what CCPA-covered businesses need to know before 2027


by Mark Hinely / September 10th, 2026

If your company sells or shares California residents’ personal information, there’s a new compliance deadline on your calendar, and it has nothing to do with cookie banners or opt-out links. Starting January 1, 2027, businesses that meet certain thresholds under the California Consumer Privacy Act need to complete an independent cybersecurity audit every year and certify the results to the state.

It’s a security requirement sitting inside a privacy law. Privacy officers have owned CCPA compliance for years but may not know about their organization’s latest penetration test results or be involved in setting secure application development standards. Security teams, meanwhile, have been mostly indirectly affected by California’s privacy statutes and regulations. This audit requirement sits right at the seam between privacy and security responsibilities, which is exactly where confusion destabilizes productivity, erodes trust, and paralyzes decision-making.

Who’s in scope, and when

Applicability isn’t just about revenue; its about risk to consumers. The California Privacy Protection Agency’s (CPPA) risk test considers two factors: 1) how much of a company’s revenue comes from selling or sharing personal information, and 2) how much personal information it processes. For example, the audit requirement would apply to a company earning $2 million per year if 50% or more of that revenue comes from selling or sharing California residents’ data. The audit requirement will also apply to a company that makes $25 million in annual revenue if that company processes the personal data of 250,000 California residents or sensitive data, such as debit card information, Social Security Number, or racial or religious data of 50,000 California residents. Companies that meet the relevant criteria in 2026 will be required to undergo an audit according to the following timeline

The audit is required every year when an organization meets the criteria. 

Factors that can impact whether an organization meets the audit criteria go beyond organic growth. An acquisition, a new data-sharing deal, or the receipt of new data elements that fall in the “sensitive data” definition can pull a company overnight. It would be wise for organizations to monitor their data processing volume and types periodically each year.

How this differs from a SOC 2

Companies already undergoing SOC 2 or similar assessments sometimes assume this is more of the same.  It’s true that some overlap between traditional security audit frameworks exists. Specifically, the regulators have identified AICPA, NIST, and ISO 27001 as acceptable foundations, but a few things go beyond a typical SOC 2 scope.

None of the California requirements are foreign to a mature security program. For example, the audit components include standards such as MFA, encryption, access controls, training, and incident response. The audit mostly forces documentation and independent verification of what is already in place.

Because this requirement lives inside a privacy statute, many people assume a law firm or privacy consultant can handle it. It’s a cybersecurity assessment, not a legal review. Businesses that navigate this well tend to get privacy and security talking early instead of treating it as one department’s problem.

What to do now

The audit period for the first tier starts January 1, 2027, less than a year out. The best practice is to ensure that controls that will be evaluated during the audit are already functioning by then, not assembled after the fact.

If you’re not sure where your business stands in relation to the California audit components or want an opinion on whether existing audit work would satisfy the CPPA’s requirements, contact Kirkpatrick Price. 

You can read more about the CPPA’s regulations here: https://www.cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf

About the Author

Mark Hinely

As an auditor and attorney with over 15 years of industry experience, Mark helps organizations identify and resolve regulatory compliance and data privacy risks so that they can improve operational effectiveness, reduce the likelihood of legal sanctions, ensure customer satisfaction, and grow their business. Mark, who has practiced law in both public and private sectors, as well as performed in-house compliance work for various healthcare companies, is passionate about helping organizations understand privacy regulations and stay compliant. Mark has been working with KirkpatrickPrice for 8 years and is responsible for leading and creating our Privacy Assurance Services.

We will be happy to hear your thoughts

Leave a reply

Som2ny Network
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart