California’s cybersecurity audit rule is now in force. Under Article 9 of the CCPA regulations, businesses that process enough California residents’ data must run an annual, independent cybersecurity audit and certify it to the state. This guide covers the requirements: who is in scope, what the audit assesses, who can perform it, who signs off, and when it is due.
CCPA Article 9 requirements at a glance
Article 9 is set out across sections 7120 to 7124 of the final CCPA regulations.
| Requirement | What you need to do |
|---|---|
| Check whether Article 9 applies | Compare your revenue and California data volumes with the section 7120 thresholds |
| Complete the audit every year | Audit the required 12-month period, complete the report, and file the certification by the applicable April 1 deadline |
| Use an independent auditor with real evidence | Appoint a qualified auditor who did not build the program, and give them evidence rather than assurances |
| Assess the program and the 18 components | Review the documented program and each applicable component under section 7123 |
| Produce the report and certify completion | Record scope, evidence, findings, and remediation; retain records for five years; file the executive certification |
Requirement 1: Check whether Article 9 applies to your business
Article 9 does not apply to every CCPA business. It applies only where your processing of personal information presents a “significant risk to consumers’ security.”
The three routes that put you in scope
Section 7120 defines significant risk through two conditions, the second carrying two alternative volume tests — three routes in practice. Meeting any one puts you in scope:

- You derived 50% or more of your annual revenue from selling or sharing consumers’ personal information in the preceding calendar year. No minimum company size.
- Your annual gross revenue exceeded $26,625,000, and you processed the personal information of 250,000 or more California residents or households, both in the preceding calendar year.
- Your annual gross revenue exceeded $26,625,000, and you processed the sensitive personal information of 50,000 or more California residents, both in the preceding calendar year.
Two nuances decide most borderline cases:
- “Consumer” means any California resident in any relationship with you: customer, employee, job applicant, or a contact in your CRM. Because employees and business contacts count, a B2B company that sells no data can still cross the 250,000 threshold.
- The revenue figure is worldwide; the population counts are California-only. Revenue is total gross revenue from all sources. The 250,000 and 50,000 counts include only California residents.
Article 9 applies to any for-profit company that does business in California, whatever its industry or where it is headquartered. The $26,625,000 figure is the CCPA business threshold, adjusted for inflation and current for 2025-2026.

Not sure which side of the line you fall on?
Run your own numbers against all three conditions and see your result, revenue tier, and audit period in 90 seconds.Note on scope: The audit boundary is not limited to databases labeled “California data.” It follows the systems that process, access, or protect that personal information, which can include identity and access, cloud, employee devices, HR, applicant-tracking, CRM, logging, backup, and service-provider systems, though not every system automatically.
Requirement 2: Complete the audit every year

