your status with a qualified professional.

← Back to the blog