California cybersecurity audit: CCPA Article 9 rule for covered businesses
|

California cybersecurity audit: does the CCPA rule apply?

Does the California cybersecurity audit rule apply to my business? A California business is in scope if it either earned at least 50% of its revenue from selling or sharing personal information, or exceeded roughly $26.625 million in annual gross revenue and processed the personal information of at least 250,000 California consumers or households (or the sensitive personal information of at least 50,000). Covered businesses must complete an annual California cybersecurity audit under Article 9 of the California Privacy Protection Agency’s regulations and file an executive certification of completion, with the first audits phasing in from April 2028.

California just changed what a cybersecurity program has to prove. In September 2025 the California Privacy Protection Agency adopted a package of final regulations that includes Article 9, a new cybersecurity audit requirement built on the California Consumer Privacy Act and the California Privacy Rights Act. The California cybersecurity audit is not another maturity assessment or control review. It is a formal, evidence-based audit that ties the effectiveness of a company’s cybersecurity program to the protection of California consumers’ personal information, ends in an executive certification filed with a state regulator under penalty of perjury, and starts phasing in for the largest businesses with a 2027 audit period. This post walks through who is covered, what the audit must actually do, when the certifications are due, and where a covered business should be spending 2026.

What is the California cybersecurity audit rule, and where does it live? 🔍

Article 9 of the California Privacy Protection Agency’s CCPA regulations requires annual cybersecurity audits for businesses whose processing of personal information presents a “significant risk to consumers’ security,” with an executive certification submitted to the Agency by the applicable April 1 deadline.

The rule is Article 9 of the regulations issued by the California Privacy Protection Agency under the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq.) as amended by the California Privacy Rights Act. In September 2025 the Agency adopted a single final package covering cybersecurity audits (Article 9), risk assessments (Article 10), automated decision-making technology (Article 11), and updates to the existing CCPA regulations. The full regulatory text is available in the CPPA final regulations text (September 2025).

Article 9 is different from earlier California cybersecurity guidance in three important ways. First, the effectiveness of the cybersecurity program is evaluated by reference to whether it safeguards personal information from unauthorized access, destruction, use, modification, or disclosure — not against a generic control framework. Second, findings must rely primarily on specific evidence, not on management assertions. Third, an executive responsible for the cybersecurity program must certify completion, under penalty of perjury, in a filing made directly with the regulator.

Who has to complete a California cybersecurity audit? 🏢

Two independent triggers bring a business into scope. Meet either one and the audit applies.

The rule casts a wide net over businesses whose data-processing activities pose a “significant risk to consumers’ security.” The regulations set the thresholds for that phrase and refresh the dollar figure every odd-numbered year to reflect CPI:

TriggerThresholdBasis
Revenue mixAt least 50% of annual revenue from selling or sharing consumers’ personal information in the preceding calendar year.Article 9
Volume + size (part 1)Annual gross revenue over $26.625 million (2025 figure; CPI-adjusted every odd-numbered year) AND processing the personal information of at least 250,000 California consumers or households.Article 9
Volume + size (part 2)Annual gross revenue over $26.625 million (2025 figure) AND processing the sensitive personal information of at least 50,000 California consumers or households.Article 9

Two operational notes matter here. “California consumers” means natural persons who are California residents, not just companies incorporated in California — a business with no California office can be in scope. And “sensitive personal information” is a defined category under the CCPA that includes government identifiers, precise geolocation, race, religion, union membership, contents of certain communications, health information, biometric information, and consumers’ sex-life or sexual-orientation data. The 50,000-consumer trigger for sensitive personal information is lower for a reason.

What must the California cybersecurity audit actually cover? 🛡️

The audit must assess how the cybersecurity program safeguards personal information from unauthorized access, destruction, use, modification, or disclosure — plus loss of availability — component by component, based on evidence, and it must document gaps and the remediation plan for each.

