Blog
sprinto angle right
CCPA
sprinto angle right
CCPA Article 9 Requirements: Scope, 18 Control Domains, and Deadlines

CCPA Article 9 Requirements: Scope, 18 Control Domains, and Deadlines

TL;DR
  • Article 9 (sections 7120 to 7124) requires an annual, independent cybersecurity audit, certified to the California Privacy Protection Agency (CPPA) by a senior executive under penalty of perjury. The final regulations took effect January 1, 2026.
  • You are in scope if you meet any one of three routes under section 7120, based on revenue and the volume of California residents’ data you process. California employees and business contacts count, so B2B companies that sell no data can still qualify.
  • The audit assesses up to 18 components under section 7123, using evidence rather than management’s word.
  • First certifications are due April 1, 2028, 2029, or 2030 by revenue tier, but the audit period opens fifteen months earlier (January 1, 2027) for the first tier so evidence has to exist from day one.
  • SOC 2 and ISO 27001 work toward it but do not fully satisfy it. CCPA cybersecurity audits are annual, not a one-time certification.

California’s cybersecurity audit rule is now in force. Under Article 9 of the CCPA regulations, businesses that process enough California residents’ data must run an annual, independent cybersecurity audit and certify it to the state. This guide covers the requirements: who is in scope, what the audit assesses, who can perform it, who signs off, and when it is due.

CCPA Article 9 requirements at a glance

Article 9 is set out across sections 7120 to 7124 of the final CCPA regulations.

RequirementWhat you need to do
Check whether Article 9 appliesCompare your revenue and California data volumes with the section 7120 thresholds
Complete the audit every yearAudit the required 12-month period, complete the report, and file the certification by the applicable April 1 deadline
Use an independent auditor with real evidenceAppoint a qualified auditor who did not build the program, and give them evidence rather than assurances
Assess the program and the 18 componentsReview the documented program and each applicable component under section 7123
Produce the report and certify completionRecord scope, evidence, findings, and remediation; retain records for five years; file the executive certification

Requirement 1: Check whether Article 9 applies to your business

Article 9 does not apply to every CCPA business. It applies only where your processing of personal information presents a “significant risk to consumers’ security.”

The three routes that put you in scope

Section 7120 defines significant risk through two conditions, the second carrying two alternative volume tests — three routes in practice. Meeting any one puts you in scope:

ccpa-applicability-decision-flow
  1. You derived 50% or more of your annual revenue from selling or sharing consumers’ personal information in the preceding calendar year. No minimum company size.
  2. Your annual gross revenue exceeded $26,625,000, and you processed the personal information of 250,000 or more California residents or households, both in the preceding calendar year.
  3. Your annual gross revenue exceeded $26,625,000, and you processed the sensitive personal information of 50,000 or more California residents, both in the preceding calendar year.

Two nuances decide most borderline cases:

  • “Consumer” means any California resident in any relationship with you: customer, employee, job applicant, or a contact in your CRM. Because employees and business contacts count, a B2B company that sells no data can still cross the 250,000 threshold.
  • The revenue figure is worldwide; the population counts are California-only. Revenue is total gross revenue from all sources. The 250,000 and 50,000 counts include only California residents.

Article 9 applies to any for-profit company that does business in California, whatever its industry or where it is headquartered. The $26,625,000 figure is the CCPA business threshold, adjusted for inflation and current for 2025-2026

secure-check
Run your own numbers against all three conditions and see your result, revenue tier, and audit period in 90 seconds.

Note on scope: The audit boundary is not limited to databases labeled “California data.” It follows the systems that process, access, or protect that personal information, which can include identity and access, cloud, employee devices, HR, applicant-tracking, CRM, logging, backup, and service-provider systems, though not every system automatically.

Requirement 2: Complete the audit every year

ccpa-article-9-certification-deadlines

CCPA cybersecurity audits are annual for businesses that meet the Article 9 criteria. This is not a certification you complete once and leave behind. The first cycle is phased in by gross revenue.

Revenue band for an in-scope businessFirst audit periodReport completed and certification filed by
More than $100M in 2026Jan 1, 2027 to Jan 1, 2028April 1, 2028
$50M to $100M in 2027Jan 1, 2028 to Jan 1, 2029April 1, 2029
Less than $50M in 2028Jan 1, 2029 to Jan 1, 2030April 1, 2030

After April 1, 2030, the cycle repeats. Each January 1, you look back at the year that just ended: if you met the Section 7120 criteria during it, your audit covers the next 12 months, and the report is due by April 1 of the following year.

For the earliest group, the date that matters isn’t just April 1, 2028. Your controls must have been running and producing evidence from January 1, 2027, because you cannot reliably rebuild a year of access reviews, training records, vulnerability fixes, or backup tests after the audit period ends.

Requirement 3: Use an independent auditor, and give them evidence

Section 7122 sets out two tests: who is allowed to run the audit, and on what the audit must be built.

