CCPA & CPRA Cybersecurity At A Glance
- Who: For-profit businesses that do business in California and, in the preceding calendar year, had more than $26,625,000 in annual gross revenue (as adjusted January 1, 2025), or that buy, sell or share the personal information of 100,000 or more consumers or households, or that derive 50% or more of annual revenue from selling or sharing personal information (Cal. Civ. Code § 1798.140(d)).
- Reasonable security: Every covered business must implement reasonable security procedures and practices appropriate to the nature of the personal information it collects (§ 1798.100(e)).
- Cybersecurity audits: Since January 1, 2026, businesses whose processing presents significant risk to consumers' security must complete an annual cybersecurity audit performed by a qualified, objective and independent auditor (11 CCR §§ 7120 through 7123).
- Deadlines: The first attestations are due April 1, 2028 (2026 revenue over $100 million), April 1, 2029 ($50 million to $100 million) and April 1, 2030 (under $50 million), then every April 1 (§ 7121).
- Signature: A member of executive management (e.g., CISO, CIO, CEO) submits the certification to the California Privacy Protection Agency (CalPrivacy) under penalty of perjury (§ 7124).
- Frameworks: An audit built on NIST CSF 2.0 or ISO 27001 can be used only if it meets every Article 9 requirement, on its own or with supplemental work.
- Recommendation: ComplianceForge recommends the Secure Controls Framework (SCF), which publishes a Set Theory Relationship Mapping (STRM) for the CCPA as amended by the CPRA.
Executive Accountability: The Cybersecurity Audit Certification
If your business must complete a cybersecurity audit, a member of your executive management team must submit a certification of completion to CalPrivacy through its website by April 1 following each audit year (11 CCR § 7124). The signer must be directly responsible for the business's cybersecurity audit compliance, have enough knowledge of the audit to provide accurate information and have the authority to submit the certification.
The certification is signed under penalty of perjury. Only the certification is submitted, not the audit report, but the report and the documents behind it must be kept for five years after the certification is submitted, and regulators and litigants may seek them after an incident.
That is why the quality and independence of the audit matter as much as the controls. Our readiness program helps you build the documented, SCF-based evidence an independent auditor needs, so the executive who signs has a defensible basis for doing so.
Who Signs
A member of executive management who is directly responsible for cybersecurity audit compliance, knows the audit well enough to provide accurate information and has the authority to submit the certification (§ 7124).
Legal Exposure Beyond CalPrivacy
A certification signed under penalty of perjury without a credible audit behind it is a CCPA problem first.
Officers may also face exposure under other California laws, such as the California False Claims Act, depending on how a certification is used. How those laws apply to your business is a question for your legal counsel.
Under Penalty Of Perjury
The certification of completion is signed under penalty of perjury and filed with CalPrivacy by April 1 for each year an audit is required (§ 7124).
5-Year Retention
Keep the audit report and the documents that support it for five years after you submit the certification (Article 9).
Evidence, Not Assertions
Audit findings must rest on specific evidence the auditor examined, not primarily on assertions or attestations by management (Article 9).
For each year a cybersecurity audit is required, a qualified member of executive management submits a written certification of completion to CalPrivacy, through its website, no later than April 1 of the following year.
What Are The CCPA And CPRA?
The California Consumer Privacy Act (CCPA) took effect on January 1, 2020. Voters approved the California Privacy Rights Act (CPRA) as Proposition 24 in November 2020, and most of its amendments took effect on January 1, 2023. The CPRA created the California Privacy Protection Agency, which now operates as CalPrivacy, gave it rulemaking and enforcement authority and directed it to adopt regulations on cybersecurity audits, risk assessments and automated decisionmaking technology (ADMT).
The CCPA is often treated as a privacy law, but it carries direct cybersecurity obligations: reasonable security for every covered business (§ 1798.100(e)), a private right of action for certain data breaches (§ 1798.150) and, since January 1, 2026, regulations that require annual cybersecurity audits for businesses whose processing presents significant risk.