Article 9 lists a long set of program components the audit must reach and, for each one, requires the auditor to describe (a) how the component contributes to safeguarding personal information, (b) any gaps or weaknesses, and (c) the business’s plan to address them. Components include:

  • Multifactor authentication.
  • Encryption of personal information at rest and in transit.
  • Account management and access controls.
  • Inventory and management of personal information and the information system.
  • Vulnerability scans, penetration testing, and vulnerability disclosure and reporting.
  • Audit-log management.
  • Segmentation of the information system.
  • Cybersecurity awareness, education, and training.
  • Oversight of service providers, contractors, and third parties.
  • Retention schedules and proper disposal of personal information.
  • Incident-response management.
  • Business continuity and disaster-recovery plans, including data-recovery capabilities and backups.

The auditor’s findings cannot rest primarily on management assertions or attestations. They must be supported by evidence the auditor deems appropriate, including documents reviewed, sampling and testing, and interviews conducted. That evidence standard reshapes the year’s work: privacy data inventories, sensitive-data classifications, consumer-processing controls, third-party data-sharing arrangements, and governance processes must be capable of producing artifacts the auditor can test.

When is the California cybersecurity audit deadline? 🗓️

The first audit reports are due in phases starting April 1, 2028, covering the 2027 calendar year for the largest businesses. Smaller businesses phase in over the following two years.

The phase-in schedule is set out in Article 9 and turns on annual gross revenue measured at a specified January 1 snapshot date:

Business sizeFirst audit periodFirst report due
Annual gross revenue over $100 million as of January 1, 2027Calendar year 2027April 1, 2028
Annual gross revenue between $50 million and $100 million as of January 1, 2028Calendar year 2028April 1, 2029
Annual gross revenue under $50 million as of January 1, 2029Calendar year 2029April 1, 2030

The clock runs on the audit period, not the report

For the largest businesses, the audit period begins January 1, 2027. That means remediation, evidence design, and control stabilization have to be finished during 2026. Waiting until the certification deadline in April 2028 is too late — the underlying operating year would already be on the record.

From our practice: build the evidence file before you buy the auditor

Independence is the constraint most companies underestimate. If the internal team or the external firm that designs, documents, or operates a control is the same team that later audits it, the audit fails on independence. Deciding early who audits — and separating that role from remediation from day one — is cheaper than restructuring engagements after the fact. The evidence file (documents, sampling, testing artifacts, interview notes) is worth building in parallel.

How should a covered business prepare for the California cybersecurity audit? 🧭

Confirm scope now, align cross-functional ownership, map current controls to the Article 9 component list, plan the evidence file, and separate the audit role from remediation before the audit period begins.

  1. Confirm applicability. Test both triggers against your last complete calendar year. For the volume trigger, define “California consumer” consistently across systems and count both personal information and sensitive personal information separately.
  2. Align cross-functional ownership. The audit will pull in privacy, information security, legal, procurement, enterprise risk management, internal audit, and business control owners. Assign a single accountable owner and a documented RACI before scope work starts.
  3. Define audit scope. Identify the systems, applications, business units, third parties, and data flows that process California consumers’ personal information. Map data lineage from collection to disposal.
  4. Map existing certifications to Article 9. SOC 2, ISO 27001, NIST CSF, PCI DSS, internal audit — for each, compare scope, evidence, and independence to Article 9 rather than assuming coverage. Document the gaps.
  5. Design the evidence strategy. Access management, vulnerability management, incident response, third-party oversight, remediation tracking, and governance activities each need retained, auditor-testable evidence for the full audit period.
  6. Fix third-party paper. Vendor and service-provider contracts should require the cooperation the auditor will need, plus reasonable security procedures appropriate to the data involved. Renewal cycles in 2026 are the window to update templates.
  7. Separate audit from remediation. Whether the audit is internal, external, or hybrid, identify the auditor role early and prohibit them from designing procedures, preparing business documents, making recommendations on the program, or implementing controls.
  8. Prepare the executive certifier. Identify the executive who will certify, define review expectations, and build a governance process that supports an informed attestation under penalty of perjury.

