Table of contents
The state of California has updated the California Consumer Privacy Act (CCPA) and its supporting regulations yet again, and this time it has a cybersecurity audit requirement. The California Privacy Protection Agency (CPPA) oversees compliance with these regulations. This post will cover what organizations need to know about their cybersecurity obligations, including who they apply to, the penalties for non-compliance, when they must be done, and what the requirements are.
This post only covers the cybersecurity requirements of CCPA. The privacy requirements are a separate and much less technical topic. Businesses must keep in mind that cybersecurity and privacy are two (2) different things, and they must still comply with the privacy portions of CCPA (including the risk assessment) even if they pass the cybersecurity audit.
TrustedSec has years of experience helping organizations implement and audit both cybersecurity and privacy requirements. Please get in touch with us for any questions on the applicability, scope, or requirements of CCPA or other compliance frameworks.
Overview
Each of the topics in this section are covered in much more detail throughout the other sections of this post. Click on the topic headers or use the navigation bar to jump to the relevant detailed section.
Applicability
The CCPA cybersecurity audit requirement applies to businesses that do business in the State of California and collect consumers’ personal information if they meet certain revenue and/or personal information processing thresholds. The cybersecurity audit requirements are narrower than the CCPA requirements, so not all business subject to CCPA will need to complete a cybersecurity audit.
Enforcement
Violations of the CCPA cybersecurity audit requirement are enforced via the same mechanism as the rest of CCPA, via a system of administrative fines and civil penalties for non-compliance as well as additional per-consumer, per-incident damages for breaches imposed by CPPA or via consumer individual or class action.
Rollout Timeline
The cybersecurity audit requirement has a phased rollout based on decreasing revenue thresholds. The first wave will be required to meet the cybersecurity requirements throughout calendar year 2027 and complete an audit in early 2028. All organizations that meet the cybersecurity audit applicability criteria will be required to meet the cybersecurity requirements in 2031 and complete an audit in early 2032.
Certification
Each business to which the cybersecurity audit requirement applies must submit an annual certification that the audit was completed and that the business meets the cybersecurity requirements via the CPPA website by April 01 following the calendar year covered by the audit. This certification must be made by executive management under the penalty of perjury.
Audit Performance
CCPA has strict requirements for auditor skills and independence. While CCPA allows for internal audits, businesses will need to determine if they have any personnel with the appropriate audit skills, cybersecurity skills, and independence to perform the audit. Businesses must also ensure that external auditors meet these requirements.
Audit Scope
The cybersecurity requirements and audit effectively apply to any devices that handle personal information, including network infrastructure, security infrastructure, cloud services, and other service providers that can impact the security of personal information.
Cybersecurity Requirements
There are 18 top-level requirements, some of which are supported by subrequirements. The requirements are somewhat vague, but CCPA allows leeway for businesses to implement the requirements in a manner that is appropriate to the business’s size and complexity and the nature and scope of its processing activities.
Applicability
Businesses are only required to comply with the CCPA cybersecurity audit requirement if CCPA itself is already applicable to them. See our other post CCPA Update: Who’s In Scope (coming soon) for more information on CCPA applicability.
Businesses that are required to comply with CCPA are only required to meet the CCPA cybersecurity audit requirement if they meet either of the following criteria:
- Derive 50% or more of annual revenues from selling or sharing consumers' personal information
- Meet the annual gross revenue threshold for CCPA applicability ($26,625,000 as of January 1, 2025) and meet either of the following criteria:
- Processed the personal information of 250,000 or more consumers or households in the preceding calendar year
- Processed the sensitive personal information (more on that definition below) of 50,000 or more consumers in the preceding calendar year
The gross revenue threshold shown above is adjusted for inflation every two (2) years. The CPPA publishes the current threshold.
Details on what qualifies as Personal Information and Sensitive Personal Information is covered in our previous post CCPA Update: Who’s In Scope (coming soon).
Enforcement
From an enforcement perspective, the cybersecurity audit requirement is the same as any other requirement within CCPA and is subject to the same penalties as any other violation. Details on CCPA enforcement mechanisms and fines are covered in our previous post CCPA Update: Who’s In Scope.
