The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, continues to reshape compliance obligations for businesses operating in California. Among the most significant new requirements are mandatory cybersecurity audits and privacy risk assessments, taking effect between 2027 and 2030. These obligations mark a shift from purely rights-based privacy regulation toward operational accountability – requiring businesses to proactively demonstrate that their data practices meet regulatory standards.

The breadth of the required reviews means businesses should act now to determine whether they are covered, assess existing safeguards, and establish the governance, documentation and remediation processes needed for compliance.

Cybersecurity Audits: Scope and Applicability

Businesses face mandatory annual security reviews when their handling of consumer data creates meaningful exposure for individuals. These circumstances bring a company within scope:

  • Generating at least half of yearly revenue through personal information sales or sharing; or
  • Combining annual gross revenues exceeding $26.625 million with:
    • maintaining records on 250,000 or more California residents; or
    • processing sensitive data covering at least 50,000 individuals.

The evaluation must be performed by an independent auditor – internal or external – who has no oversight responsibilities for the company’s security program. Most organizations will find that engaging a third-party firm offers the clearest path to satisfying independence standards.

Audit Domains

The examination spans 18 security categories:

  1. Authentication-identity verification (including MFA);
  2. Encryption at rest and in transit;
  3. Account management and access controls;
  4. Inventory and management;
  5. Secure configuration of hardware and software;
  6. Internal and external vulnerability testing and penetration simulations;
  7. Audit logging;
  8. Network monitoring and defenses;
  9. Antivirus and antimalware protections;
  10. Network segmentation;
  11. Port and protocol restrictions;
  12. Cybersecurity awareness, including workforce security awareness;
  13. Cybersecurity training and education;
  14. Secure coding practices;
  15. Vendor oversight;
  16. Data retention and destruction;
  17. Incident response; and
  18. Business continuity planning.

Phased Compliance Deadlines

Filing deadlines are tiered by company size:

  • Organizations with over $100 million in revenue must certify by April 1, 2028;
  • Those with between $50-100 million in revenue must certify by April 1, 2029; and
  • Those with under $50 million in revenue must certify by April 1, 2030.

Thereafter, annual certification is due each April 1. If enforcement authorities request the underlying report, the business has 30 days to produce it.

Preparing for Audit

A methodical approach to readiness can prevent last-minute compliance crises. Begin by examining current protocols (including SOC 2 attestations) and performing an internal diagnostic to identify which safeguards already satisfy CCPA standards. Consider running a rehearsal exercise – reviewing documentation, interviewing personnel and cataloging shortfalls.

Next, address identified deficiencies before the compliance window opens, prioritizing items with greatest regulatory exposure; then secure a credentialed evaluator. Internal auditors cannot have involvement in the activities under examination and must possess recognized credentials. Internal audit leads must report to an executive outside the security function’s chain of command.

Finally, the certifying officer must possess working familiarity with the review’s substance and corporate authority to submit filings. Build leadership sign-off into the project timeline and compile evidentiary materials to substantiate the certification if questioned.

Privacy Risk Assessments: A Recurring Obligation for High-Impact Data Practices

CCPA regulations also impose a duty on companies whose data handling creates appreciable privacy exposure. Before launching any processing activity with significant privacy implications, organizations must conduct a formal risk evaluation.

Activities triggering this mandate include:

  • Selling or sharing personal information (including digital tracking pixels);
  • Handling sensitive categories such as medical records, financial details or precise geolocation;
  • Algorithmic analysis of individuals in employment, education or location contexts;
  • Deploying automated decision systems for consequential determinations affecting employment, lending or healthcare; and
  • Training such systems using personal data for high-stakes purposes or biometric matching.

For new activities, evaluation must occur before data flows begin. Legacy operations predating January 1, 2026, must be evaluated by year-end 2027. Each evaluation expires after three years and must be revisited when data practices undergo meaningful modification. Documentation must remain accessible for the longer of the processing duration or five years. Initial submissions to the California Privacy Protection Agency are due by December 31, 2027, or April 1, 2028, with annual filings thereafter.

Required Assessment Elements

A compliant evaluation must:

  • Articulate the specific business rationale and enumerate exactly which data categories are employed, limiting scope to necessary information;
  • Map operational mechanics, including data sources, internal flows, external disclosures, retention periods, consumer touchpoints and affected population size;
  • For algorithmic systems, explain the computational approach, constraints, outputs and pathway to human outcomes;
  • Weigh anticipated benefits against privacy harms, including unauthorized exposure, discrimination and manipulation; and
  • Document the decision to proceed along with safeguards deployed.

Building an Assessment Program

A mature program requires weaving privacy analysis into everyday operations. Key organizational pillars include:

  • Ownership and governance. Assign named individuals to shepherd each evaluation. Map approval chains factoring in exposure severity. Establish escalation routes for high-risk findings and clarify accountability for corrective measures.
  • Methodology and templates. Draft uniform questionnaires capturing initiative descriptions, timelines, data inventories, information flows and residual exposure. Identify triggers that automatically launch evaluations: new ventures, platform changes, novel data uses and vendor onboarding. Construct a rubric with objective criteria for grading privacy hazards.
  • Process integration. Wire evaluation checkpoints into project kickoffs and stage-gate approvals. Condition system launches on completed assessments. Make privacy vetting non-negotiable in procurement and supplier qualification.
  • Training and culture. Codify protocols in written guidance. Equip staff with understanding of regulatory rationale, review triggers, evaluation techniques and remediation strategies. Cultivate an organizational mindset viewing privacy as competitive advantage rather than box-checking.
  • Continuous improvement. Measure evaluation throughput and remediation progress. Stress-test the process periodically. Recalibrate criteria as regulations evolve.
  • Technology. Dedicated privacy platforms can automate workflows, provide shared workspaces, embed risk scoring with automated escalation, link to data cataloging efforts and centralize assessment archives.

Remediation

Evaluations have limited value if conclusions sit idle.

  • Designate accountable individuals for each finding.
  • Set timelines calibrated to severity.
  • Maintain tracking logs with issue descriptions, risk grades, assignees and resolution evidence.
  • Schedule recurring check-ins and push reminders as deadlines approach.
  • Stratify issues into severity tiers and tackle the most serious first – especially those implicating regulatory mandates.
  • Prioritize durable solutions over quick patches.

Key Takeaways

California’s new mandates for security evaluations and privacy assessments mark a notable evolution in state privacy enforcement. For organizations without prior structured security examinations or privacy impact analyses, these requirements will demand meaningful investment – yet they also offer strategic upside through lower legal exposure, stronger defenses and deeper consumer confidence.

Affected organizations should launch preparations without delay:

  • Verify scope applicability,
  • Catalog implicated systems and personnel,
  • Chart project roadmaps synchronized to the 2026-2028 regulatory calendar,
  • Run diagnostic exercises, and
  • Draft assessment questionnaires.

Although staggered deadlines afford some breathing room, companies that defer action will struggle to build the governance infrastructure the new obligations require. These developments exemplify a wider movement toward demonstrable accountability, and organizations building compliance infrastructure today will stand on firmer ground as California’s framework matures and peer jurisdictions follow suit.

For questions about compliance with these new CCPA requirements and deadlines, please contact Chiara Portner or your regular Lathrop GPM attorney.