Blog
sprinto angle right
CCPA
sprinto angle right
What is Article 9 of the CCPA, and why does it matter?

What is Article 9 of the CCPA, and why does it matter?

TL;DR

  • Article 9 of the CCPA requires an annual cybersecurity audit by an independent auditor. A named executive then certifies it to the California Privacy Protection Agency by April 1 each year, under penalty of perjury. It took effect January 1, 2026.
  • Scope is set by revenue and by how many California residents’ data you process, whatever your industry or location. Because California residents who are your employees or business contacts also count, B2B companies that sell no data can cross the threshold.
  • For companies with more than $100 million in 2026 gross revenue, the first certification is due April 1, 2028, but the 1-year audit period it covers opens January 1, 2027. From that day, every control the auditor examines has to be operating and leaving a record, audit evidence cannot be created afterwards.
  • Your SOC 2 or ISO 27001 program counts toward it but does not fully satisfy it. The gaps are predictable, starting with which systems are in scope.

Article 9 of the California Consumer Privacy Act (CCPA) regulations requires businesses that process the personal information of California residents and cross certain revenue and volume thresholds to complete a cybersecurity audit every year. The rule is part of sections 7120 to 7124 of Title 11 of the California Code of Regulations. It came into effect on January 1, 2026.

Your business does not have to be based in the state; what matters is whether you process Californians’ data. A qualified independent auditor performs the audit. A named executive then certifies to the California Privacy Protection Agency, by April 1 each year and under penalty of perjury, that it was completed. 

The first certifications aren’t due until April 1, 2028, but that doesn’t mean you can put off preparations. Businesses must start planning because audits take time to schedule. For companies with more than $100 million in annual revenue, the audit period opens on January 1, 2027. Every control the auditor examines must produce evidence from that day. That means you have to confirm whether you are in scope, what the auditor will examine, how much of your SOC 2 or ISO 27001 work carries over, who can perform the audit and who signs off on it, and what the final report exposes you to. I will address all these questions and more in this piece.

What does CCPA Article 9 require?

Article 9 of CCPA requires an annual, independent audit of a business’s cybersecurity program. The regulation names 18 components the auditor must examine, such as authentication, encryption, vulnerability management, and incident response. It requires the auditor to document, with evidence, how the program protects personal information in each. 

SectionWhat it coversWhere this piece covers it
7120, Requirement to Complete a Cybersecurity AuditWho must complete one: the ‘significant risk’ conditions based on revenue and the volume of California residents’ data processedWho has to do a CCPA cybersecurity audit?
7121, Timing Requirements for Cybersecurity Audits and Audit ReportsWhen: the revenue-based tiers that stagger the first audits from 2027 to 2030, and the annual cycle after thatWhen is the CCPA Article 9 deadline?
7122, Thoroughness and Independence of Cybersecurity AuditsWho may perform it: auditor qualifications, independence, the reporting line for internal auditors, the evidence standard, and the five-year retention duty on both business and auditorWho can perform the audit, and who cannot?
7123, Scope of Cybersecurity Audit and Audit ReportWhat it examines: the 18 components, what the written report must contain, and when an audit done for another purpose can be reusedWhat does the audit cover? / Does a SOC 2 or ISO 27001 audit satisfy Article 9?
7124, Certification of CompletionHow completion is certified: the executive’s written certification to the agency by April 1, under penalty of perjuryWho signs the certification, and what are they signing?

A published list outlines what an auditor must examine and the standard of evidence for the findings. Whether a program meets the bar remains a judgment; the regulation sets no pass mark. The focus is gathering evidence rather than management’s word.

Note: CCPA Article 9 differs from GDPR Article 9, which covers special-category personal data.

But CCPA Article 9 is not separate from the California Privacy Rights Act (CPRA). The CCPA is the statute California passed in 2018. The California Privacy Rights Act (CPRA), a ballot measure voters approved in 2020, amended that statute rather than replacing it: it added consumer rights, created the California Privacy Protection Agency, and instructed the new agency to add rules on cybersecurity audits, risk assessments, and automated decision-making technology (ADMT). 