Note that encryption of personal information is one of the cybersecurity requirements and that additional penalties apply following breaches of nonencrypted and nonredacted personal information.
Rollout Timeline
CCPA regulations define a phased rollout for the cybersecurity audit at 11 CCR §7121 based on the business’ gross annual revenue.
Any business that exceeds the gross annual revenue threshold in the gross annual revenue year indicated below must comply with the cybersecurity requirements during the indicated audit coverage period and submit an audit report to the state covering that period by the submission deadline.
Gross Annual Revenue Year | Gross Annual Revenue | Audit Coverage Period | Audit Report Submission Deadline |
|---|---|---|---|
2026 | Greater than $100,000,000 | January 01, 2027 - January 01, 2028 | April 01, 2028 |
2027 | Greater than $50,000,000 | January 01, 2028 - January 01, 2029 | April 01, 2029 |
2028 | Less than $50,000,000 | January 01, 2029 - January 01, 2030 | April 01, 2030 |
After April 01, 2030, the phased rollout is complete, and the annual revenue thresholds shown in the table above become irrelevant. Each business must check whether it met the cybersecurity audit applicability criteria during the calendar year that just ended on January 01 of each year. Businesses that met the applicability criteria in the previous calendar year must comply with the cybersecurity requirements during the entire calendar year that just began and will need to conduct a cybersecurity audit covering that calendar year by April 01 of the following year.
Note that the audit will cover the entire calendar year prior to the audit reporting deadline, so all relevant security requirements must be in place by the start of a business’s audit coverage period on January 01 of the year the audit covers, not by the start of the audit a few months before the audit reporting deadline. A business will fail their audit if an auditor uncovers evidence that the cybersecurity requirements were not implemented at any time during the audit coverage period.
For example, a business that meets the CCPA cybersecurity audit applicability criteria for the first time during the calendar year 2030 (as determined on January 01, 2031) must:
- Have the cybersecurity requirements implemented during the entirety of calendar year 2031, starting on January 01, 2031
- Complete an audit covering calendar year 2031 during Q1 of 2032
- Submit audit certification to CPPA by April 01, 2032
Certification
Businesses must submit a written certification that a cybersecurity audit was completed and meets the cybersecurity requirements defined in CCPA by April 01 following any year that the business is required to meet the cybersecurity requirements.
This certification must be completed by a member of the business’s executive management team who meets all of the following criteria:
- Is directly responsible for the business’s cybersecurity-audit compliance
- Has sufficient knowledge of the business’s cybersecurity audit to provide accurate information
- Has the authority to submit the business’s certification to the Agency
The certification must be submitted via the CPPA website. As of the time of publication, the CPPA website does not provide instructions for submitting the certification, which is not surprising because the first certification submissions are not required until April 01, 2028. The author suspects CPPA will create a form that captures all of the required information described below, but businesses may want to be prepared to create their own certification letter in case CPPA uses a more freeform submission process. As per CCPA, the certification must include all of the following:
- The business’s name and point of contact for the business, including the contact’s name, phone number, and email address
- A statement that the business has completed the cybersecurity audit
- The time period covered by the cybersecurity audit, by month and year
- An electronically signed attestation to the following statement: “I attest that I meet the requirements of California Code of Regulations, Title 11, section 7124, subsection (c), to submit this certification. Under penalty of perjury under the laws of the state of California, I hereby declare that the information contained within and submitted with this certification is true and correct and that the business has not made any attempt to influence the auditor’s decisions or assessments regarding the cybersecurity audit.”
- The name and business title of the person submitting the certification, and the date of the certification
Audit Performance
CCPA defines a set of requirements for how the cybersecurity audits are to be performed. These key requirements include:
- Performed by an independent professional auditor
- Use procedures and standards accepted in the profession of auditing
- Auditor must have knowledge of cybersecurity and how to audit a cybersecurity program
While CCPA leaves the door open to internal or external audits, many smaller businesses that do not have an internal audit department will struggle to find in-house personnel that meet all of the criteria above in order to perform an internal audit and will likely require an external audit. Businesses that choose to use an internal auditor will need to take extra care to demonstrate that the auditor is independent, professional, and has the appropriate cybersecurity knowledge. Businesses should also keep these criteria in mind when choosing an external auditor.