CCPA cybersecurity audits are annual for businesses that meet the Article 9 criteria. This is not a certification you complete once and leave behind. The first cycle is phased in by gross revenue.
| Revenue band for an in-scope business | First audit period | Report completed and certification filed by |
|---|---|---|
| More than $100M in 2026 | Jan 1, 2027 to Jan 1, 2028 | April 1, 2028 |
| $50M to $100M in 2027 | Jan 1, 2028 to Jan 1, 2029 | April 1, 2029 |
| Less than $50M in 2028 | Jan 1, 2029 to Jan 1, 2030 | April 1, 2030 |
After April 1, 2030, the cycle repeats. Each January 1, you look back at the year that just ended: if you met the Section 7120 criteria during it, your audit covers the next 12 months, and the report is due by April 1 of the following year.
For the earliest group, the date that matters isn’t just April 1, 2028. Your controls must have been running and producing evidence from January 1, 2027, because you cannot reliably rebuild a year of access reviews, training records, vulnerability fixes, or backup tests after the audit period ends.
Requirement 3: Use an independent auditor, and give them evidence
Section 7122 sets out two tests: who is allowed to run the audit, and on what the audit must be built.
Who can perform the audit
Your auditor may be internal or external. Either way, they must:
- Understand cybersecurity and know how to audit a cybersecurity program
- Follow procedures accepted by bodies such as the AICPA, PCAOB, ISACA, or ISO
- Make objective, impartial decisions, free of pressure from the business
No single auditor certification is required.
Who cannot perform the audit
Independence is the harder test. The auditor cannot be anyone who helped build or run the program being audited. That excludes anyone who:
- Developed the procedures being audited
- Prepared your cybersecurity documents
- Recommended changes to the program, beyond reporting findings
- Implemented or maintained the program
The practical consequence: the firm that helps you get ready is disqualified from the audit of record, so plan for two separate parties. If you use an internal auditor, the highest-ranking auditor must report to a member of executive management who does not have direct responsibility for the cybersecurity program, and an executive meeting that same description must conduct their performance review and determine their pay. That rules out the CISO or anyone who owns security.
What the audit must be built on
Section 7122(d) sets the evidence standard in one sentence: “No finding of any cybersecurity audit may rely primarily on assertions or attestations by the business’s management.” Findings must rest primarily on specific evidence the auditor deems appropriate – documents reviewed, sampling and testing performed, and interviews conducted. This applies to every component the auditor assesses, and it is what separates Article 9 from a questionnaire-driven review.
The obligation runs both ways. Under section 7122(b) you must make available to the auditor all information in your possession, custody, or control that they request as relevant to the audit, including information about your cybersecurity program, your information system, and your use of service providers and contractors. Under section 7122(c) you must make good-faith efforts to disclose all facts relevant to the audit, and must not misrepresent any of them.
Requirement 4: Assess your cybersecurity program and the 18 components
Section 7123(a) sets the objective. The audit must assess how your cybersecurity program protects personal information from unauthorized access, destruction, use, modification, or disclosure, and how it protects against unauthorized activity resulting in the loss of availability of personal information. Everything below serves that test.
The auditor checks two things: whether you have a documented cybersecurity program that fits your size, complexity, and processing, and whether you follow it day-to-day. They then review each applicable component listed in section 7123.

The 18 CCPA Article 9 components
The regulation refers to these as cybersecurity program components. The auditor assesses each applicable one separately and documents the evidence behind the finding.
| # | Component | What it covers | Evidence you may need |
|---|---|---|---|
| 1 | Authentication | MFA, phishing-resistant MFA, strong passwords | IdP settings, MFA enrollment, password configs |
| 2 | Encryption | Personal information at rest and in transit | Storage encryption, TLS, key-management records |
| 3 | Account management and access controls | Least privilege, privileged accounts, joiner-mover-leaver, physical access | Access reviews, JML records, PAM logs, badge records |
| 4 | Personal information and system inventory | Data maps, classifications, asset inventories | Data-flow maps, asset registers, classification records |
| 5 | Secure configuration | Patching, hardening, masking, change management | Config baselines, patch reports, change tickets |
| 6 | Vulnerability management | Scans, penetration tests, disclosure program | Scan and pen-test results, bug-bounty and remediation records |
| 7 | Audit-log management | Centralized log storage, retention, monitoring | SIEM settings, retention rules, log-review records |
| 8 | Network monitoring and defenses | Intrusion detection or prevention, data-loss prevention | Alerts, IDS or IPS settings, DLP policies |
| 9 | Anti-malware | Protection against malicious software | Endpoint coverage, detections, quarantine records |
| 10 | System segmentation | Separation of networks and sensitive systems | Network diagrams, firewall rules, segmentation tests |
| 11 | Ports, services, and protocols | Restriction of unnecessary or risky services | Port scans, approved-service lists, exception records |
| 12 | Cybersecurity awareness | Staying current on new threats | Threat briefings, advisories, security updates |
| 13 | Cybersecurity training | Onboarding, annual, and post-breach training | Completion records, training content, post-breach logs |
| 14 | Secure development | Code review, testing, secure practices | Review records, SAST or DAST results, release approvals |
| 15 | Third-party oversight | Service providers, contractors, third parties | Vendor inventory, assessments, contracts, reassessments |
| 16 | Retention and secure disposal | Retention schedules and secure destruction | Retention rules, deletion logs, destruction certificates |
| 17 | Incident response | Detecting, handling, and recovering from incidents | IR plan, tabletop exercises, incident records |
| 18 | Business continuity and disaster recovery | Continuity plans, recovery, backups | BCP and DR plans, backup logs, restoration tests |

