Back to the hub

Does my business need a CCPA cybersecurity audit?

Only if your processing presents significant risk under 11 CCR section 7120(b): you derive 50 percent or more of revenue from selling or sharing personal information, or you meet the revenue threshold and processed 250,000 consumers or households, or 50,000 consumers' sensitive personal information, in the preceding year.

Applies to: Businesses covered by the CCPA whose processing meets one of the significant-risk conditions in 11 CCR section 7120(b), which must complete an annual cybersecurity audit by an independent auditor.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Most California businesses will never owe a CCPA cybersecurity audit. The ones that do are a defined set, and the definition is arithmetic rather than judgment. The California Office of Administrative Law approved the cybersecurity audit regulations on September 22, 2025, and they took effect on January 1, 2026. This page is the threshold test and the timetable.

Who has to complete a cybersecurity audit?

Section 7120(a) states that every business whose processing of consumers' personal information presents significant risk to consumers' security must complete a cybersecurity audit. Section 7120(b) then defines significant risk, and it is a closed list of two routes.

The first route, at 7120(b)(1), is the business that meets the threshold in Civil Code section 1798.140(d)(1)(C) in the preceding calendar year. That is the revenue-mix threshold: deriving 50 percent or more of annual revenue from selling or sharing consumers' personal information. Data brokers and ad-tech businesses land here regardless of size.

The second route, at 7120(b)(2), needs two things to be true. The business meets the threshold in Civil Code section 1798.140(d)(1)(A), the annual gross revenue figure, and then either processed the personal information of 250,000 or more consumers or households in the preceding calendar year, under (b)(2)(A), or processed the sensitive personal information of 50,000 or more consumers, under (b)(2)(B).

Read the second route carefully. The volume counts are much higher than the CCPA's own 100,000-consumer threshold for being a business at all. A company can be squarely covered by the CCPA and still owe no cybersecurity audit.

When is the first audit due?

Section 7121(a) sets three staggered first deadlines keyed to revenue, and each one covers a full 12-month audit period rather than a point in time.

A business whose annual gross revenue for 2026 was more than one hundred million dollars as of January 1, 2027 must complete its first cybersecurity audit report no later than April 1, 2028, covering January 1, 2027 through January 1, 2028. A business whose 2027 revenue was between fifty million and one hundred million dollars as of January 1, 2028 reports by April 1, 2029, covering January 1, 2028 through January 1, 2029. A business whose 2028 revenue was less than fifty million dollars reports by April 1, 2030, covering January 1, 2029 through January 1, 2030.

After April 1, 2030 the regulation switches to a rolling annual test. Under 7121(b), if on January 1 of one year a business meets the section 7120 criteria for the preceding year, it must complete an audit covering the next 12 months and complete the report by April 1 of the following year.

The practical consequence is that the audit period starts more than a year before the report is due. A business in the smallest band that waits until 2030 to think about this will have already lived through the period being audited.

Who is allowed to do the audit?

Section 7122(a) requires a qualified, objective, independent professional, using procedures and standards accepted in the profession of auditing. The regulation gives examples of qualifying standards bodies: the American Institute of Certified Public Accountants, the Public Company Accountability Oversight Board, the Information Systems Audit and Control Association, and the International Organization for Standardization.

That rules out a self-certification signed by the head of engineering. It does not require a Big Four firm. Independence and recognized methodology are what the provision asks for, and a smaller specialist auditor that works to ISACA or ISO standards satisfies it.

How this sits with the risk assessment duty

The cybersecurity audit and the risk assessment are separate obligations with separate triggers, separate timetables, and separate thresholds. A business can owe one and not the other. Risk assessments are triggered by what you do with data, such as selling or sharing it or processing sensitive personal information. The cybersecurity audit is triggered by revenue mix or by scale. Check both tests independently rather than assuming the answer carries across.

Next step

If you are not sure whether you cross the section 7120(b) thresholds, the free 2-minute Obligation Scan works out which California duties reach your business and what each one requires. The US state privacy law hub sets the rest of the CCPA picture in order.

Compliance checklist

  • Work out whether you cross section 7120(b)(1): 50 percent or more of annual revenue from selling or sharing personal information, the Civil Code 1798.140(d)(1)(C) threshold.
  • If not, check section 7120(b)(2): the 1798.140(d)(1)(A) revenue threshold plus either 250,000 consumers or households, or 50,000 consumers' sensitive personal information, in the preceding calendar year.
  • Place yourself in the right section 7121(a) revenue band so you know whether your first report is due April 1, 2028, 2029 or 2030.
  • Line up a qualified, objective, independent auditor now, because section 7122(a) will not accept a self-assessment.
  • Budget for the audit period, not just the report date: each deadline covers a full 12 months of activity that starts the January before it.

Sources

Last verified: 2026-09-15

Informational, not legal advice.