Most of the attention on California's new privacy regulations has gone to automated decisions, because that is the part with a January 2027 date on it. Sitting alongside it is a second obligation that far more companies will trip over, for an unhelpful reason: the year that decides your deadline is 2026, which is already most of the way through.
If your business is covered, you will owe an independent cybersecurity audit, and which April you owe it by was determined by revenue you are earning right now.
This is a builder's read of the requirement, not legal advice. Your counsel decides whether you are in scope. This is what to have ready once they tell you.
Which April is yours
The phase-in keys off gross revenue for 2026, not for the year the audit is due.
| First audit due | If 2026 gross revenue was |
|---|---|
| 1 April 2028 | Over $100 million |
| 1 April 2029 | $50 million to $100 million |
| 1 April 2030 | Under $50 million |
Two things follow that people miss. A company that crosses $100 million during 2026 has bought itself the earliest deadline, even if revenue later falls. And 2028 sounds distant until you count backwards: an independent audit needs a scope, evidence and a remediation window before anyone signs anything, so a 2028 deadline realistically means starting in 2027.
Coverage runs on the existing CCPA business test, which catches you three ways: gross annual revenue above $26,625,000, or buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50% or more of revenue from selling or sharing personal information. The revenue figure is generally read on global gross revenue rather than California revenue.
What "independent" actually constrains
The audit has to be performed by a qualified, objective, independent professional, and that is the requirement most likely to change how your engineering organisation is structured, not just what it documents.
In practice it rules out the comfortable arrangement where the team that runs security also assesses it. An internal auditor can qualify, but only with a reporting line that does not run through the people whose work is being audited. If your security lead reports to the CTO and the audit covers engineering controls, that is a conflict you need to resolve before an auditor asks about it rather than during.
What the audit is actually looking at
The programme under review is the one protecting personal information from unauthorised access, destruction, use, modification or disclosure. Expect the familiar control families, examined for evidence rather than intent:
- Authentication and access control, including how privileged access is granted and removed
- Encryption at rest and in transit
- Account management and the joiner-mover-leaver process
- Vulnerability management and patching cadence
- Logging, monitoring and how alerts actually get actioned
- Incident response, including whether the plan has been exercised
- Vendor and service-provider oversight, which is where most engineering teams are thinnest
- Training, and evidence people completed it
The through-line is that assertions are worth nothing. A documented policy that nobody follows is a finding, not a control, and it is a worse finding than an absent policy because it is now written down.
Two obligations that turn into engineering work
Retention. Audit-related documentation has to be kept for at least five years. That is longer than most logging retention defaults, and it is a decision to make deliberately rather than inherit from a platform. If your evidence lives in a system that rolls off at 30 or 90 days, the evidence for your 2028 audit is already being deleted.
Certification. A certification of completion goes to the California Privacy Protection Agency. So unlike an internal security review that can quietly slip, this one has a filing attached and a date attached to the filing.
What to do while it is still cheap
Nothing here needs a consultant yet. Four things a team can do in a fortnight:
- 1.Establish which April applies. It is a finance question, not a security one, and it changes your whole timeline. Ask now, while 2026 revenue is still being earned rather than reconstructed.
- 2.Fix retention before you fix controls. Everything else can be improved later; evidence you did not keep cannot be recovered. This is the single item with a hard dependency on time, the same reason decision logging belongs at the top of an ADMT backlog rather than the bottom.
- 3.Check the independence question. Look at your reporting lines and decide whether an internal audit could credibly be called objective. If not, that is a hiring or structural decision with a lead time.
- 4.Inventory your subprocessors. Vendor oversight is where audits most often find gaps, and the list itself usually takes longer to assemble than anyone expects. If you use development partners, how you vet them is part of this answer.
What this means for your team
- The deciding year is now. Everything else on this page has a 2028-to-2030 date, but the revenue that sets which one applies is being earned this year.
- Evidence beats policy. Auditors test whether a control operated, not whether it was described.
- Retention is the irreversible item. Five years is the bar, and defaults are usually far shorter.
- This obligation is separate from the ADMT rules but lands on the same teams. If you are already scoping what the ADMT rules require you to build, fold the audit inventory into the same exercise rather than running two.
If you are working out which April applies and what evidence you would be able to produce today, that is a short and useful conversation. Tell us what your stack looks like and we will tell you where the gaps usually are at your size.
Sources
- California Privacy Protection Agency: CCPA updates, cybersecurity audits, risk assessments and ADMT
- California Privacy Protection Agency: updated monetary thresholds
- Ropes & Gray: California's CCPA cybersecurity audit rule takes effect
- Skadden: California finalizes CCPA regulations for ADMT, risk assessments and cybersecurity audits