Skip to content
← Back to blog
Security·August 13, 2026·6 min read

The CCPA cybersecurity audit: what it asks, and which year yours lands

California now requires an independent cybersecurity audit, on a deadline set by your 2026 revenue. That means the year deciding it is already running.

Most of the attention on California's new privacy regulations has gone to automated decisions, because that is the part with a January 2027 date on it. Sitting alongside it is a second obligation that far more companies will trip over, for an unhelpful reason: the year that decides your deadline is 2026, which is already most of the way through.

If your business is covered, you will owe an independent cybersecurity audit, and which April you owe it by was determined by revenue you are earning right now.

This is a builder's read of the requirement, not legal advice. Your counsel decides whether you are in scope. This is what to have ready once they tell you.

Which April is yours

The phase-in keys off gross revenue for 2026, not for the year the audit is due.

First audit dueIf 2026 gross revenue was
1 April 2028Over $100 million
1 April 2029$50 million to $100 million
1 April 2030Under $50 million

Two things follow that people miss. A company that crosses $100 million during 2026 has bought itself the earliest deadline, even if revenue later falls. And 2028 sounds distant until you count backwards: an independent audit needs a scope, evidence and a remediation window before anyone signs anything, so a 2028 deadline realistically means starting in 2027.

Coverage runs on the existing CCPA business test, which catches you three ways: gross annual revenue above $26,625,000, or buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50% or more of revenue from selling or sharing personal information. The revenue figure is generally read on global gross revenue rather than California revenue.

What "independent" actually constrains

The audit has to be performed by a qualified, objective, independent professional, and that is the requirement most likely to change how your engineering organisation is structured, not just what it documents.

In practice it rules out the comfortable arrangement where the team that runs security also assesses it. An internal auditor can qualify, but only with a reporting line that does not run through the people whose work is being audited. If your security lead reports to the CTO and the audit covers engineering controls, that is a conflict you need to resolve before an auditor asks about it rather than during.

What the audit is actually looking at

The programme under review is the one protecting personal information from unauthorised access, destruction, use, modification or disclosure. Expect the familiar control families, examined for evidence rather than intent:

  • Authentication and access control, including how privileged access is granted and removed
  • Encryption at rest and in transit
  • Account management and the joiner-mover-leaver process
  • Vulnerability management and patching cadence
  • Logging, monitoring and how alerts actually get actioned
  • Incident response, including whether the plan has been exercised
  • Vendor and service-provider oversight, which is where most engineering teams are thinnest
  • Training, and evidence people completed it

The through-line is that assertions are worth nothing. A documented policy that nobody follows is a finding, not a control, and it is a worse finding than an absent policy because it is now written down.

Two obligations that turn into engineering work

Retention. Audit-related documentation has to be kept for at least five years. That is longer than most logging retention defaults, and it is a decision to make deliberately rather than inherit from a platform. If your evidence lives in a system that rolls off at 30 or 90 days, the evidence for your 2028 audit is already being deleted.

Certification. A certification of completion goes to the California Privacy Protection Agency. So unlike an internal security review that can quietly slip, this one has a filing attached and a date attached to the filing.

What to do while it is still cheap

Nothing here needs a consultant yet. Four things a team can do in a fortnight:

  1. 1.Establish which April applies. It is a finance question, not a security one, and it changes your whole timeline. Ask now, while 2026 revenue is still being earned rather than reconstructed.
  2. 2.Fix retention before you fix controls. Everything else can be improved later; evidence you did not keep cannot be recovered. This is the single item with a hard dependency on time, the same reason decision logging belongs at the top of an ADMT backlog rather than the bottom.
  3. 3.Check the independence question. Look at your reporting lines and decide whether an internal audit could credibly be called objective. If not, that is a hiring or structural decision with a lead time.
  4. 4.Inventory your subprocessors. Vendor oversight is where audits most often find gaps, and the list itself usually takes longer to assemble than anyone expects. If you use development partners, how you vet them is part of this answer.

What this means for your team

  • The deciding year is now. Everything else on this page has a 2028-to-2030 date, but the revenue that sets which one applies is being earned this year.
  • Evidence beats policy. Auditors test whether a control operated, not whether it was described.
  • Retention is the irreversible item. Five years is the bar, and defaults are usually far shorter.
  • This obligation is separate from the ADMT rules but lands on the same teams. If you are already scoping what the ADMT rules require you to build, fold the audit inventory into the same exercise rather than running two.

If you are working out which April applies and what evidence you would be able to produce today, that is a short and useful conversation. Tell us what your stack looks like and we will tell you where the gaps usually are at your size.

Sources

Frequently asked questions.

It depends on your 2026 gross revenue, across three tiers with first audits due 1 April 2028, 2029 and 2030, largest businesses first. The revenue figures for each tier are in the article body. The important part is that the tier is set by revenue in 2026, which means the year determining your deadline is already underway.

A qualified, objective and independent professional. An internal auditor can qualify, but only where the reporting line does not run through the people whose work is being audited. If your security lead reports to the CTO and the audit covers engineering controls, that conflict needs resolving before an auditor raises it.

At least five years. That is considerably longer than most default logging and evidence retention settings, so it is worth checking now: if your evidence lives in a system that rolls off after 30 or 90 days, the material for a 2028 audit is already being deleted.

No, they are separate obligations from the same set of regulations, though they land on the same teams. The ADMT rules attach on 1 January 2027 and concern automated decisions about people. The cybersecurity audit concerns the programme protecting personal information, and phases in between 2028 and 2030 by revenue.

Find out which April applies, because it is a finance question that sets your whole timeline. Then fix evidence retention before improving controls: controls can be improved later, but evidence you failed to keep cannot be recovered.