

If your company sells or shares California residents’ personal information, there’s a new compliance deadline on your calendar, and it has nothing to do with cookie banners or opt-out links. Starting January 1, 2027, businesses that meet certain thresholds under the California Consumer Privacy Act need to complete an independent cybersecurity audit every year and certify the results to the state.
It’s a security requirement sitting inside a privacy law. Privacy officers have owned CCPA compliance for years but may not know about their organization’s latest penetration test results or be involved in setting secure application development standards. Security teams, meanwhile, have been mostly indirectly affected by California’s privacy statutes and regulations. This audit requirement sits right at the seam between privacy and security responsibilities, which is exactly where confusion destabilizes productivity, erodes trust, and paralyzes decision-making.
Who’s in scope, and when
Applicability isn’t just about revenue; its about risk to consumers. The California Privacy Protection Agency’s (CPPA) risk test considers two factors: 1) how much of a company’s revenue comes from selling or sharing personal information, and 2) how much personal information it processes. For example, the audit requirement would apply to a company earning $2 million per year if 50% or more of that revenue comes from selling or sharing California residents’ data. The audit requirement will also apply to a company that makes $25 million in annual revenue if that company processes the personal data of 250,000 California residents or sensitive data, such as debit card information, Social Security Number, or racial or religious data of 50,000 California residents. Companies that meet the relevant criteria in 2026 will be required to undergo an audit according to the following timeline

The audit is required every year when an organization meets the criteria.
Factors that can impact whether an organization meets the audit criteria go beyond organic growth. An acquisition, a new data-sharing deal, or the receipt of new data elements that fall in the “sensitive data” definition can pull a company overnight. It would be wise for organizations to monitor their data processing volume and types periodically each year.
How this differs from a SOC 2
Companies already undergoing SOC 2 or similar assessments sometimes assume this is more of the same. It’s true that some overlap between traditional security audit frameworks exists. Specifically, the regulators have identified AICPA, NIST, and ISO 27001 as acceptable foundations, but a few things go beyond a typical SOC 2 scope.

None of the California requirements are foreign to a mature security program. For example, the audit components include standards such as MFA, encryption, access controls, training, and incident response. The audit mostly forces documentation and independent verification of what is already in place.
Because this requirement lives inside a privacy statute, many people assume a law firm or privacy consultant can handle it. It’s a cybersecurity assessment, not a legal review. Businesses that navigate this well tend to get privacy and security talking early instead of treating it as one department’s problem.
What to do now

The audit period for the first tier starts January 1, 2027, less than a year out. The best practice is to ensure that controls that will be evaluated during the audit are already functioning by then, not assembled after the fact.
If you’re not sure where your business stands in relation to the California audit components or want an opinion on whether existing audit work would satisfy the CPPA’s requirements, contact Kirkpatrick Price.
You can read more about the CPPA’s regulations here: https://www.cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf
About the Author
Mark Hinely