The lawmaking process lasted about four years and drew thousands of public comments before the Office of Administrative Law approved the text in September 2025. Article 9 is the cybersecurity-audit rule the agency added under that instruction.

California’s own economic impact statement estimates that 52,326 businesses are subject to the CCPA, and puts ongoing compliance costs at roughly $16,400 a year for a small business and $20,400 for a typical one, across the audit, risk assessment, ADMT, and insurance obligations.

Who has to do a CCPA cybersecurity audit?

You owe an Article 9 audit if your processing presents significant risk to consumers’ security. Section 7120 sets out two conditions, the second carrying two alternative volume tests, which works out to three routes into scope. Meeting any one of them puts you there.

Here, a consumer means any California resident in any relationship with you: customer, employee, job applicant, or a contact in your CRM. Personal information is anything that identifies or could reasonably be linked to a person or household, from a name or email address to a device ID or browsing history.

The CCPA (and Article 9) applies to any for-profit company that does business in California, regardless of where it is headquartered. So, if you sell to, employ, or collect data from people in the state, the rule applies. 

Now, let’s look at those three conditions:

ConditionsTrigger
1You derived 50% or more of annual revenue from selling or sharing California residents’ personal information in the preceding calendar year. No minimum company size.
2Your annual gross revenue exceeded $26,625,000 and you processed the personal information of 250,000 or more California residents or households, both in the preceding calendar year.
3Your annual gross revenue exceeded $26,625,000 and you processed the sensitive personal information of 50,000 or more California residents, both in the preceding calendar year.

Processed here covers anything done with the data: collecting, storing, using, or disclosing it. Sharing is the CCPA’s word for passing data to another company for targeted advertising, whether or not money changes hands. Sensitive personal information is a defined subset that includes government ID numbers, account credentials, precise location, health data, and racial, religious, or sexual-orientation data.

The population threshold count for conditions 2 and 3 should include only California residents. Customers in other states and countries are not counted. The revenue threshold is the opposite: total gross revenue from all sources, worldwide, in the preceding calendar year, not revenue earned in California.

check if CCPA applies to your business

Section 7120 doesn’t state a revenue threshold, but it points to Civil Code section 1798.140(d)(1)(A), which is adjusted for inflation in odd-numbered years and currently at $26,625,000

The key point here is that the 250,000 population threshold is not hard to cross. If you have a Californian workforce and a fairly well-maintained CRM, you’re likely already in scope.

secure-check-dark

When is the CCPA Article 9 deadline?

The first audit dates and audit periods defined in Section 7121 are spread out based on your business’s gross revenue. The audit itself covers a 12-month period, and you have three months after that to complete the audit report and submit the certification. Only the certification goes to the agency; the report stays with you and your auditor.

In practice, if a business’s gross revenue for 2026 was more than $100 million, it must audit the period from January 1, 2027 to January 1, 2028, and complete its first audit report and certification by April 1, 2028. A business whose 2027 revenue was between $50 million and $100 million can start a year later, audit in 2028, and report by April 1, 2029. 

After April 1, 2030 the phase-in ends and the audit repeats on an annual cycle. On the next January 1, you look back at the year that just completed to work out whether you are in scope, since the section 7120 conditions are all measured over that year. If you are, the audit covers the 12 months starting that same day. The report and certification are due three months after the completion of the said period.

The table below walks it year by year.

YearAudit period opening on January 1 of this yearReport and certification due on April 1 of this year
2026NoneNone
2027Businesses whose 2026 gross revenue was above $100 millionNone
2028Businesses whose 2027 gross revenue was $50 million to $100 millionBusinesses whose 2026 gross revenue was above $100 million
2029Businesses whose 2028 gross revenue was below $50 millionBusinesses whose 2027 gross revenue was $50 million to $100 million
2030None set by section 7121Businesses whose 2028 gross revenue was below $50 million

Worth saying twice, because it is the thing people miss. You already have to keep personal information secure. That duty is part of Civil Code section 1798.100(e) and predates Article 9 by years. It expects you to protect personal information from unauthorized access, destruction, use, modification or disclosure. Article 9 sends an auditor to check that same list, so now you have to prove you are doing it. 