Professional Auditing
Auditing requires knowledge of specific audit techniques. Most cybersecurity personnel, even those performing technical assessments like vulnerability scans and penetration tests, do not have these skills.
Businesses will need to demonstrate that the auditor, whether internal or external, is familiar with and follows audit procedures and standards such as those published by AICPA, ISACA, ISO, or PCAOB.
Cybersecurity Knowledge
Audits require knowledge of the subject being audited, as well as standard audit procedures, and cybersecurity is no different. Many internal audit teams and external audit providers may be more familiar with financial or other non-technical controls than they are with cybersecurity controls. This can lead to audit reports that miss important findings or include false positive findings due to misunderstandings about the requirements and how they are typically implemented.
Businesses must take care to determine whether their auditor, internal or external, has the necessary cybersecurity knowledge to perform this type of assessment to ensure accurate audit results and to comply with the CCPA requirement.
Independence
An auditor, whether internal or external, must be free to make decisions and assessments without influence by the business.
CCPA goes a step further for internal audits and requires the lead auditor to report directly to a member of the business’s executive management team who does not have direct responsibility for the cybersecurity program. Performance evaluations and compensation of the internal auditor also must be determined by a member of the business’s executive management team who does not have direct responsibility for the cybersecurity program.
Many businesses have a bad habit of asking their cybersecurity personnel to audit their own cybersecurity program. While this seemingly solves the problem of cybersecurity knowledge, it violates the principle of independence: The auditor must not participate in activities that the auditor may assess during the audit. Examples of activities that an auditor cannot participate in include:
- Developing procedures
- Preparing the business documents
- Making cybersecurity program recommendations
- Implementing or maintaining the cybersecurity program
The independence problem is not exclusive to internal auditors. Businesses working towards compliance may seek outside help to design and implement the cybersecurity program and often attempt to find a single consulting firm that can help both implement and audit the program. The same principle applies: The external auditor cannot participate in activities that they will later audit. Businesses that seek to have their cybersecurity compliance program designed, implemented, and audited by the same consulting firm must verify that the consulting firm will not assign audit tasks to the same personnel that participated in design or implementation. Businesses must also verify that the program has strong internal controls to prevent the audit from being influenced by the fact that the consulting firm helped with the design or implementation of the program being audited.
Cooperation
As an auditor of nearly 20 years, there is nothing more frustrating than a client that does not provide the information necessary to conduct an audit—or worse, attempts to conceal information that would result in a failing audit.
CCPA requires businesses provide the auditor with all requested information relevant to the cybersecurity audit. Businesses must also make good-faith efforts to disclose all relevant facts and are prohibited from misrepresenting relevant facts. Businesses that do not provide the necessary information may find themselves failing an audit because the auditor has lost faith in the audit process, regardless of the actual compliance status.
Evidence
CCPA requires auditors to rely on evidence, such as documentation reviews and testing of systems. This may also include interviews with personnel performing work covered by the requirements. Auditors are specifically prohibited from relying exclusively on assertions and attestations by business management. “It works this way because I said so” is not good enough for CCPA.
Businesses should prepare for an audit by:
- Understanding what systems, personnel, and locations are in or out of scope (and why)
- Collecting all relevant policies and procedures
- Collecting records that demonstrate that the required processes are being followed
- Making sure the personnel that perform required processes will be available for interviews
- Being prepared to provide over-the-shoulder demonstrations of required processes
- Being prepared to retrieve artifacts from in-scope systems, e.g., configuration and log files
- Being prepared to provide auditors with access to in-scope systems
Report Handling
The cybersecurity audit report must be provided to a member of the business’s executive management team who has direct responsibility for the cybersecurity program. This may come as a surprise to many businesses that tend to delegate such tasks to the cybersecurity team.