Who can perform the audit

Your auditor may be internal or external. Either way, they must:

  • Understand cybersecurity and know how to audit a cybersecurity program
  • Follow procedures accepted by bodies such as the AICPA, PCAOB, ISACA, or ISO
  • Make objective, impartial decisions, free of pressure from the business

No single auditor certification is required.

Who cannot perform the audit

Independence is the harder test. The auditor cannot be anyone who helped build or run the program being audited. That excludes anyone who:

  • Developed the procedures being audited
  • Prepared your cybersecurity documents
  • Recommended changes to the program, beyond reporting findings
  • Implemented or maintained the program

The practical consequence: the firm that helps you get ready is disqualified from the audit of record, so plan for two separate parties. If you use an internal auditor, the highest-ranking auditor must report to a member of executive management who does not have direct responsibility for the cybersecurity program, and an executive meeting that same description must conduct their performance review and determine their pay. That rules out the CISO or anyone who owns security.

What the audit must be built on

Section 7122(d) sets the evidence standard in one sentence: “No finding of any cybersecurity audit may rely primarily on assertions or attestations by the business’s management.” Findings must rest primarily on specific evidence the auditor deems appropriate – documents reviewed, sampling and testing performed, and interviews conducted. This applies to every component the auditor assesses, and it is what separates Article 9 from a questionnaire-driven review.

The obligation runs both ways. Under section 7122(b) you must make available to the auditor all information in your possession, custody, or control that they request as relevant to the audit, including information about your cybersecurity program, your information system, and your use of service providers and contractors. Under section 7122(c) you must make good-faith efforts to disclose all facts relevant to the audit, and must not misrepresent any of them.

Requirement 4: Assess your cybersecurity program and the 18 components

Section 7123(a) sets the objective. The audit must assess how your cybersecurity program protects personal information from unauthorized access, destruction, use, modification, or disclosure, and how it protects against unauthorized activity resulting in the loss of availability of personal information. Everything below serves that test.

The auditor checks two things: whether you have a documented cybersecurity program that fits your size, complexity, and processing, and whether you follow it day-to-day. They then review each applicable component listed in section 7123.

ccpa-article-9-control-domains.webp

The 18 CCPA Article 9 components

The regulation refers to these as cybersecurity program components. The auditor assesses each applicable one separately and documents the evidence behind the finding.

#ComponentWhat it coversEvidence you may need
1AuthenticationMFA, phishing-resistant MFA, strong passwordsIdP settings, MFA enrollment, password configs
2EncryptionPersonal information at rest and in transitStorage encryption, TLS, key-management records
3Account management and access controlsLeast privilege, privileged accounts, joiner-mover-leaver, physical accessAccess reviews, JML records, PAM logs, badge records
4Personal information and system inventoryData maps, classifications, asset inventoriesData-flow maps, asset registers, classification records
5Secure configurationPatching, hardening, masking, change managementConfig baselines, patch reports, change tickets
6Vulnerability managementScans, penetration tests, disclosure programScan and pen-test results, bug-bounty and remediation records
7Audit-log managementCentralized log storage, retention, monitoringSIEM settings, retention rules, log-review records
8Network monitoring and defensesIntrusion detection or prevention, data-loss preventionAlerts, IDS or IPS settings, DLP policies
9Anti-malwareProtection against malicious softwareEndpoint coverage, detections, quarantine records
10System segmentationSeparation of networks and sensitive systemsNetwork diagrams, firewall rules, segmentation tests
11Ports, services, and protocolsRestriction of unnecessary or risky servicesPort scans, approved-service lists, exception records
12Cybersecurity awarenessStaying current on new threatsThreat briefings, advisories, security updates
13Cybersecurity trainingOnboarding, annual, and post-breach trainingCompletion records, training content, post-breach logs
14Secure developmentCode review, testing, secure practicesReview records, SAST or DAST results, release approvals
15Third-party oversightService providers, contractors, third partiesVendor inventory, assessments, contracts, reassessments
16Retention and secure disposalRetention schedules and secure destructionRetention rules, deletion logs, destruction certificates
17Incident responseDetecting, handling, and recovering from incidentsIR plan, tabletop exercises, incident records
18Business continuity and disaster recoveryContinuity plans, recovery, backupsBCP and DR plans, backup logs, restoration tests

Face-CTA-1

Every item in the evidence column has to exist for the whole audit period, dated as it happened.

See how Sprinto collects evidence for the 18 components.

