Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

CCPA & CPRA Compliance Guide: Cybersecurity Audits & Reasonable Security

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), requires every covered business to use reasonable security procedures and practices to protect personal information. Since January 1, 2026, CCPA also require businesses whose processing presents significant risk to complete an annual, independent cybersecurity audit and to have an executive certify its completion to the California Privacy Protection Agency (CalPrivacy). The first CCPA-relevant attestations are due April 1, 2028.

The annual CCPA cybersecurity audit is prescriptive. CCPA cybersecurity audits cover up to 18 named cybersecurity program components, follows strict independence rules and produces a report with specific contents. NIST CSF 2.0 and ISO 27001/27002 are strong foundations, but neither was written for the CCPA, so relying on them takes significant supplementation. ComplianceForge recommends the Secure Controls Framework (SCF) as the control set for CCPA cybersecurity compliance, with independent assessment through the Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) ecosystem, so the executive who signs has third-party evidence behind the certification.

Key Takeaways

CCPA & CPRA Cybersecurity At A Glance

What CISOs And Executives Need To Know
  • Who: For-profit businesses that do business in California and, in the preceding calendar year, had more than $26,625,000 in annual gross revenue (as adjusted January 1, 2025), or that buy, sell or share the personal information of 100,000 or more consumers or households, or that derive 50% or more of annual revenue from selling or sharing personal information (Cal. Civ. Code § 1798.140(d)).
  • Reasonable security: Every covered business must implement reasonable security procedures and practices appropriate to the nature of the personal information it collects (§ 1798.100(e)).
  • Cybersecurity audits: Since January 1, 2026, businesses whose processing presents significant risk to consumers' security must complete an annual cybersecurity audit performed by a qualified, objective and independent auditor (11 CCR §§ 7120 through 7123).
  • Deadlines: The first attestations are due April 1, 2028 (2026 revenue over $100 million), April 1, 2029 ($50 million to $100 million) and April 1, 2030 (under $50 million), then every April 1 (§ 7121).
  • Signature: A member of executive management (e.g., CISO, CIO, CEO) submits the certification to the California Privacy Protection Agency (CalPrivacy) under penalty of perjury (§ 7124).
  • Frameworks: An audit built on NIST CSF 2.0 or ISO 27001 can be used only if it meets every Article 9 requirement, on its own or with supplemental work.
  • Recommendation: ComplianceForge recommends the Secure Controls Framework (SCF), which publishes a Set Theory Relationship Mapping (STRM) for the CCPA as amended by the CPRA.
Why Should I Care?

Executive Accountability: The Cybersecurity Audit Certification

If your business must complete a cybersecurity audit, a member of your executive management team must submit a certification of completion to CalPrivacy through its website by April 1 following each audit year (11 CCR § 7124). The signer must be directly responsible for the business's cybersecurity audit compliance, have enough knowledge of the audit to provide accurate information and have the authority to submit the certification.

The certification is signed under penalty of perjury. Only the certification is submitted, not the audit report, but the report and the documents behind it must be kept for five years after the certification is submitted, and regulators and litigants may seek them after an incident.

That is why the quality and independence of the audit matter as much as the controls. Our readiness program helps you build the documented, SCF-based evidence an independent auditor needs, so the executive who signs has a defensible basis for doing so.

Who Signs

A member of executive management who is directly responsible for cybersecurity audit compliance, knows the audit well enough to provide accurate information and has the authority to submit the certification (§ 7124).

Legal Exposure Beyond CalPrivacy

A certification signed under penalty of perjury without a credible audit behind it is a CCPA problem first.

Officers may also face exposure under other California laws, such as the California False Claims Act, depending on how a certification is used. How those laws apply to your business is a question for your legal counsel.

Under Penalty Of Perjury

The certification of completion is signed under penalty of perjury and filed with CalPrivacy by April 1 for each year an audit is required (§ 7124).

5-Year Retention

Keep the audit report and the documents that support it for five years after you submit the certification (Article 9).

Evidence, Not Assertions

Audit findings must rest on specific evidence the auditor examined, not primarily on assertions or attestations by management (Article 9).

11 CCR § 7124: Certification Of Completion

For each year a cybersecurity audit is required, a qualified member of executive management submits a written certification of completion to CalPrivacy, through its website, no later than April 1 of the following year.