California cybersecurity audit at a glance

  • Article 9 of the California Privacy Protection Agency’s CCPA regulations, adopted in September 2025.
  • Applies to businesses that either earn 50%+ of revenue from selling or sharing personal information, or exceed roughly $26.625 million in revenue and process 250,000+ Californians’ personal information or 50,000+ Californians’ sensitive personal information.
  • First reports due April 1, 2028 for businesses over $100M in revenue; audit period starts January 1, 2027.
  • Auditor must be qualified, objective, and independent; findings must rely primarily on evidence, not assertions.
  • Executive responsible for the program submits a written certification to the Agency under penalty of perjury.

Frequently asked questions about the California cybersecurity audit ❓

Q. What is the California cybersecurity audit rule, and where does it come from?

It is Article 9 of the California Privacy Protection Agency’s regulations under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. The California Privacy Protection Agency adopted the final regulations in September 2025 in a single package covering Article 9 cybersecurity audits, Article 10 risk assessments, Article 11 automated decision-making technology, and updates to the existing CCPA regulations. The California cybersecurity audit rule requires covered businesses to complete an annual audit of their cybersecurity program and submit an executive certification of completion to the Agency.

Q. Which businesses have to complete a California cybersecurity audit?

The audit applies to businesses whose processing of consumers’ personal information presents a “significant risk to consumers’ security.” That is defined by two independent triggers. First, businesses that derived at least 50% of their annual revenue in the preceding calendar year from selling or sharing personal information. Second, businesses that had annual gross revenue exceeding roughly $26.625 million (a 2025 figure that adjusts every odd-numbered year for CPI) AND processed the personal information of at least 250,000 California consumers or households, OR the sensitive personal information of at least 50,000 California consumers or households. Meeting either trigger brings the business into scope.

Q. When is the first California cybersecurity audit report due?

The rule phases in by size. Businesses with annual gross revenue over $100 million as of January 1, 2027 must complete their first audit covering 2027 by April 1, 2028. Businesses with revenue between $50 million and $100 million as of January 1, 2028 have a first-audit deadline of April 1, 2029 for the 2028 calendar year. Businesses with revenue under $50 million as of January 1, 2029 have a first-audit deadline of April 1, 2030 for the 2029 calendar year.

Q. Who can perform the California cybersecurity audit, and how independent must they be?

The auditor must be a qualified, objective, independent professional, and can be either internal or external. The rule prohibits the auditor from participating in activities that may compromise independence — designing procedures, preparing business documents, making recommendations on the cybersecurity program, or implementing or maintaining the program. If the auditor is internal, the highest-ranking auditor must report to an executive who is not responsible for the cybersecurity program. Findings must rest on specific evidence — documents reviewed, sampling and testing, interviews — not on management assertions.

Q. Can existing certifications like SOC 2, ISO 27001, or PCI DSS satisfy the California cybersecurity audit?

A business may leverage an audit or assessment prepared for another purpose if, on its own or supplemented, it meets every Article 9 requirement. In practice, SOC 2, ISO 27001, NIST CSF, PCI DSS, or internal audit reports rarely map one-for-one to the Article 9 scope and evidence rules. Use them as inputs — map their scope to the Article 9 component list and evidence requirements — but do not assume any of them is sufficient without a gap analysis.

Q. What does the executive certification for the California cybersecurity audit have to say?

The covered business submits a written certification — not the audit report itself — to the California Privacy Protection Agency through its website by the applicable deadline. The certification must come from an executive directly responsible for the cybersecurity program, and it must state under penalty of perjury that the audit was completed as required and that the business has not tried to influence the auditor’s decisions or assessments.

This article is general information, not legal advice for your situation. Applicability and audit readiness turn on specific facts, contract terms, and processing activities. If your organization may be covered under Article 9, contact SW Accounting & Consulting Corp for a scoping and readiness review.

Similar Posts