If you are in the top revenue tier, your controls have to be running and generating records from January 1, 2027, which is the day your audit period opens. April 1, 2028 is only the filing date. Plan for the filing date and you start 15 months too late.

Also, auditor supply matters. You cannot solve a late start by hiring whoever helped you prepare.

What does the Article 9 cybersecurity audit cover?

The audit covers your cybersecurity program and how well it protects California residents’ personal information. Section 7123(a) states the audit must assess how the program protects personal information from unauthorized access, destruction, use, modification, or disclosure, and how it protects against unauthorized activity that makes personal information unavailable.

To answer that, the auditor looks at three things under section 7123(b). First, whether you have a real cybersecurity program: written policies and procedures that fit your business size and the kind of data you handle. Second, each of the 18 components in section 7123(c) that applies to your systems. Third, whether you follow your own rules day to day. 

The 18 components are where most of the work happens. They fall into six groups: how users log in and what they can access, how you protect personal information, how you keep attackers out, how you detect problems, how you manage staff and vendors, and how you recover from an incident.

To make things easier to remember, I’ve grouped the 18 items into 6 categories below. The last column shows the official numbering from the CCPA regulatory text.

ClusterComponentsSection #
Identity and accessAuthentication including phishing-resistant multi-factor authentication (MFA); account management and access controls1, 3
Data protectionEncryption at rest and in transit; inventory of personal information and information systems2, 4
Attack surfaceSecure configuration; vulnerability scans, penetration testing and a vulnerability disclosure program; control of ports, services and protocols5, 6, 11
Monitoring and defenseAudit-log management; network monitoring and defenses; antivirus and antimalware; system segmentation7–10
People and processSecurity awareness; education and training; secure development and code review; oversight of service providers, contractors and third parties (outside companies that handle your data)12–15
Resilience and lifecycleRetention schedules and secure disposal; incident response; business continuity and disaster recovery16–18

Two requirements set this apart from audits your team has already been through. The report must identify and describe in detail any gaps and weaknesses the auditor finds, and document your plan and timeline for resolving them. A report that leaves out an identified gap, or the remediation plan for it, does not meet the regulation’s requirements.

And under section 7123(e)(9) and (10), it must account for breach notifications: a sample copy, or a description, of any notice you sent to affected consumers under California’s breach-notification law, and of any notice you were required to send to an agency with jurisdiction over privacy laws in California, the latter with the dates and details of the incident and the remediation you carried out. If you notified affected consumers of an incident in March, the auditor records that in the report, next to what you did about it. Neither a SOC 2 report nor an ISO 27001 certification audit asks for that.

There is also a rule about how each of those components gets checked. The auditor cannot cover a component by asking your security lead whether it is in place and writing down the answer. Section 7122(d) puts it in one sentence:

“No finding of any cybersecurity audit may rely primarily on assertions or attestations by the business’s management.”

Under section 7122(g), both the business and the auditor must keep every document relevant to the audit, including the evidence behind each finding, for at least five years after the audit is completed.

block-quote
“The ideal situation to get to is real-time compliance. When everything’s hooked up on Sprinto, and if a control fails, you get an alert right away. You know exactly when you’re out of compliance and why. So that when we do go to the auditors, we know exactly where you stand.”

Does a SOC 2 or ISO 27001 audit satisfy Article 9?

Partly. Section 7123(f) permits using a cybersecurity audit or assessment prepared for another purpose, provided it meets every Article 9 requirement, alone or through supplementation. The text names the NIST Cybersecurity Framework 2.0 as the only example.

Tom Kemp, Executive Director of the California Privacy Protection Agency, has described that provision as deliberate: California wanted businesses to reuse their existing risk assessments and cybersecurity audits rather than start over. He has been equally clear about its limits. In his words, having done the work for GDPR does not mean there is “a one-to-one mapping.”

