CCPA Cybersecurity Audit 2026: Who Must Comply, Thresholds & Deadlines
On January 1, 2026, the California Privacy Protection Agency (CPPA) brought into force regulations that add a new layer to the CCPA/CPRA: certain businesses must now complete an annual cybersecurity audit, run risk assessments, and certify completion to the regulator. If you sell into California, it is worth knowing exactly where you stand — because the rule does not apply to every website, and the details matter.
The one-line summary: this is not a "get a badge on your site" requirement. It is a formal audit of your internal security program, performed by an independent professional auditor, for businesses above specific size and data-volume thresholds.
Are you even in scope?
Two things must be true at once. First, the business must be subject to the CCPA — meaning it does business in California and meets at least one CCPA coverage threshold. Simply having California visitors is not enough. Second, it must cross one of the audit-specific risk thresholds below.
Step 1 — CCPA coverage (any one of these)
- Annual gross revenue above roughly $26.6M (the figure is inflation-adjusted); or
- Buys, sells, or shares the personal information of 100,000+ consumers or households; or
- Derives 50%+ of annual revenue from selling or sharing personal information.
Step 2 — Cybersecurity-audit thresholds (revenue AND one volume trigger)
The audit obligation itself targets businesses whose processing presents significant risk: annual revenue above ~$26M and at least one of:
| Trigger | Threshold |
|---|---|
| California residents / households whose data is processed | 250,000+ |
| Consumers whose sensitive data is processed | 50,000+ |
| Share of revenue from selling / sharing personal data | 50%+ |
Below every one of these thresholds, neither the audit nor the baseline CCPA obligations apply. Most small and mid-size stores will not be in scope — but fast-growing DTC brands and data-heavy platforms should check carefully.
What the audit actually covers
The cybersecurity audit assesses your internal security program: multi-factor authentication, encryption, access management, logging and monitoring, incident response, patch management, vendor oversight, and more. It must be carried out by an independent, objective professional auditor, backed by written risk-assessment reports, with a signed certification of completion sent to the CPPA and audit evidence retained for at least five years.
Important distinction: the cybersecurity audit is about internal controls that live behind your login — not the public features of your website. A privacy policy, a "Do Not Sell or Share" link, or an HTTPS certificate are useful, but they do not constitute or replace the CPPA audit, and their absence is not automatically an "audit gap."
Compliance timeline (first certification due)
| Annual revenue | First certification due |
|---|---|
| Over $100M | April 1, 2028 |
| $50M – $100M | April 1, 2029 |
| Under $50M | April 1, 2030 |
The deadlines are phased through 2028–2030, but the underlying program work — MFA everywhere, encryption, incident response, vendor due diligence — takes time to stand up. Waiting until the certification year is how businesses end up scrambling.
Where a readiness diagnostic fits
An automated scan cannot see inside your security program, so it cannot certify the CPPA audit — that requires the independent auditor. What it can do is give you a readiness diagnostic: a first, honest look at your privacy-rights posture (the parts that are observable), plus a structured checklist of what the formal audit will demand, so you walk into it prepared instead of surprised.
- Observable privacy-rights signals: CCPA disclosures, opt-out mechanics where you sell/share data, Global Privacy Control handling, disclosed data categories.
- A gap checklist for the internal audit: the security controls to have in place before an independent auditor arrives.
- A clear scope call: are you actually in scope, and if so, on which timeline?
Selling into the US? Start with a readiness check.
Our automated audit gives you a plain-language readiness diagnostic for CCPA/CPRA and web security — what's observable today, and what the formal cybersecurity audit will require next. It prepares you for the independent audit; it does not replace it.
🔍 Run my readiness checkRelated articles
This article is general information, not legal advice. Coverage and thresholds depend on your specific business facts; confirm your status with a qualified professional.
← Back to the blog