Law / United States / California

CCPA Cybersecurity Audit Regulations

Cal. Code Regs. tit. 11, Sections 7120 to 7124

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 8 months, effective 1 January 2026.

A comprehensive regime rule binding private bodies.

As of 15 September 2026.

What it requires

  • If your business meets the CCPA's business-scale thresholds, deriving 50 percent or more of annual revenue from selling or sharing personal information, or having more than $25 million in annual gross revenue and having processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year, complete a cybersecurity audit.
  • Complete that audit using a qualified, objective, independent auditor, who may be internal or external to the business, and who did not develop, implement, or maintain the cybersecurity program being audited.
  • If you use an internal auditor, have the highest-ranking auditor report to, and have their performance evaluation and compensation determined by, a member of executive management who does not have direct responsibility for the cybersecurity program.
  • Retain all documents relevant to each cybersecurity audit for at least five years, and give the audit report only to a member of executive management with direct responsibility for the cybersecurity program.
  • Submit a written certification of completion to the California Privacy Protection Agency by April 1 following each year you were required to complete an audit, starting April 1, 2028 for the largest businesses and reaching every covered business by April 1, 2030.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

Enforced by the California Privacy Protection Agency or the Attorney General under the CCPA's general enforcement authority (Civil Code Section 1798.185); this Article states no cybersecurity-audit-specific penalty amount of its own.

What it reaches

Obligation class

Security, DPIA, Reporting, Retention

Who checks it

Audit expectation

periodic

Who audits it

Internal independent, Independent third party

Where the report goes

Filed with regulator, Kept

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 9 of the California Privacy Protection Agency's CCPA regulations, adopted by the Agency Board on July 24, 2025 and effective January 1, 2026, requires a business whose processing of personal information meets the CCPA's revenue-from-data-sales threshold, or its revenue threshold combined with processing the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more consumers in the preceding calendar year, to complete a cybersecurity audit using a qualified, independent auditor, who may be internal or external to the business, and to submit a written certification of that completion to the Agency each year by April 1.

The underlying audit report is not filed with the Agency; the business and auditor must retain it for five years, and it goes only to an executive with direct responsibility for the cybersecurity program.

First certifications are due on a staggered schedule starting April 1, 2028 for businesses with 2026 annual gross revenue over $100 million, then April 1, 2029 for the $50 million to $100 million tier, and April 1, 2030 for smaller covered businesses, after which every covered business audits and certifies annually.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official California Privacy Protection Agency (CPPA) approved rulemaking text

Back to the example  ·  Lint your app