Mapping the 18 components of CCPA Article 9 against SOC 2, ISO 27001:2022, NIST CSF 2.0, and other frameworks revealed a few potential gaps that may occur in your program:

  1. A CCPA-specific personal information inventory: Article 9 assesses how your program protects personal information as the CCPA defines it. A SOC 2 or ISO 27001 asset inventory focuses on systems and owners. Article 9 asks how personal information, by CCPA category, moves through those systems and who outside the company can reach it.
  2. A formal vulnerability disclosure process: Scanning and penetration testing are standard. What you may miss is a published route for outsiders to report vulnerabilities, with safe-harbor language (a stated promise not to pursue researchers who report in good faith) and response timelines.
  3. Phishing-resistant MFA for every group: Article 9 also applies to your employees, independent contractors, and other personnel. It also covers outside companies that handle your team’s personal information, which the CCPA calls service providers and contractors. It specifies phishing-resistant MFA, meaning methods such as hardware keys or passkeys that a fake login page cannot capture. A program that applies it only to administrator accounts has a gap to document and a remediation timeline to write.
  4. Coverage of every system holding California residents’ data: A SOC 2 report covers a defined system, usually the product and the infrastructure under it. An ISO 27001 certificate covers a declared management-system scope. Article 9 focuses on protecting all California residents’ personal information. If your employees, job applicants, and business contacts are state residents, that pulls in your HR system, the applicant tracking system, the CRM, and the marketing tools that a software company’s SOC 2 boundary often leaves out.
  5. Business continuity and data retention, if your SOC 2 covers Security only: Most SOC 2 reports cover only the Security criteria. Backups, disaster recovery, and business continuity fall under the Availability criteria, and retention schedules and information disposal fall under Confidentiality. Both are Article 9 components. So, a security-only report may leave you with a few gaps.
  6. An audit period that matches the calendar year: SOC 2 observation windows are set by the company. An ISO 27001 certificate runs on a three-year cycle in which annual surveillance audits sample controls rather than assess all of them. In Article 9, the audit period is a fixed calendar year covering all applicable components. Reusing either framework’s audit under section 7123(f) means supplementing for the months and the components it did not cover.
SOC 2 System Boundary

In addition, Article 9 adds an explicit ban in section 7122(d) on findings that rest primarily on management’s assertions. This applies to all 18 components the auditor has to assess. That means you’d need to ensure access reviews, MFA enrollment, vulnerability remediation, training completion, and vendor reviews all have records covering the full audit period, which for the top revenue tier opens in January 2027.

An audit report only holds if the systems it covers haven’t changed since the audit.
  • “If they have material changes in their systems, number of systems, then it becomes useless — because if you don’t have all the systems on the SOC 2 report, you cannot really use it with your client… Not just observation window, but material changes to their scope: number of systems, number of legal entities, any changes to those. And then just changing the workflows altogether — any changes would trigger a re-audit and a reissuance of the report.”
  • Sammy Chowdhury, Co-founder and Chief Compliance Officer, Prescient Security (An excerpt from What 500 → 1000 Employees Does to Your Audit Program webinar)

Who can perform the CCPA Article 9 audit, and who cannot?

Section 7122 requires a qualified, objective, independent professional. Qualified means the auditor must know cybersecurity and know how to audit a cybersecurity program. However, it names no particular certification. The audit must follow procedures and standards accepted in the auditing profession, and the regulation gives the AICPA, the PCAOB, ISACA, and ISO as examples. 

The auditor may be internal or external, but section 7122 excludes anyone who helped build what is being audited. An auditor cannot have developed the procedures, prepared the business’s documents, made recommendations about the cybersecurity program outside of articulating audit findings, or implemented or maintained it.

The practical consequence: the firm that helps you get audit-ready is disqualified from auditing you. For this reason, two different auditors must handle the gap assessment and the audit of record.

An internal auditor is allowed, with conditions. Under section 7122(a)(3), the highest-ranking auditor must report directly to a member of executive management who has no direct responsibility for the cybersecurity program. That executive must run the auditor’s performance review and set their pay. That rules out the CISO or anyone else who owns security; the CFO, general counsel, or an audit committee are the obvious alternatives. 

