Are You Ready for New CCPA Requirements?

A brief look into cybersecurity audits and privacy risk asssessments

7/29/2026

Highlighting the New CCPA Requirements

CalPrivacy updated CCPA with additional regulations (California Consumer Privacy Act Regulations) that went into effect January 1, 2026. There are two components that require new actions from any company that meets CCPA thresholds ($26.625 million annual revenue, processes data concerning California residents).

  1. Article 9: Cybersecurity Audits

  1. Article 10: [Privacy] Risk Assessments

Rather than regurgitating the regulation itself, I want to highlight some key components (please refer to CCPA for the full requirements, including whether your business is required to complete these based on § 7120 and § 7150):

Cybersecurity Audits

Executing cybersecurity audits

  • Existing cybersecurity audits, like those using NIST CSF 2.0, can be utilized for this purpose, provided they meet all the requirements set out in CCPA. It is important to note that this still must be done by an independent, qualified auditor. The auditor can be internal or external to your business, but they must be independent. This means the cybersecurity or InfoSec team at your company, since they are involved in maintaining the cybersecurity program, cannot conduct the audit. However, an internal audit function, as long as it meets the requirements outlined in CCPA, could do so. Once completed, a certificate of completion must be submitted by your business’s designated executive leader to CalPrivacy (see below).

  • One caveat to pay particular attention to is the time period your cybersecurity audit covers and requisite submission-by dates. CalPrivacy has elected to place particular requirements around the audit period and submission-by date. Any audit must be conducted for the period Jan 1 20xx to Jan 20xy of the following year (see more below). The certification of completion must then be submitted to CalPrivacy by April 1 20xy, meaning the audit itself must be conducted between Jan 2 and March 31 20xy of each year. If this does not line up with the way your existing cybersecurity audits are conducted, you’ll need to adjust your internal or vendor audit schedule to accommodate these CCPA requirements.

  • CCPA has allowed for a tiered revenue threshold requirement for completion and submission of the first cybersecurity audit in years 2027-2029. To break that threshold down, you can answer the following questions:

    • Was your gross revenue in 2026 more than $100,000,000? If so, an audit must be conducted for the period Jan 1, 2027, to Jan 1, 2028, and submitted by April 1, 2028. If not, reevaluate next year.

    • Was your gross revenue in 2027 $50 million or more? If so, an audit must be conducted for the period Jan 1, 2028, to Jan 1, 2029, and submitted by April 1, 2029.

    • Any gross revenue that meets the minimum threshold requirement for CCPA ($26.625 million at the time of this writing in 2026) would need to complete an audit for the period Jan 1, 2029, to Jan 1, 2030, and submit by April 1, 2030.

Submitting a certificate of completion to CalPrivacy

  • The submission of the certification must be completed by someone on your executive-level management team who is responsible for cybersecurity audit compliance and has sufficient knowledge and authority to attest to the accuracy of the cybersecurity audit. This means that a third-party vendor cannot submit the certification on your behalf.

Privacy Risk Assessments

Executing risk assessments

  • If you already conduct risk assessments for other regulatory bodies (DPIAs for GDPR, for example), these can be utilized for CCPA’s requirements; however, they must meet all the requirements set forth in CCPA. Due to CCPA’s detailed requirements regarding when an assessment should be conducted while GDPR’s are more vague, the likelihood existing risk assessments will need to be modified to be inclusive of CCPA requirements and that new assessments may need to be executed is high. A risk assessment “report” submission will also still be required (see below).

  • A risk assessment must be documented even if the outcome of the assessment is that the project or process is deemed to present significant risk to the consumer and will not move forward. This may be novel for legal or compliance teams that are often used to only documenting risks associated with business decisions that will be implemented.

Submitting a risk assessment “report” to CalPrivacy

  • The submission of the report, which is a record count by category of risk assessment and an attestation signed by the submitting individual, must be completed by April 1st of each year following the risk assessment period (exception to this being 2026 & 2027, which can be combined and sent by no later than April 1, 2028) once effective. The submitting individual must be someone on your executive-level management team who is responsible for privacy risk assessment compliance and has sufficient knowledge and authority to attest to the accuracy of the risk assessment result and underlying detail. This means that a third-party vendor cannot be the attesting/submitting individual on your behalf.

Where to Start

If your company isn’t formulating a plan to address these requirements now, you may be scrambling later. This is particularly true for the Cybersecurity Audit requirement, as there will be a small window between January-April of each year in which an independent auditor will need to assess and execute these audits.

If you intend to (or already do) use a vendor to execute your existing cybersecurity audit, I’d recommend locking down the vendor you want to use sooner rather than later. A great way to test their qualifications is to use 2026 as a “test run” year—not only will your organization be prepared for the kinds of questions that will be asked, but you’ll also get results you can address before the 2027 round of audits. With a likely limited supply of vendors qualified to do these audits, companies may be stuck with limited resources if they wait too long.

If you intend to use your own company’s auditors to execute the cybersecurity audit, ensure that the requirements for independence are also met under the CCPA, because they are specific.

Regardless of the method you use, timing for completing the audit and submitting the report is essential and may require modification to the way you do business today (more on that below).

At Cadence, we can help with either of these requirements – executing a cybersecurity audit, privacy risk assessment, or getting you ready for both!

privacy; GDPR; cadence; CCPA, data
privacy; GDPR; cadence; CCPA, data

Cadence Privacy