- Right to know and access the personal information a business collects, including a portable copy
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use and disclosure of sensitive personal information
- Right not to be retaliated against for exercising these rights
- Rights related to ADMT used for significant decisions, starting January 1, 2027
Does The CCPA Apply To Your Business?
The CCPA applies to a for-profit business that does business in California and meets any one of these thresholds (§ 1798.140(d)):
- More than $26,625,000 in annual gross revenue in the preceding calendar year (as adjusted January 1, 2025)
- Annually buys, sells or shares the personal information of 100,000 or more consumers or households
- Derives 50% or more of annual revenue from selling or sharing personal information
Since January 1, 2023, the personal information of employees, job applicants and business contacts is fully covered.
What Changed On January 1, 2026
New CCPA regulations added three major obligations and a filing timeline:
- Annual cybersecurity audits for businesses whose processing presents significant risk (Article 9)
- Risk assessments before processing that presents significant risk to privacy, with existing processing assessed by December 31, 2027 (Article 10)
- ADMT requirements for significant decisions, starting January 1, 2027
- First audit certifications and risk assessment submissions due April 1, 2028
Article 9: CCPA Cybersecurity Audit Requirements
Article 9 of the CCPA regulations (11 CCR §§ 7120 through 7124) turns reasonable security into an annual, documented and independent audit. These are binding requirements with defined applicability, timing, independence, scope and certification rules. Our readiness program is organized around each of them.
§ 7120: Who Must Complete An Audit
A business whose processing of personal information presents significant risk to consumers' security, which means it:
- Derived 50% or more of its annual revenue from selling or sharing personal information in the preceding calendar year, or
- Met the CCPA revenue threshold in the preceding calendar year and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers
§ 7121: When The Audit Is Due
Each audit covers a calendar year. The first certification is due April 1, 2028 for businesses with more than $100 million in 2026 revenue (covering 2027), April 1, 2029 for $50 million to $100 million in 2027 revenue and April 1, 2030 for under $50 million in 2028 revenue. After that, a certification is due every April 1.
§ 7122: Thoroughness And Independence
The auditor must be a qualified, objective and independent professional using procedures and standards accepted in the profession of auditing. Internal auditors are allowed if the highest-ranking auditor reports to an executive who is not directly responsible for the cybersecurity program. The auditor must not take part in the activities it may assess, such as developing procedures, preparing the business's documents, or recommending, implementing or maintaining the program.
§ 7123: Scope And Audit Report
The audit assesses how the cybersecurity program protects personal information from unauthorized access, destruction, use, modification or disclosure, across up to 18 named components (see the list). The report must describe what was assessed and the evidence examined, identify gaps and weaknesses, document remediation plans, include breach notification records where applicable and include the auditor's signed statement of independence.
§ 7124: Certification Of Completion
A qualified member of executive management submits a certification of completion to CalPrivacy by April 1, signed under penalty of perjury. The audit report itself is not submitted but must be retained.
Audits Prepared For Another Purpose
You may rely on a cybersecurity audit, assessment or evaluation prepared for another purpose, such as one based on NIST CSF 2.0, only if it meets every Article 9 requirement, on its own or with supplementation.
Separate from the cybersecurity audit, the regulations require a risk assessment before processing that presents significant risk to consumers' privacy, including selling or sharing personal information, processing sensitive personal information, using ADMT for a significant decision and certain uses of automated processing to infer characteristics or to train ADMT. Processing that began before 2026 must be assessed by December 31, 2027, and the first submissions to CalPrivacy are due April 1, 2028. Risk assessments must be kept for the longer of five years or the duration of the processing. ADMT requirements for significant decisions apply from January 1, 2027.
Why NIST CSF 2.0 And ISO 27001/27002 Aren't Enough For The CCPA
NIST CSF 2.0 and ISO 27001/27002 are not sufficient on their own for CCPA cybersecurity compliance. The Article 9 rules let you rely on an audit prepared for another purpose, such as one based on NIST CSF 2.0, but only if it meets every Article 9 requirement, on its own or with supplementation. NIST says the CSF "does not prescribe how outcomes should be achieved," and ISO 27001 leaves control selection to your risk assessment and Statement of Applicability. To use either one for the CCPA, you have to add and track the CCPA-specific requirements yourself.