Who signs the certification, and what are they signing?

One person signs the certification: a member of executive management. This refers to a senior executive responsible for the audit program and authorized to sign for the business. They need to file it with the California Privacy Protection Agency by April 1 after each audit period ends. 

Under section 7124(d)(4), the signer attests under penalty of perjury that the audit was completed and that the business has not made any attempt to influence the auditor’s decisions or assessments regarding the cybersecurity audit.’ This document is what the agency receives. The full audit report, with its findings and remediation plan, stays with the business and the auditor. But the agency can demand the whole report under section 7304. It allows them to audit any business for CCPA compliance, announced or unannounced, and back it up with a subpoena.

who signs the certification

The report also includes a signature from the highest-ranking auditor, under section 7123(e)(8). They must sign and date a statement in the report saying they conducted an independent review, used their own judgment, and didn’t just take management’s word for it. That report goes to the executive who runs the cybersecurity program. 

To sum up, the auditor signs the report and the executive signs the certification. Each is attesting to something different. The auditor confirms the audit was independent and evidence-based. The executive confirms that the audit was completed and that the business did not try to influence the auditor.

Now, since the executive has to sign under penalty of perjury, they might want each person involved in the process to confirm, in writing, what they gave the auditor and how. That is something you might want to consider when prepping for the audit.

banner-icon

Which of the 18 components are you already covering?

See our component-by-component breakdown of Article 9 requirements for what evidence each one tends to need.

How does Article 9 relate to risk assessments and ADMT?

Article 9 was created alongside Article 10 (risk assessments) and Article 11 (ADMT). So anyone researching Article 9 will run into the other two within minutes, and the three are easy to blur into one obligation. They are not one obligation. Each has its own test for who is covered and its own deadline, and being subject to one does not put you in scope for the others.

What connects them is the subject matter. All three regulate what businesses do with California residents’ personal information, and they overlap in practice. A company that processes sensitive personal information at volume is likely to owe an Article 9 audit and an Article 10 risk assessment. A company that uses software to screen job applicants may owe an Article 10 assessment and Article 11 notices. The vendor cooperation duty in section 7050(h) covers Article 9 audits and Article 10 assessments alike. So the same compliance team will usually handle all three, working from the same data inventory.

What separates them is the question each one asks.

Key aspectsArticle 9: Cybersecurity auditsArticle 10: Risk assessmentsArticle 11: ADMT
Fundamental question it answersHow well does your security program protect personal information?Is this activity worth the privacy risk it creates?Does a person get notice, a way out, and an explanation?
Who owes itBusinesses meeting a section 7120 conditionAny business doing one of six listed activitiesAny business using ADMT for a significant decision
What you produceAn independent auditor’s reportA written assessment, finished before you start the activityA pre-use notice, an opt-out route, and an explanation of the logic
Who sees itYour own executive responsible for securityNobody outside the business, unless askedThe consumer
What the agency getsA certification that the audit was done, by April 1Counts and categories, by April 1Nothing routine
If the regulator asks for the full documentArticle 9 sets no deadline of its own30 days, to the agency or the Attorney GeneralNot applicable
Key dateFirst certifications April 1, 2028Processing already running assessed by Dec 31, 2027; first submissions April 1, 2028Applies from January 1, 2027
How long you keep itFive years after the auditAs long as the processing runs, or five years, whichever is longer

Two things to note from the table. The first is about timing. Your Article 9 tier sets the date for your first audit report, but two of these obligations can reach you well before that. If you are about to start anything that needs a risk assessment, you have to do it before the processing begins, and that has been the rule since January 1, 2026. If you already use ADMT to make a significant decision about someone, you have until January 1, 2027. So you can have work to do this year even if your first audit report is not due until 2030.

The other thing is that Articles 9 and 10 both use the phrase ‘significant risk’ and mean different things by it. Article 9’s version is about volume, how many California residents’ data you hold. Article 10’s is about activity, what you do with it. Having done an Article 10 risk assessment does not answer the Article 9 question, and being under the Article 9 thresholds does not excuse you from Article 10.