California Consumer Privacy Act

What Are The CCPA And CPRA?

The California Consumer Privacy Act (CCPA) took effect on January 1, 2020. Voters approved the California Privacy Rights Act (CPRA) as Proposition 24 in November 2020, and most of its amendments took effect on January 1, 2023. The CPRA created the California Privacy Protection Agency, which now operates as CalPrivacy, gave it rulemaking and enforcement authority and directed it to adopt regulations on cybersecurity audits, risk assessments and automated decisionmaking technology (ADMT).

The CCPA is often treated as a privacy law, but it carries direct cybersecurity obligations: reasonable security for every covered business (§ 1798.100(e)), a private right of action for certain data breaches (§ 1798.150) and, since January 1, 2026, regulations that require annual cybersecurity audits for businesses whose processing presents significant risk.

Consumer Rights Under The CCPA
  • Right to know and access the personal information a business collects, including a portable copy
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information
  • Right to limit the use and disclosure of sensitive personal information
  • Right not to be retaliated against for exercising these rights
  • Rights related to ADMT used for significant decisions, starting January 1, 2027

Does The CCPA Apply To Your Business?

The CCPA applies to a for-profit business that does business in California and meets any one of these thresholds (§ 1798.140(d)):

  • More than $26,625,000 in annual gross revenue in the preceding calendar year (as adjusted January 1, 2025)
  • Annually buys, sells or shares the personal information of 100,000 or more consumers or households
  • Derives 50% or more of annual revenue from selling or sharing personal information

Since January 1, 2023, the personal information of employees, job applicants and business contacts is fully covered.

What Changed On January 1, 2026

New CCPA regulations added three major obligations and a filing timeline:

  • Annual cybersecurity audits for businesses whose processing presents significant risk (Article 9)
  • Risk assessments before processing that presents significant risk to privacy, with existing processing assessed by December 31, 2027 (Article 10)
  • ADMT requirements for significant decisions, starting January 1, 2027
  • First audit certifications and risk assessment submissions due April 1, 2028
CCPA Regulations

Article 9: CCPA Cybersecurity Audit Requirements

Article 9 of the CCPA regulations (11 CCR §§ 7120 through 7124) turns reasonable security into an annual, documented and independent audit. These are binding requirements with defined applicability, timing, independence, scope and certification rules. Our readiness program is organized around each of them.

§ 7120: Who Must Complete An Audit

A business whose processing of personal information presents significant risk to consumers' security, which means it:

  • Derived 50% or more of its annual revenue from selling or sharing personal information in the preceding calendar year, or
  • Met the CCPA revenue threshold in the preceding calendar year and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers

§ 7121: When The Audit Is Due

Each audit covers a calendar year. The first certification is due April 1, 2028 for businesses with more than $100 million in 2026 revenue (covering 2027), April 1, 2029 for $50 million to $100 million in 2027 revenue and April 1, 2030 for under $50 million in 2028 revenue. After that, a certification is due every April 1.

§ 7122: Thoroughness And Independence

The auditor must be a qualified, objective and independent professional using procedures and standards accepted in the profession of auditing. Internal auditors are allowed if the highest-ranking auditor reports to an executive who is not directly responsible for the cybersecurity program. The auditor must not take part in the activities it may assess, such as developing procedures, preparing the business's documents, or recommending, implementing or maintaining the program.

§ 7123: Scope And Audit Report

The audit assesses how the cybersecurity program protects personal information from unauthorized access, destruction, use, modification or disclosure, across up to 18 named components (see the list). The report must describe what was assessed and the evidence examined, identify gaps and weaknesses, document remediation plans, include breach notification records where applicable and include the auditor's signed statement of independence.

§ 7124: Certification Of Completion

A qualified member of executive management submits a certification of completion to CalPrivacy by April 1, signed under penalty of perjury. The audit report itself is not submitted but must be retained.

Audits Prepared For Another Purpose

You may rely on a cybersecurity audit, assessment or evaluation prepared for another purpose, such as one based on NIST CSF 2.0, only if it meets every Article 9 requirement, on its own or with supplementation.

Article 10 Risk Assessments And Automated Decision Making Technology (ADMT)

Separate from the cybersecurity audit, the regulations require a risk assessment before processing that presents significant risk to consumers' privacy, including selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision and certain uses of automated processing to infer characteristics or to train ADMT. Processing that began before 2026 must be assessed by December 31, 2027, and the first submissions to CalPrivacy are due April 1, 2028. Risk assessments must be kept for the longer of five years or the duration of the processing. ADMT requirements for significant decisions apply from January 1, 2027.