Where the CCPA cybersecurity audit is specific and the general frameworks are not:
This is not a knock on either framework. NIST CSF 2.0 is a strong way to organize cybersecurity outcomes, and ISO 27001 is a strong management system. The issue is the gap between what they describe and what the CCPA requires, which means you would build and maintain your own CCPA crosswalk on top of them. Learn more in our NIST CSF 2.0 and ISO 27001/27002 guides.
What Is The Best Cybersecurity Framework For CCPA Compliance?
ComplianceForge recommends the Secure Controls Framework (SCF) as the control framework for CCPA cybersecurity compliance. The SCF is a free metaframework with 1,500+ controls across 34 domains, mapped to 200+ laws, regulations and frameworks, and it publishes a Set Theory Relationship Mapping (STRM) for the CCPA as amended by the CPRA. Based o how the SCF covers cybersecurity and data privacy in one control set, the same controls support your reasonable security obligations, your Article 9 audit and your privacy program.
CCPA Mapped With STRM
The SCF publishes a STRM for the CCPA (January 2026), as amended by the CPRA, based on NIST IR 8477. It maps CCPA statute and regulation requirements to SCF controls with a stated relationship and strength, so you can show an auditor which controls meet which requirement.
The 18 Audit Components, Covered
Each Article 9 audit component lines up with SCF domains, such as Identification & Authentication (IAC), Cryptographic Protections (CRY), Network Security (NET), Vulnerability & Patch Management (VPM), Third-Party Management (TPM) and Business Continuity & Disaster Recovery (BCD), so your auditor can test specific controls instead of broad outcomes.
Security And Privacy In One Control Set
The SCF's Data Privacy (PRI) domain sits alongside its security domains, so consumer rights, notices, retention and data minimization are managed in the same control set as your security program. See our Data Privacy Program (DPP).
CIS Controls Included
The California Attorney General's 2016 Data Breach Report pointed to the CIS Critical Security Controls as a minimum level of information security. The SCF publishes a STRM for CIS Controls v8.1, so you can show that alignment too. See our CIS Controls guide.
Ready For Independent Assessment
Accredited SCR 3PAOs assess SCF controls using a documented methodology, which gives the executive who signs independent evidence. See how it works.
Free To Use
The SCF is free to use under a Creative Commons license, so there is no framework licensing cost to adopt it as your common control set.
ComplianceForge is an authorized SCF Licensed Content Provider (LCP). Our SCF-based policies and standards (SCRP) and procedures (CSOP) give you editable documentation already aligned to SCF controls, so your evidence traces back to CCPA requirements through the SCF's CCPA STRM. For program-level requirements, pair them with our Data Privacy Program (DPP), Integrated Incident Response Program (IIRP), Vulnerability & Patch Management Program (VPMP), Third-Party Risk Management (TPRM) Program and Continuity Of Operations Plan (COOP).
Independent Assurance For The Executive Who Signs
The CCPA cybersecurity audit must be performed by a qualified, objective and independent auditor, and the executive who signs the certification rarely tests every control personally. The Secure, Compliant & Resilient Conformity Assessment Program (SCR CAP) ecosystem gives you access to accredited, independent assessors who evaluate SCF controls against a documented methodology.
The SCR CAP does not currently offer a CCPA-specific certification. SCR certifications available today include NIST CSF 2.0 and SCF CORE Fundamentals. An SCR certification is not a CCPA cybersecurity audit and does not replace the § 7124 certification. Because Article 9 lets you rely on an assessment prepared for another purpose when it meets every Article 9 requirement, on its own or with supplementation, an independent SCF-based assessment can be a strong foundation. Confirm with your auditor and legal counsel how any assessment fits your Article 9 audit.
What Article 9 Requires Of The Auditor
Qualified, objective and independent, using accepted auditing standards, with findings based on evidence rather than management assertions. The auditor must not have developed, implemented or maintained what it audits.