Where Sprinto fits

Girish Redekar, Sprinto’s co-founder and CEO, describes compliance as a progression rather than a single audit event. On the Privacy Please podcast he put it this way:

block-quote
“A company usually moves through stages. First, it gets the foundational practices in place. Then it reaches a point where those practices run continuously, whether anyone is looking or not. After that, the company starts building resilience: preventing bad things where possible, detecting issues earlier, and reacting faster when something does go wrong. Trust is a spectrum. It is not a binary switch.”

Article 9 is a test of the second stage. An auditor who needs a year of evidence for each of the 18 components is asking whether your controls ran when nobody was checking, and the regulation’s evidence rule means the answer has to be on record rather than recalled.

Sprinto supports CCPA as a framework, alongside SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS. The platform covers the 18 components Article 9 asks an auditor to examine: authentication and MFA, access controls and reviews, encryption, vulnerability management, logging, security training, vendor oversight, incident response, and business continuity.

The overlap with other frameworks provides a strong starting point. The obligation Article 9 adds is evidentiary: you have to show, with records collected across a full year, that the program you already run protects personal information. Continuous monitoring is the difference between producing that record and reconstructing it.

When your auditor asks for 12 months of access-review records, Sprinto makes it easy to produce them. Each review is captured with a timestamp when it happens, so the January record exists in December in the same form as the November one, and your team hands over a year of evidence instead of rebuilding it from calendar invites and screenshots. 

Do note that the platform cannot do the audit for you. For that, you will have to engage a qualified independent auditor who had no hand in building your program.

Face-CTA-3

Want to see how this would work for your program?

Talk to a compliance expert about mapping the controls you already run to what an Article 9 auditor will ask for.

What should you do before January 2027?

Seven things, in roughly this order. The first three tell you whether and where you are exposed; the last four get you ready to be audited. None require you to wait for the audit period to open. Some get harder the later you start:

  1. Determine whether Article 9 applies to you, and write down your reasoning: Review your Worldwide gross revenue, California-resident and household counts, and sensitive personal information counts for the preceding calendar year.
  2. Scope every system that holds California residents’ personal information: That includes HR, applicant tracking, CRM, and marketing tools, and the third parties with access to them, not only the systems inside your SOC 2 boundary.
  3. Map your existing audits against the 18 components: Record where SOC 2 or ISO 27001 evidence already meets the Article 9 standard and where it does not, so the supplementation work under section 7123(f) is defined rather than guessed.
  4. Close the common gaps: Scope, CCPA-specific personal information inventories, vulnerability disclosure, MFA coverage across every in-scope category, and the components a Security-only SOC 2 leaves out.
  5. Choose your auditor path now. The firm that helps you prepare cannot audit you, and the queue for qualified auditors is expected to lengthen as 2028 approaches, so you need to put the two-party arrangement in place before readiness work starts.
  6. Check your vendor contracts: Section 7050(h) requires service providers and contractors to cooperate with your audit and give your auditor relevant information they hold; section 7051(a)(5) lets your contracts say so explicitly, and agreements signed before the regulations were final may not.
  7. Name the certifying executive and build the chain of confirmations that lets them sign: They will attest under penalty of perjury that nobody influenced the auditor, which means every person who dealt with the auditor should confirm in writing what they provided and how.

CCPA enforcement has grown quickly. None of it concerns Article 9 yet, as the certifications are not due. The California Attorney General settled with Healthline Media for $1.55 million in July 2025. The California Privacy Protection Agency imposed a $1.35 million penalty on Tractor Supply in September 2025. It was over broken opt-outs, ignored Global Privacy Control signals, stale privacy-policy disclosures, deficient notices to job applicants, and vendor contracts missing required terms. 

In 2026, the pace picked up: the Attorney General settled with Disney for $2.75 million in February, the agency fined PlayOn Sports $1.1 million in March, and in May the Attorney General, county district attorneys, and the agency together announced a $12.75 million settlement with General Motors over the sale of drivers’ location data and driving-behavior data without adequate notice or consent, the largest under the CCPA so far. 