Both the business and the auditor must maintain documents relevant to the audit for a minimum of five (5) years after audit completion. While some businesses may be uncomfortable with an auditor maintaining copies of security-related information, this is a requirement. Businesses should take their own steps to assess the retention procedures and protections implemented by external auditors.
Audit Scope
The official scope of the cybersecurity audit is to “assess how the business’s cybersecurity program: protects personal information from unauthorized access, destruction, use, modification, or disclosure; and protects against unauthorized activity resulting in the loss of availability of personal information.”
For practical purposes, this means that any device that handles personal information is in scope for the cybersecurity requirements and audit.
Many organizations that are new to cybersecurity requirements tend to focus only on devices that store the covered information and forget about devices that only process or transmit the information—e.g., workstations used to interact with personal information within a cloud application that do not store personal information locally, or network switching and routing infrastructure that transmits personal information as it moves from one (1) device to another.
Although CCPA does not explicitly state that devices that process or transmit personal information are in scope, compromise of such devices could clearly lead to unauthorized access to or affect the availability of personal data at a minimum. Applying compliance requirements to devices that only process or transmit covered information, without storage, is also a principle in other compliance frameworks that follow the flow of specific types of information (e.g., PCI DSS and CMMC).
Businesses will also find that much of their security infrastructure will fall in scope, even though it does not directly store, process, or transmit personal information. This is because any security infrastructure used to implement the CCPA cybersecurity requirements cannot effectively protect personal information if the security infrastructure itself is not secured.
The generally accepted practice from other cybersecurity frameworks (e.g., PCI DSS and CMMC) is that a host must be completely isolated from devices that store, process, or transmit covered information (personal information in this case) to be considered out of scope. If a host can establish a connection on any port, protocol, or service to a device that handles personal information it will generally be considered in scope, even if that connection transits a firewall. Segmentation of information systems is a CCPA cybersecurity requirement, so separating systems that have a business reason to handle personal information from systems that do not is mandatory.
CCPA also explicitly applies to the security of cloud services used by a business to handle personal information. Similarly, businesses may outsource some security functions to service providers. Outsourcing the handling of personal information is not a magic loophole to avoid compliance requirements, and each cybersecurity requirement must be met by either the business, the service provider, or a combination of both.
Businesses should work with cloud and other service providers that handle or can impact the security of personal information to determine how cybersecurity responsibilities will be assigned between the parties and how the service provider meets the necessary requirements. Ideally, this should be handled as part of the contract process defined in the privacy portion of CCPA at 11 CCR §§7050-7053.
Cybersecurity Requirements
CCPA defines 18 top-level cybersecurity requirements, some of which contain additional subrequirements.
The requirement text shown below is all that CCPA provides. These requirements are fairly vague, which may leave some businesses wondering what is considered good enough to meet them. The answer is a solid “it depends.” CCPA states that the cybersecurity program should be “appropriate to the business’s size and complexity and the nature and scope of its processing activities, taking into account the state of the art and cost of implementing the components of a cybersecurity program.” This means there “good enough” varies based on the resources available to the business and how it handles personal information.
- A business that handles enormous volumes of personal information, including sensitive personal information, across many thousands of devices and retains that information for extended periods of time would be expected to implement each of the requirements in a much more robust way than another business that handles low volumes of personal information on only a few devices, never handles sensitive personal information, and does not retain personal information for very long.
- Similarly, a small mom-and-pop shop would not have the resources to implement a complex cybersecurity program or have one as thorough as that of a large enterprise with enough resources to staff a dedicated Information Security department.
