California’s new cybersecurity audit requirements may not take effect until 2028, but the compliance timeline starts much sooner. The first certifications for businesses with annual revenue of greater than $100 million are not due until April 1, 2028, but that date can create a false sense of security. For those businesses, the first audit period begins January 1, 2027, giving affected businesses limited time to assess whether existing review processes satisfy the regulation.
For companies that already conduct regular security assessments, the key question is whether existing audits can be leveraged to meet California’s requirements and where they may need to take additional steps to close the gaps.
This alert is the first installment in our Cybersecurity Awareness Month series. Throughout October, we will be sharing insights on emerging cybersecurity, privacy, and AI governance developments affecting businesses. Be on the lookout for future alerts.
What is the audit requirement?
Effective January 1, 2026, the California Privacy Protection Agency (CPPA) adopted regulations requiring that applicable businesses must complete an annual cybersecurity audit and certify its completion with the agency.
Who must comply?
A business must complete an annual cybersecurity audit if its processing of personal information presents a "significant risk" to consumers’ security. A business meets that standard if it either derives 50% or more of its annual revenue from selling or sharing personal information or had an annual gross revenue in the preceding calendar year above the CCPA’s $25 million threshold (as adjusted for inflation) and, in that same year, processed the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more consumers.
When is the first audit due?
Certification deadlines depend on a company’s annual gross revenue. In making this determination, the CPPA cited an expectation that larger businesses would be better able to bear the costs of earlier compliance.
- More than $100 million: first certification due April 1, 2028, covering calendar year 2027.
- $50 million to $100 million: first certification due April 1, 2029, covering calendar year 2028.
- Less than $50 million: first certification due April 1, 2030, covering calendar year 2029.
After the first audit, each audit covers a full calendar year and is due April 1 of the following year.
What must the audit cover?
The audit must assess how the company’s cybersecurity program protects personal information from unauthorized access, destruction, use, modification, or disclosure, as well as loss of availability. It must evaluate 18 aspects of the program, as applicable, including authentication and access controls, encryption, asset and data inventories, vulnerability and patch management, monitoring and logging, employee training, vendor oversight, incident response, and business continuity and disaster recovery.
The audit report must identify the criteria and evidence the auditor relied on, describe how each component is implemented and how effective it is, and detail any gaps or weaknesses along with the company’s plan and timeline to address them. It must also include copies or descriptions of any data breach notifications made to consumers or California regulators during the audit period.
Who can complete the audit?
The audit must be completed by a qualified, objective, and independent auditor using accepted professional standards, such as those issued by the AICPA, PCAOB, ISACA, or ISO. Findings must rest primarily on specific evidence, such as documents, testing, and interviews, rather than on management assertions.
Businesses may use internal auditors, but, importantly, an internal auditor cannot participate in activities they may later audit, such as building or maintaining the cybersecurity program. The highest-ranking internal auditor must also report to, and be evaluated and compensated by, an executive who does not have direct responsibility for the cybersecurity program. These requirements may limit the ability of many companies to rely on personnel involved in designing, operating, or overseeing the cybersecurity program.
How can businesses ease the compliance burden?
- Companies can leverage existing audits: In response to significant public comment, the CPPA confirmed existing audits may satisfy the California requirement. Businesses may rely on audits prepared for other purposes, such as an assessment under the NIST Cybersecurity Framework 2.0, if they meet the regulatory requirements on their own or with supplementation.
- The report stays internal: Businesses do not file the audit report with the CPPA. Rather, the report must be shared with an executive with direct responsibility for the cybersecurity program, and the business then must submit a written certification signed by a member of executive management who is responsible for audit compliance and has sufficient knowledge of the audit. Businesses must retain all relevant audit documents for at least five years.
- Controls are not mandated: While the audit must assess each of the applicable eighteen components described above, businesses retain flexibility in whether and how to implement particular controls.
What should businesses do now?
The audit evaluates an entire calendar year, so timing matters. Businesses that wait until 2028 to assess audit readiness may discover that important evidence, testing, documentation, or governance processes were not collected during the period under review. Once the audit period closes, some deficiencies may be difficult to correct retroactively.
- Confirm applicability and timing: Determine whether the business meets the audit thresholds and which revenue tier, and therefore which audit period, applies.
- Map existing audits against the requirements: Compare the scope and timing of current security audits against the eighteen components and the required audit period. For businesses in the first tier, the audit must cover calendar year 2027.
- Close the gaps: Decide whether internal or external resources should address any gaps, keeping the independence requirements in mind when assessing internal capabilities.
- Assign executive ownership: Identify the executive who will receive the report and the executive who will sign the certification, and, if internal resources will be used, build reporting lines that preserve auditor independence.
For more information, please contact us or your regular Parker Poe contact. Click here to subscribe to our latest alerts and insights.