Most California business owners think of the CCPA as a website-cookie-banner law. As of January 1, 2026, it is also a cybersecurity law with teeth. New regulations from the California Privacy Protection Agency require certain businesses to conduct annual independent cybersecurity audits, run formal privacy risk assessments, and attest to the state, under penalty of perjury, that they did it.
The rules are prescriptive, the deadlines are staggered out to 2030, and the “does this apply to me” question has a genuinely useful answer for most small and midsize companies. Here is the plain-English version. As always with regulation: this is a technology-readiness guide, not legal advice, and your counsel makes the applicability call.
Step one: does the CCPA apply to you at all?
The audit and assessment rules only bite businesses already covered by the CCPA. You are covered if you do business in California and meet any one of these: annual gross revenue above roughly $26.6 million (the inflation-adjusted threshold), buying, selling, or sharing the personal information of 100,000 or more California consumers or households a year, or deriving half or more of your revenue from selling or sharing personal information.
If you clear none of those bars, the new audit rule does not apply to you, and you can stop worrying about the state filing. Do not stop reading, though, because the control set it prescribes is a good preview of where all regulators are heading.
Step two: does the cybersecurity audit rule apply to you?
Being a CCPA business is not enough. The annual cybersecurity audit requirement kicks in only when your processing presents “significant risk,” defined by two triggers. You are in if you earned 50 percent or more of your revenue from selling or sharing personal information, or if you exceed the revenue threshold and, in the prior year, processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more.
Read that carefully. A company can be a CCPA business without being large enough, or data-heavy enough, to owe an annual audit. Many mid-sized California firms will land exactly there: covered by the CCPA, exempt from the audit. The risk-assessment rule is a separate test, covered below.
What the audit actually requires
If you are in scope, the audit is not a self-assessment. It must be performed by a qualified, objective, independent professional, covering a defined set of control areas that span access controls, data integrity, disclosure controls, availability, and program governance, roughly 18 domains in total. Findings and a remediation plan must be documented, a member of executive management must attest to completion, records must be retained for five years, and the agency can demand your documentation with 30 days’ notice.
The deadlines are staggered by revenue. Businesses above $100 million in revenue file their first audit certification by April 1, 2028; those between $50 million and $100 million by April 1, 2029; and those under $50 million by April 1, 2030. After that, it is annual. Those dates feel far away. They are not, because auditors review a full year of evidence, which means the year being audited starts long before the filing date. A business due in April 2029 is being judged on how it operated in 2028, which it needs to prepare for in 2027.
The risk assessment rule (which catches more businesses)
Separate from audits, any CCPA business must conduct a privacy risk assessment before processing personal information in ways that present significant privacy risk: selling or sharing personal information, processing sensitive personal information, or using automated decision-making technology for significant decisions about people. These assessments were required beginning January 1, 2026, and the first attestation and summary filing, covering 2026 and 2027, is due April 1, 2028. Additional automated decision-making obligations arrive January 1, 2027.
Because the trigger is the type of processing rather than sheer size, this rule reaches many more mid-sized companies than the audit does.
Why the penalties make this real
Current CCPA penalties run up to $2,663 per violation and up to $7,988 per intentional violation or violation involving children’s data, and each affected consumer and each day of noncompliance can be treated as a separate violation. The enforcement division has openly described a new era of privacy enforcement. This is not a paper exercise.
What to do now, whether or not you are in scope
If you are in scope: start operating like the audit year has already begun. The 18 control domains the auditor will test are, not coincidentally, the same controls that stop breaches: multifactor authentication, least-privilege access, encryption, logging and monitoring, vulnerability management, tested backups, vendor oversight, incident response, and training. Build them now, generate evidence continuously, and the eventual audit documents reality instead of scrambling to create it. Our Microsoft 365 security checklist maps closely to several of these domains.
If you are out of scope: recognize that this rule, the SEC’s rules, cyber insurance carriers, and frameworks like SOC 2 are all converging on the same expectations. Implementing the control set voluntarily now means you are ready if you grow into scope, and protected either way.
Where we fit
Two important boundaries. The independent audit must be performed by an objective third party, so we do not act as your auditor; that independence is the point. And applicability is a legal question for your counsel. What we do is the technical half: implementing the control domains, building the monitoring and logging that produces audit evidence through our in-house 24/7 SOC, and getting your environment to the state where an auditor finds a working program rather than a to-do list.
That is core to our cybersecurity services for California companies, across Los Angeles, Orange County, and San Diego, and it matters most for data-heavy sectors like healthcare and financial services. If you are not sure where you land on the thresholds, or you know you are in scope and the deadline math just got uncomfortable, reach out.