NIST CSF 2.0 vs ISO 27001 vs CCPA

Why NIST CSF 2.0 And ISO 27001/27002 Aren't Enough For The CCPA

NIST CSF 2.0 and ISO 27001/27002 are not sufficient on their own for CCPA cybersecurity compliance. The Article 9 rules let you rely on an audit prepared for another purpose, such as one based on NIST CSF 2.0, but only if it meets every Article 9 requirement, on its own or with supplementation. NIST says the CSF "does not prescribe how outcomes should be achieved," and ISO 27001 leaves control selection to your risk assessment and Statement of Applicability. To use either one for the CCPA, you have to add and track the CCPA-specific requirements yourself.

Where the CCPA cybersecurity audit is specific and the general frameworks are not:

CCPA Requirement
NIST CSF 2.0
ISO 27001:2022
Independent annual audit: a qualified, objective and independent auditor whose findings rest on evidence, not management assertions (§§ 7120 through 7122)
No audit or auditor independence requirement.
Certification audits cover the ISMS scope you define, which may not include every system that handles personal information.
Authentication: authentication, including multi-factor authentication, is a named audit component (§ 7123)
PR.AA-03: "Users, services, and hardware are authenticated." The method is up to you.
Annex A 8.5 (secure authentication) leaves the method to your risk assessment.
Encryption: encryption of personal information at rest and in transit is a named audit component (§ 7123)
PR.DS-01 and PR.DS-02 protect data at rest and in transit, without requiring encryption.
Annex A 8.24 (use of cryptography) applies where your risk assessment selects it.
Personal information inventory and retention: inventory and management of personal information, retention schedules and disposal are audit components, and CCPA notices must disclose retention periods (§ 1798.100(a)(3))
ID.AM-07 (inventories of data for designated data types) and ID.AM-08 (life cycle management), with nothing specific to personal information.
Annex A 5.9 (inventory), 5.34 (privacy and protection of PII) and 8.10 (information deletion), scoped by your Statement of Applicability.
Network controls: segmentation, limiting ports, services and protocols, and network monitoring and defenses are separate audit components (§ 7123)
Outcomes such as DE.CM-01 (network monitoring), with specific techniques left to you.
Annex A network controls (8.20 to 8.22) are selected through your risk assessment.
Audit report content: gaps, remediation plans, breach notification records and a signed auditor independence statement (§ 7123)
No reporting requirement.
Certification body reports follow certification scheme rules, not Article 9 content.
Executive certification: signed under penalty of perjury and submitted to CalPrivacy by April 1 (§ 7124)
No regulatory attestation.
Certificates are issued by certification bodies, not filed with a regulator.
Privacy obligations: consumer requests, opt-outs, risk assessments and ADMT rules
Out of scope. NIST publishes a separate Privacy Framework.
Out of scope. ISO/IEC 27701 is a separate privacy standard.

This is not a knock on either framework. NIST CSF 2.0 is a strong way to organize cybersecurity outcomes, and ISO 27001 is a strong management system. The issue is the gap between what they describe and what the CCPA requires, which means you would build and maintain your own CCPA crosswalk on top of them. Learn more in our NIST CSF 2.0 and ISO 27001/27002 guides.

Best Framework For The CCPA

What Is The Best Cybersecurity Framework For CCPA Compliance?

ComplianceForge recommends the Secure Controls Framework (SCF) as the control framework for CCPA cybersecurity compliance. The SCF is a free metaframework with 1,500+ controls across 34 domains, mapped to 200+ laws, regulations and frameworks, and it publishes a Set Theory Relationship Mapping (STRM) for the CCPA as amended by the CPRA. Based o how the SCF covers cybersecurity and data privacy in one control set, the same controls support your reasonable security obligations, your Article 9 audit and your privacy program.

CCPA Mapped With STRM

The SCF publishes a STRM for the CCPA (January 2026), as amended by the CPRA, based on NIST IR 8477. It maps CCPA statute and regulation requirements to SCF controls with a stated relationship and strength, so you can show an auditor which controls meet which requirement.