Requirement 5: Produce the report and certify completion

The report has to show what the auditor reviewed, the evidence used, what they found, and what you plan to fix. Under section 7123(e), it must include:

  • Your information system, and the policies, procedures, and practices reviewed
  • The audit criteria, and the documents, samples, tests, and interviews examined
  • Which of the 18 components were treated as applicable, and how your program implements each
  • An assessment of how effective the program and controls are
  • Any gaps or weaknesses, with a remediation plan and timeline for each
  • Any corrections to earlier audit reports
  • The titles of up to three people responsible for the program, and the auditor’s name, affiliation, and qualifications
  • A statement signed and dated by the highest-ranking auditor that the review was independent, impartial, and evidence-based
  • Any consumer breach notifications and regulator notifications, where applicable

The regulation does not want a “pass” or “fail.” It wants effectiveness explained, weaknesses named, and remediation dated.

Once complete, the report is sent to an executive responsible for the cybersecurity program, and you and the auditor retain all audit records, including supporting evidence, for at least 5 years. Separately, a member of executive management files a certification with the CPPA by April 1. The two documents are different:

Audit reportExecutive certification
Prepared by the auditorCompleted by an authorized executive
Contains scope, evidence, findings, gaps, and remediationConfirms the required audit was completed
Given to the executive over the program, kept five yearsSubmitted to the CPPA, filed by April 1

The certifying executive must be directly responsible for Article 9 compliance, know enough about the audit to be accurate, have authority to file, and sign under penalty of perjury that the audit was completed and that the business did not try to influence the auditor. Only the certification goes to the CPPA. The full report stays with you.

ccpa-where-the-documents-go.webp

Can you reuse SOC 2, ISO 27001, or NIST evidence?

Yes, but an existing audit does not automatically satisfy Article 9. Section 7123(f) lets you use an audit or assessment done for another purpose if it meets every Article 9 requirement on its own or with supplementation. The regulation names an audit based on NIST CSF 2.0 as an example.

Existing programWhat you may reuseWhat you still need to check
SOC 2 Type IIControl descriptions, testing, access reviews, monitoring and operating evidenceSystem boundary, Article 9 report contents, all 18 components, audit period, certification
ISO 27001ISMS policies, risk records, asset inventories, internal audits, corrective actionsCalifornia-specific scope, Article 9 evidence, auditor independence, certification
NIST CSF 2.0Cybersecurity outcomes, profiles, risk activities, control mappingsWhether it meets every Article 9 reporting and evidence requirement

Common gaps include scope (HR, applicant, and CRM systems outside a SOC 2 boundary), a CCPA-specific personal information inventory, a formal vulnerability disclosure process, phishing-resistant MFA extended to contractors, and, for Security-only SOC 2 reports, business continuity and the depth of retention and disposal coverage. For a fuller comparison, see SOC 2 vs ISO 27001.

Keep CCPA Article 9 evidence current with Sprinto

Sprinto’s Autonomous Trust Platform is built to produce the evidence that Article 9 rewards: proof that your controls ran throughout the entire audit period. It interprets the regulation into live controls, maps them to your environment, and keeps one control set aligned across CCPA, SOC 2, ISO 27001, and NIST, so the same evidence works for several programs. 

Autonomous evidence collection captures timestamped records from your cloud, identity, HR, and device systems, continuous monitoring flags control drift before it becomes a finding, and the platform covers the 18 domains an auditor examines, from access reviews and vulnerability management to vendor oversight and security training.

Sprinto handles the readiness and evidence work, not the audit itself, so you still engage an independent auditor and file the executive certification.

secure-check-waves
See how Sprinto maps Article 9 to controls you already run.

FAQs

Annual, for businesses that meet the Article 9 criteria. After the phase-in, the audit covers a 12-month period, with the report completed by April 1 of the following year.

For the highest revenue band, the audit period starts January 1, 2027. The report must be complete and the certification submitted by April 1, 2028.

It is not limited to databases that store California data. The scope can include any system that processes personal information, provides access to it, or supports its security and availability. The auditor decides what is relevant.

No. You may use an internal or external auditor, as long as they are qualified, independent, and separate from the work being audited. Internal auditors must meet the reporting conditions in section 7122.

Not on its own. You can reuse policies, controls, and evidence, but you still have to check and fill gaps against the full Article 9 requirements, starting with scope and the report contents.

Yes. It can map requirements, collect evidence, monitor control status, track gaps, and organize auditor requests. It cannot make the auditor’s independent judgments or file the executive certification for you.

The regulations set no standard price. Cost depends on the size of the audit boundary, internal versus external auditor, the number of systems and vendors, the testing required, how much evidence you already have, and how many gaps need fixing. Budget it in five parts: readiness work, auditor fees, internal team time, technical testing, and remediation.

Radhika Sarraf
Author

Radhika Sarraf

Radhika Sarraf is a content marketer at Sprinto, where she explores the world of cybersecurity and compliance through storytelling and strategy. With a background in B2B SaaS, she thrives on turning intricate concepts into content that educates, engages, and inspires. When she’s not decoding the nuances of GRC, you’ll likely find her experimenting in the kitchen, planning her next travel adventure, or discovering hidden gems in a new city.
Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
research & insights curated to help you earn a seat at the table.
single-blog-footer-img