Almost every case turned on an opt-out that did not work or data sold without notice. These are failures a consumer can feel. The statutory penalties behind those figures are $2,663 per violation and $7,988 per intentional violation and for each violation involving the personal information of a consumer under 16. Both ceilings are adjusted for inflation on the same schedule as the revenue threshold, and the next adjustment falls on January 1, 2027.

Penalties are not the only reason to start preparing. Section 7301(b) says that when the California Privacy Protection Agency decides whether to pursue an investigation, it may consider the time between a requirement taking effect and the alleged violation, along with good-faith efforts to comply. The regulations make documented early efforts something the regulator may weigh. The earlier the record starts, the more there is to weigh.

FAQs

Revenue alone does not decide it. Above the $26,625,000 threshold, you are in scope if you also processed the personal information of 250,000 or more California residents or households, or the sensitive personal information of 50,000 or more, in the preceding calendar year. Separately, and with no revenue or volume test at all, you are in scope if you derived 50% or more of your annual revenue from selling or sharing personal information. The $100 million threshold is timing: if your 2026 gross revenue exceeds it, you are in the first tier, with an audit period opening January 1, 2027, and a certification due April 1, 2028.

Possibly. The CCPA defines sharing as disclosing personal information to another company for cross-context behavioral advertising, whether or not money changes hands. Pixels and ad-platform integrations that pass identifiers about California residents can qualify. Sharing matters for the 50%-of-revenue condition and for the CCPA’s general applicability; it does not change the 250,000 or 50,000 head counts, which turn on processing.

Any company. The test is whether you do business in California and process California residents’ personal information above the section 7120 thresholds, wherever you are incorporated or headquartered. A company based in New York, Texas, India, or the UK is measured the same way as one in San Francisco.

January 1, 2026. The California Privacy Protection Agency’s board adopted the rules on July 24, 2025, and the Office of Administrative Law approved them on September 22, 2025. The first audit period opens January 1, 2027, and the first certifications are due April 1, 2028.

Most of the CCPA sets out consumer rights (to know, delete, correct, opt out) and the notices and contracts businesses owe. Article 9 imposes an obligation on the business’s security program itself: an annual audit by an independent professional against 18 named components, with an executive certification to the regulator. It is the only part of the CCPA regulations that requires an independent audit.

Not on its own. Section 7123(f) lets you build on an audit prepared for another purpose, but only where it meets every Article 9 requirement, with supplementation where it falls short. SOC 2 provides a foundation. Common shortfalls include scope (HR, applicant, and CRM systems outside the SOC 2 boundary), CCPA-specific personal information inventories, a formal vulnerability disclosure process, MFA coverage extending to contractors and service providers, and, for Security-only reports, business continuity and data retention.

No. Section 7122 bars the auditor from developing procedures, preparing documents, making recommendations about the program beyond articulating audit findings, or implementing or maintaining it. Plan for two separate parties, and start the search early.

Submit only the certification through the agency’s website by April 1. The report stays with your business. Both you and the auditor must keep it, with supporting documentation, for five years. It remains subject to subpoena.

A member of executive management who is directly responsible for cybersecurity-audit compliance, has sufficient knowledge of the audit to provide accurate information, and has authority to submit it. They sign under penalty of perjury.

No. Risk assessments sit in Article 10, use a different definition of ‘significant risk,’ and run on a separate timeline. Being out of scope for one says nothing about the other.

The audit obligation sits with the business. Service providers and contractors have their own duty under section 7050(h): for personal information they collect under their contract with you, they must cooperate with your audit, make relevant information available to your auditor, and not misrepresent facts the auditor considers relevant. Section 7051(a)(5) lets your contracts make that explicit. Check whether agreements signed before the regulations were final say so.

Sucheth
Author

Sucheth

Sucheth is a Content Marketer at Sprinto and holds CompTIA Security+. He helps security and GRC teams to navigate audits: what each framework requires, what auditors ask for, and what it costs to maintain.
Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
research & insights curated to help you earn a seat at the table.
single-blog-footer-img