The 18 Audit Components, Covered

Each Article 9 audit component lines up with SCF domains, such as Identification & Authentication (IAC), Cryptographic Protections (CRY), Network Security (NET), Vulnerability & Patch Management (VPM), Third-Party Management (TPM) and Business Continuity & Disaster Recovery (BCD), so your auditor can test specific controls instead of broad outcomes.

Security And Privacy In One Control Set

The SCF's Data Privacy (PRI) domain sits alongside its security domains, so consumer rights, notices, retention and data minimization are managed in the same control set as your security program. See our Data Privacy Program (DPP).

CIS Controls Included

The California Attorney General's 2016 Data Breach Report pointed to the CIS Critical Security Controls as a minimum level of information security. The SCF publishes a STRM for CIS Controls v8.1, so you can show that alignment too. See our CIS Controls guide.

Ready For Independent Assessment

Accredited SCR 3PAOs assess SCF controls using a documented methodology, which gives the executive who signs independent evidence. See how it works.

Free To Use

The SCF is free to use under a Creative Commons license, so there is no framework licensing cost to adopt it as your common control set.

How ComplianceForge Uses The SCF

ComplianceForge is an authorized SCF Licensed Content Provider (LCP). Our SCF-based policies and standards (SCRP) and procedures (CSOP) give you editable documentation already aligned to SCF controls, so your evidence traces back to CCPA requirements through the SCF's CCPA STRM. For program-level requirements, pair them with our Data Privacy Program (DPP), Integrated Incident Response Program (IIRP), Vulnerability & Patch Management Program (VPMP), Third-Party Risk Management (TPRM) Program and Continuity Of Operations Plan (COOP).

Independent Assessment

Independent Assurance For The Executive Who Signs

The CCPA cybersecurity audit must be performed by a qualified, objective and independent auditor, and the executive who signs the certification rarely tests every control personally. The Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) ecosystem gives you access to accredited, independent assessors who evaluate SCF controls against a documented methodology.

The SCR CAP does not currently offer a CCPA-specific certification. SCR certifications available today include NIST CSF 2.0 and SCF CORE Fundamentals. An SCR certification is not a CCPA cybersecurity audit and does not replace the § 7124 certification. Because Article 9 lets you rely on an assessment prepared for another purpose when it meets every Article 9 requirement, on its own or with supplementation, an independent SCF-based assessment can be a strong foundation. Confirm with your auditor and legal counsel how any assessment fits your Article 9 audit.

What Article 9 Requires Of The Auditor

Qualified, objective and independent, using accepted auditing standards, with findings based on evidence rather than management assertions. The auditor must not have developed, implemented or maintained what it audits.

Who Performs Independent Assessments

SCR 3PAOs are accredited by The Cyber AB and assess SCF controls under the SCR CAP. You can find accredited 3PAOs in the SCF Marketplace.

Keep Preparation And Audit Separate

ComplianceForge prepares you with documentation and readiness assessments. Because the auditor must not prepare your documents or implement your program, we do not act as your Article 9 auditor.

Why Not Self-Attestation Alone?

Article 9 findings cannot rest primarily on management's own assertions. An independent assessment against a documented methodology is harder to dispute and also helps with cyber insurance underwriting and customer due diligence.

CCPA Security Requirements

CCPA Reasonable Security And The 18 Audit Components

Section 1798.100(e) of the CCPA says: "A business that collects a consumer's personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5."

If nonencrypted and nonredacted personal information is breached because a business failed to implement and maintain reasonable security, affected consumers can sue for statutory damages of $107 to $799 per consumer per incident, or actual damages if greater (§ 1798.150, as adjusted January 1, 2025). Before seeking statutory damages, a consumer must give 30 days' written notice, and implementing reasonable security after a breach does not count as a cure.

The CCPA does not define reasonable security in detail. The California Attorney General's February 2016 Data Breach Report said the CIS Critical Security Controls define a minimum level of information security and that failing to implement all applicable controls constitutes a lack of reasonable security. That report is guidance, not a regulation, but the Article 9 audit components below now give businesses a concrete, regulator-defined list. The auditor determines which components apply based on the size and nature of your processing.