Every item in the evidence column has to exist for the whole audit period, dated as it happened.
See how Sprinto collects evidence for the 18 components.Requirement 5: Produce the report and certify completion
The report has to show what the auditor reviewed, the evidence used, what they found, and what you plan to fix. Under section 7123(e), it must include:
- Your information system, and the policies, procedures, and practices reviewed
- The audit criteria, and the documents, samples, tests, and interviews examined
- Which of the 18 components were treated as applicable, and how your program implements each
- An assessment of how effective the program and controls are
- Any gaps or weaknesses, with a remediation plan and timeline for each
- Any corrections to earlier audit reports
- The titles of up to three people responsible for the program, and the auditor’s name, affiliation, and qualifications
- A statement signed and dated by the highest-ranking auditor that the review was independent, impartial, and evidence-based
- Any consumer breach notifications and regulator notifications, where applicable
The regulation does not want a “pass” or “fail.” It wants effectiveness explained, weaknesses named, and remediation dated.
Once complete, the report is sent to an executive responsible for the cybersecurity program, and you and the auditor retain all audit records, including supporting evidence, for at least 5 years. Separately, a member of executive management files a certification with the CPPA by April 1. The two documents are different:
| Audit report | Executive certification |
|---|---|
| Prepared by the auditor | Completed by an authorized executive |
| Contains scope, evidence, findings, gaps, and remediation | Confirms the required audit was completed |
| Given to the executive over the program, kept five years | Submitted to the CPPA, filed by April 1 |
The certifying executive must be directly responsible for Article 9 compliance, know enough about the audit to be accurate, have authority to file, and sign under penalty of perjury that the audit was completed and that the business did not try to influence the auditor. Only the certification goes to the CPPA. The full report stays with you.

Can you reuse SOC 2, ISO 27001, or NIST evidence?
Yes, but an existing audit does not automatically satisfy Article 9. Section 7123(f) lets you use an audit or assessment done for another purpose if it meets every Article 9 requirement on its own or with supplementation. The regulation names an audit based on NIST CSF 2.0 as an example.
| Existing program | What you may reuse | What you still need to check |
|---|---|---|
| SOC 2 Type II | Control descriptions, testing, access reviews, monitoring and operating evidence | System boundary, Article 9 report contents, all 18 components, audit period, certification |
| ISO 27001 | ISMS policies, risk records, asset inventories, internal audits, corrective actions | California-specific scope, Article 9 evidence, auditor independence, certification |
| NIST CSF 2.0 | Cybersecurity outcomes, profiles, risk activities, control mappings | Whether it meets every Article 9 reporting and evidence requirement |
Common gaps include scope (HR, applicant, and CRM systems outside a SOC 2 boundary), a CCPA-specific personal information inventory, a formal vulnerability disclosure process, phishing-resistant MFA extended to contractors, and, for Security-only SOC 2 reports, business continuity and the depth of retention and disposal coverage. For a fuller comparison, see SOC 2 vs ISO 27001.
Keep CCPA Article 9 evidence current with Sprinto
Sprinto’s Autonomous Trust Platform is built to produce the evidence that Article 9 rewards: proof that your controls ran throughout the entire audit period. It interprets the regulation into live controls, maps them to your environment, and keeps one control set aligned across CCPA, SOC 2, ISO 27001, and NIST, so the same evidence works for several programs.
Autonomous evidence collection captures timestamped records from your cloud, identity, HR, and device systems, continuous monitoring flags control drift before it becomes a finding, and the platform covers the 18 domains an auditor examines, from access reviews and vulnerability management to vendor oversight and security training.
Sprinto handles the readiness and evidence work, not the audit itself, so you still engage an independent auditor and file the executive certification.

FAQs
Author
Radhika Sarraf
Radhika Sarraf is a content marketer at Sprinto, where she explores the world of cybersecurity and compliance through storytelling and strategy. With a background in B2B SaaS, she thrives on turning intricate concepts into content that educates, engages, and inspires. When she’s not decoding the nuances of GRC, you’ll likely find her experimenting in the kitchen, planning her next travel adventure, or discovering hidden gems in a new city.Explore more
research & insights curated to help you earn a seat at the table.















![CCPA Compliance Checklist for 2026 [Steps, Requirements and Penalties]](https://sprinto.com/wp-content/uploads/2023/10/Copy-of-Blog_335_What-is-compliance-as-a-service-01-1024x470.jpg)