Who Performs Independent Assessments
SCR 3PAOs are accredited by The Cyber AB and assess SCF controls under the SCR CAP. You can find accredited 3PAOs in the SCF Marketplace.
Keep Preparation And Audit Separate
ComplianceForge prepares you with documentation and readiness assessments. Because the auditor must not prepare your documents or implement your program, we do not act as your Article 9 auditor.
Why Not Self-Attestation Alone?
Article 9 findings cannot rest primarily on management's own assertions. An independent assessment against a documented methodology is harder to dispute and also helps with cyber insurance underwriting and customer due diligence.
CCPA Reasonable Security And The 18 Audit Components
Section 1798.100(e) of the CCPA says: "A business that collects a consumer's personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5."
If nonencrypted and nonredacted personal information is breached because a business failed to implement and maintain reasonable security, affected consumers can sue for statutory damages of $107 to $799 per consumer per incident, or actual damages if greater (§ 1798.150, as adjusted January 1, 2025). Before seeking statutory damages, a consumer must give 30 days' written notice, and implementing reasonable security after a breach does not count as a cure.
The CCPA does not define reasonable security in detail. The California Attorney General's February 2016 Data Breach Report said the CIS Critical Security Controls define a minimum level of information security and that failing to implement all applicable controls constitutes a lack of reasonable security. That report is guidance, not a regulation, but the Article 9 audit components below now give businesses a concrete, regulator-defined list. The auditor determines which components apply based on the size and nature of your processing.
Identity & Access
- Authentication, including multi-factor authentication
- Account management and access controls
Data Protection
- Encryption of personal information at rest and in transit
- Inventory and management of personal information
- Retention schedules and proper disposal of personal information
Secure Configuration & Networks
- Secure configuration of hardware and software
- Information system segmentation
- Limiting and controlling ports, services and protocols
- Network monitoring and defenses
- Antivirus and anti-malware protections
Testing & Logging
- Vulnerability scans, penetration testing and vulnerability disclosure programs
- Audit-log management
People & Development
- Cybersecurity awareness
- Cybersecurity education and training
- Secure development and coding practices
Third Parties & Resilience
- Oversight of service providers, contractors and third parties
- Security incident response management
- Business continuity and disaster recovery plans
CCPA Enforcement: Why Non-Compliance Is Not An Option
CCPA enforcement so far has focused on privacy practices such as opt-outs, notices, contracts and data minimization. Cybersecurity audit certifications begin in 2028, and breach litigation under § 1798.150 is available today. Recent actions show the stakes.
Record CCPA Penalties
In May 2026, the California Attorney General, CalPrivacy and four district attorneys announced a $12.75 million settlement with General Motors, described as the largest CCPA penalty to date, over the sale of drivers' location and driving data and violations of the data minimization and purpose limitation rules. In September 2025, CalPrivacy fined Tractor Supply $1.35 million, its largest fine at the time, including for failing to provide an effective opt-out and disclosing personal information without privacy-protective contracts.
Administrative Fines
CalPrivacy can impose administrative fines of up to $2,663 per violation, or $7,988 per intentional violation or violation involving the personal information of consumers the business knows are under 16 (§ 1798.155, as adjusted January 1, 2025). The amounts are adjusted every odd-numbered year.
Data Breach Litigation
A breach of nonencrypted and nonredacted personal information caused by a failure to maintain reasonable security exposes the business to statutory damages of $107 to $799 per consumer per incident (§ 1798.150). Across a large breach, that adds up quickly.
Unsupported Certification Risk
The § 7124 certification is signed under penalty of perjury, and audit findings must rest on evidence, not management assertions. A certification without a credible, independent audit behind it puts the signer and the business at risk.
Vendor & Contract Risk
The CCPA requires contracts with service providers, contractors and third parties that receive personal information (§ 1798.100(d)), and oversight of those parties is an Article 9 audit component. Missing contract terms were part of the Tractor Supply action.
The Audit Clock Is Already Running
For businesses with more than $100 million in 2026 revenue, the first audit covers calendar year 2027 and the certification is due April 1, 2028. Gaps you close now are gaps the auditor will not find.