The full list of requirements includes:
Number | Requirement | Subrequirements |
|---|---|---|
1 | Authentication | (A) Multi-factor authentication (including multi-factor authentication that is resistant to phishing attacks for employees, independent contractors, and any other personnel, service providers, and contractors). (B) If the business uses passwords or passphrases, strong unique passwords or passphrases (e.g., passwords that are at least eight characters in length, not on the business’s disallowed list of commonly used passwords, and not reused). |
2 | Encryption of personal information, at rest and in transit. | None |
3 | Account management and access controls | (A) Restricting each person’s, account’s, or application’s privileges and access to personal information to what is necessary for that person, account, or application to perform their duties. For example:
(B) Restricting the number of privileged accounts, restricting those privileged accounts’ access functions to only those necessary to perform the account-holder’s job, restricting the use of privileged accounts to when they are necessary to perform functions, and using a privileged-access management solution (e.g., to ensure just-in-time temporary assignment of privileged access). (C) Restricting and monitoring the creation of new accounts for employees, independent contractors, or other personnel; service providers or contractors; and privileged accounts, and ensuring that the accounts’ access and privileges are limited as set forth in subsections (c)(3)(A) and (B). (D) Restricting and monitoring physical access to personal information (e.g., through the use of badges, secure physical file locations, and enforcement of clean-desk policies). |
4 | Inventory and management of personal information and the business’s information system | (A) Personal information inventories (e.g., maps and flows identifying where personal information is stored, and how it can be accessed) and the classification and tagging of personal information (e.g., how personal information is tagged and how those tags are used to control the use and disclosure of personal information). (B) Hardware and software inventories, and the use of allowlisting (i.e., discrete lists of authorized hardware and software to control what is permitted to connect to and execute on the business’s information system). (C) Hardware and software approval processes, and preventing the connection of unauthorized hardware and devices to the business’s information system. |
5 | Secure configuration of hardware and software | (A) Software updates and upgrades; (B) Securing on-premises and cloud-based environments; (C) Masking (i.e., systematically removing or replacing with symbols such as asterisks or bullets) the sensitive personal information set forth in Civil Code section 1798.145, subdivisions (ae)(1)(A) and (B) and other personal information as appropriate by default in applications; (D) Security patch management (e.g., receiving systematic notifications of security-related software updates and upgrades; and identifying, deploying, and verifying their implementation); (E) Change management (i.e., processes and procedures to ensure that changes to information system(s) do not undermine existing safeguards). |
6 | Internal and external vulnerability scans, penetration testing, and vulnerability disclosure and reporting (e.g., bug bounty and ethical hacking programs). | None |
7 | Audit-log management, including the centralized storage, retention, and monitoring of logs. | None |
8 | Network monitoring and defenses | (A) Technologies, such as bot-detection, intrusion-detection, and intrusion-prevention, which a business may use to detect unsuccessful login attempts, monitor the activity of authorized users, and detect and prevent unauthorized access, destruction, use, modification, or disclosure of personal information; or unauthorized activity resulting in the loss of availability of personal information; (B) Data-loss-prevention systems (e.g., software to detect and prevent unauthorized access, use, or disclosure of personal information). |
9 | Antivirus and antimalware protections. | None |
10 | Segmentation of an information system (e.g., via properly configured firewalls, routers, switches). | None |
11 | Limitation and control of ports, services, and protocols. | None |
12 | Cybersecurity awareness, including how the business maintains current knowledge of changing cybersecurity threats and countermeasures. | None |
13 | Cybersecurity education and training, including training for each employee, independent contractor, and any other personnel to whom the business provides access to its information system (e.g., when their employment or contract begins, annually thereafter, and after a personal information security breach, as described in Civil Code section 1798.150). | None |
14 | Secure development and coding best practices, including code-reviews and testing. | None |
15 | Oversight of service providers, contractors, and third parties to ensure compliance with sections 7051 and 7053. | None |
16 | Retention schedules and proper disposal of personal information no longer required to be retained, by (A) shredding, (B) erasing, or (C) otherwise modifying the personal information in those records to make it unreadable or undecipherable through any means. | None |
17 | How the business manages its responses to security incidents (i.e., its incident response management). | (A) For the purposes of subsection (17), “security incident” means an occurrence that actually or imminently jeopardizes the confidentiality, integrity, or availability of the business’s information system or the personal information the system processes, stores, or transmits, or that constitutes a violation or imminent threat of violation of the business’s cybersecurity program; unauthorized access, destruction, use, modification, or disclosure of personal information; or unauthorized activity resulting in the loss of availability of personal information is a security incident. (B) The business’s incident response management includes:
|
18 | Business-continuity and disaster-recovery plans, including data-recovery capabilities and backups. | None |