Identity & Access

  • Authentication, including multi-factor authentication
  • Account management and access controls

Data Protection

  • Encryption of personal information at rest and in transit
  • Inventory and management of personal information
  • Retention schedules and proper disposal of personal information

Secure Configuration & Networks

  • Secure configuration of hardware and software
  • Information system segmentation
  • Limiting and controlling ports, services and protocols
  • Network monitoring and defenses
  • Antivirus and anti-malware protections

Testing & Logging

  • Vulnerability scans, penetration testing and vulnerability disclosure programs
  • Audit-log management

People & Development

  • Cybersecurity awareness
  • Cybersecurity education and training
  • Secure development and coding practices

Third Parties & Resilience

  • Oversight of service providers, contractors and third parties
  • Security incident response management
  • Business continuity and disaster recovery plans
Business Risk Management

CCPA Enforcement: Why Non-Compliance Is Not An Option

CCPA enforcement so far has focused on privacy practices such as opt-outs, notices, contracts and data minimization. Cybersecurity audit certifications begin in 2028, and breach litigation under § 1798.150 is available today. Recent actions show the stakes.

Record CCPA Penalties

In May 2026, the California Attorney General, CalPrivacy and four district attorneys announced a $12.75 million settlement with General Motors, described as the largest CCPA penalty to date, over the sale of drivers' location and driving data and violations of the data minimization and purpose limitation rules. In September 2025, CalPrivacy fined Tractor Supply $1.35 million, its largest fine at the time, including for failing to provide an effective opt-out and disclosing personal information without privacy-protective contracts.

Administrative Fines

CalPrivacy can impose administrative fines of up to $2,663 per violation, or $7,988 per intentional violation or violation involving the personal information of consumers the business knows are under 16 (§ 1798.155, as adjusted January 1, 2025). The amounts are adjusted every odd-numbered year.

Data Breach Litigation

A breach of nonencrypted and nonredacted personal information caused by a failure to maintain reasonable security exposes the business to statutory damages of $107 to $799 per consumer per incident (§ 1798.150). Across a large breach, that adds up quickly.

Unsupported Certification Risk

The § 7124 certification is signed under penalty of perjury, and audit findings must rest on evidence, not management assertions. A certification without a credible, independent audit behind it puts the signer and the business at risk.

Vendor & Contract Risk

The CCPA requires contracts with service providers, contractors and third parties that receive personal information (§ 1798.100(d)), and oversight of those parties is an Article 9 audit component. Missing contract terms were part of the Tractor Supply action.

The Audit Clock Is Already Running

For businesses with more than $100 million in 2026 revenue, the first audit covers calendar year 2027 and the certification is due April 1, 2028. Gaps you close now are gaps the auditor will not find.

Our Methodology

Our CCPA Cybersecurity Audit Readiness Process

Our readiness program is structured around Article 9 and the CCPA reasonable security requirements, and aligned to the Secure Controls Framework. ComplianceForge prepares you; the annual cybersecurity audit itself is performed by a qualified, independent auditor. Because we may help prepare your documentation and remediation, we do not act as your Article 9 auditor.

Phase 1

Applicability & Revenue Tier

We confirm whether Article 9 applies, identify your revenue tier and first audit year, and map the systems that process personal information and sensitive personal information.

§ 7120
§ 7121
Phase 2

Gap Assessment Against The 18 Components

We assess each applicable audit component against SCF controls using the CCPA STRM and document why any component does not apply to your processing.

§ 7123
SCF STRM
Phase 3

Reasonable Security & Breach Readiness

We evaluate encryption and redaction of personal information, incident response and California breach notification readiness.

§ 1798.100(e)
§ 1798.150
§ 1798.82
Phase 4

Documentation & Remediation

We implement SCF-based policies, standards and procedures and track remediation of the gaps we find, so your program is documented before the audit period.

SCRP
CSOP
DPP
Phase 5

Independent Auditor Readiness

We organize your evidence and audit scope so a qualified, independent auditor, such as an SCR 3PAO, can test your controls efficiently, and we help you confirm the auditor meets the independence rules.

§ 7122
Phase 6

Certification Support

We help you prepare the executive briefing and supporting records so the person who signs understands the audit results before certifying to CalPrivacy.

§ 7124
April 1
Phase 7

Annual Cycle & Retention

We set up the annual audit cycle, five-year record retention and the review points for risk assessments when your processing changes.

Annual
5 years
Cybersecurity & Privacy Policy Documentation

Editable Policies, Standards & Procedures For The CCPA

An Article 9 auditor will ask for the policies, standards and procedures that govern how personal information is protected day to day. Without them, there is little evidence for the auditor to test and little support for the executive who signs.

ComplianceForge provides professionally written, editable cybersecurity and data privacy documentation mapped to Secure Controls Framework (SCF) controls. Because the SCF maps those controls to the CCPA, your documentation lines up with the same control set used in your readiness assessment and audit, creating a connected evidence chain from policy to practice.

SCF Control Mapping

Every policy, standard and procedure maps to SCF controls, so you do not need to build your own crosswalk to the CCPA or the 18 audit components.

Fully Editable & Customizable

Delivered in editable formats so you can tailor policies to your operating environment, technology stack and organizational structure.

Broad Regulatory Coverage

Covers the CCPA alongside NIST CSF 2.0, ISO 27001, SOC 2 and other laws and frameworks, so one documentation investment supports multiple obligations.

Integrated With Your Readiness Assessment

Documentation is selected and implemented as part of your remediation, directly addressing the gaps found in your readiness assessment.

Documentation Coverage For The CCPA
Ecosystem Partners

The SCR CAP Ecosystem

CCPA readiness and independent assessment involve several separate roles. Knowing who does what helps you keep preparation and audit separate, as Article 9 expects.

The Cyber AB

The Accreditation Body for the SCR CAP. It accredits SCR 3PAOs and oversees conflict-of-interest governance across the program.

SCR Third-Party Assessment Organizations (3PAOs)

Accredited, independent assessors that perform SCR CAP assessments and issue SCR certifications. Find an SCR 3PAO.

RPOs & Implementation Support

Registered Provider Organizations (RPOs) help organizations implement SCF controls and prepare for assessment. Find an RPO. ComplianceForge, an SCF Licensed Content Provider, provides SCF-based documentation and CCPA readiness services.

GRC Platforms

GRC platforms such as SCF Connect, which is built natively for the SCF, and Cyturus help you manage controls, evidence and remediation in one place. See our partners.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about CCPA and CPRA compliance:

Who must comply with the CCPA?
The CCPA applies to for-profit businesses that do business in California and meet at least one threshold: annual gross revenue above $26,625,000 (the inflation-adjusted figure effective January 1, 2025), buying, selling or sharing the personal information of 100,000 or more consumers or households each year, or deriving 50% or more of annual revenue from selling or sharing personal information. The California Privacy Protection Agency adjusts the revenue figure for inflation every odd-numbered year.
What is the difference between the CCPA and the CPRA?
The CPRA is not a separate law but a set of amendments to the CCPA. The CCPA took effect January 1, 2020. California voters approved the California Privacy Rights Act through Proposition 24 in November 2020, and most of its changes took effect January 1, 2023. The CPRA added the right to correct inaccurate personal information and the right to limit use of sensitive personal information, and it created the California Privacy Protection Agency to implement and enforce the law.
Which businesses need a CCPA cybersecurity audit?
Regulations effective January 1, 2026 require an annual cybersecurity audit when a business's processing presents significant risk. That covers businesses that derive 50% or more of annual revenue from selling or sharing personal information, or that meet the CCPA revenue threshold and process the personal information of 250,000 or more consumers or households or the sensitive personal information of 50,000 or more consumers. First certifications are due April 1, 2028, 2029 or 2030 depending on revenue. ComplianceForge provides SCF-aligned policies, standards and procedures, but we don't act as the independent auditor.
What security does the CCPA require for personal information?
Civil Code 1798.100(e) requires a business that collects personal information to implement reasonable security procedures and practices appropriate to the nature of that information. If nonencrypted and nonredacted personal information is breached because of a failure to maintain reasonable security, consumers can seek statutory damages of $107 to $799 per consumer per incident, or actual damages if greater. ComplianceForge's SCF-based policies, standards and procedures map to Secure Controls Framework controls, and the SCF maps those controls to the CCPA.
What are the penalties for violating the CCPA?
The California Privacy Protection Agency can impose administrative fines of up to $2,663 per violation, or up to $7,988 per intentional violation or violation involving consumers known to be under 16, based on adjustments effective January 1, 2025. Enforcement is shared with the California Attorney General, who can bring civil actions. The executive who signs a business's cybersecurity audit certification does so under penalty of perjury, which adds personal exposure.