Our CCPA Cybersecurity Audit Readiness Process
Our readiness program is structured around Article 9 and the CCPA reasonable security requirements, and aligned to the Secure Controls Framework. ComplianceForge prepares you; the annual cybersecurity audit itself is performed by a qualified, independent auditor. Because we may help prepare your documentation and remediation, we do not act as your Article 9 auditor.
Applicability & Revenue Tier
We confirm whether Article 9 applies, identify your revenue tier and first audit year, and map the systems that process personal information and sensitive personal information.
Gap Assessment Against The 18 Components
We assess each applicable audit component against SCF controls using the CCPA STRM and document why any component does not apply to your processing.
Reasonable Security & Breach Readiness
We evaluate encryption and redaction of personal information, incident response and California breach notification readiness.
Documentation & Remediation
We implement SCF-based policies, standards and procedures and track remediation of the gaps we find, so your program is documented before the audit period.
Independent Auditor Readiness
We organize your evidence and audit scope so a qualified, independent auditor, such as an SCR 3PAO, can test your controls efficiently, and we help you confirm the auditor meets the independence rules.
Certification Support
We help you prepare the executive briefing and supporting records so the person who signs understands the audit results before certifying to CalPrivacy.
Annual Cycle & Retention
We set up the annual audit cycle, five-year record retention and the review points for risk assessments when your processing changes.
Editable Policies, Standards & Procedures For The CCPA
An Article 9 auditor will ask for the policies, standards and procedures that govern how personal information is protected day to day. Without them, there is little evidence for the auditor to test and little support for the executive who signs.
ComplianceForge provides professionally written, editable cybersecurity and data privacy documentation mapped to Secure Controls Framework (SCF) controls. Because the SCF maps those controls to the CCPA, your documentation lines up with the same control set used in your readiness assessment and audit, creating a connected evidence chain from policy to practice.
SCF Control Mapping
Every policy, standard and procedure maps to SCF controls, so you do not need to build your own crosswalk to the CCPA or the 18 audit components.
Fully Editable & Customizable
Delivered in editable formats so you can tailor policies to your operating environment, technology stack and organizational structure.
Broad Regulatory Coverage
Covers the CCPA alongside NIST CSF 2.0, ISO 27001, SOC 2 and other laws and frameworks, so one documentation investment supports multiple obligations.
Integrated With Your Readiness Assessment
Documentation is selected and implemented as part of your remediation, directly addressing the gaps found in your readiness assessment.
- SCF Policies & Standards (SCRP): cybersecurity and privacy policies and standards (reasonable security, § 1798.100(e))
- SCF Procedures (CSOP): control procedures, including account management and access controls
- Data Privacy Program (DPP): privacy program documentation
- Integrated Incident Response Program (IIRP): incident response and breach notification (§ 1798.82)
- Vulnerability & Patch Management Program (VPMP): vulnerability scans and penetration testing
- Third-Party Risk Management (TPRM) Program: oversight of service providers, contractors and third parties
- Continuity Of Operations Plan (COOP): business continuity and disaster recovery
The SCR CAP Ecosystem
CCPA readiness and independent assessment involve several separate roles. Knowing who does what helps you keep preparation and audit separate, as Article 9 expects.
The Cyber AB
The Accreditation Body for the SCR CAP. It accredits SCR 3PAOs and oversees conflict-of-interest governance across the program.
SCR Third-Party Assessment Organizations (3PAOs)
Accredited, independent assessors that perform SCR CAP assessments and issue SCR certifications. Find an SCR 3PAO.
RPOs & Implementation Support
Registered Provider Organizations (RPOs) help organizations implement SCF controls and prepare for assessment. Find an RPO. ComplianceForge, an SCF Licensed Content Provider, provides SCF-based documentation and CCPA readiness services.
GRC Platforms
GRC platforms such as SCF Connect, which is built natively for the SCF, and Cyturus help you manage controls, evidence and remediation in one place. See our partners.
Frequently-Asked Questions
Here are answers to common questions about CCPA and CPRA compliance:
