California's New Cybersecurity Audit Law: Are You Covered?

Most businesses outside California assume the state's privacy law is someone else's problem. It usually isn't. California's Consumer Privacy Act applies based on whose data you handle, not where your office sits, and new cybersecurity audit and risk assessment rules under the law took effect January 1, 2026. A wave of law firm advisories in the past two weeks is telling clients to stop treating this as a future deadline. Most companies in the 25 to 250 employee range will not trigger the mandatory audit requirement yet. But the risk assessment piece can apply regardless of size, and it is worth five minutes to check where you actually stand.

What Actually Changed

The California Privacy Protection Agency finalized regulations that add two new obligations on top of the existing CCPA:

Cybersecurity audits. Businesses that meet a "significant risk" threshold now have to run an annual cybersecurity audit performed by a qualified, independent auditor, covering 18 specific program components: asset inventory, access controls, authentication, encryption, logging and monitoring, and more. The business then certifies completion to the CPPA under penalty of perjury.

Privacy risk assessments. Before starting certain high-risk processing activities, like selling personal information, handling sensitive personal data, or using automated decision-making for significant consumer decisions, a business now has to document a risk assessment and eventually report a summary to the CPPA.

Both obligations are already in effect. The audit certification deadlines are phased by revenue, which is where most 25 to 250 employee businesses get a longer runway than the headlines suggest.

Who Actually Has to Do the Audit

The audit requirement only kicks in if a business hits one of two triggers:

  1. It derives 50% or more of its annual revenue from selling or sharing personal information, regardless of total revenue or company size. Or
  2. It has gross annual revenue above roughly $26.6 million (the CCPA's original $25 million threshold, adjusted for inflation) and, in the prior calendar year, processed the personal information of 250,000 or more consumers, or the sensitive personal information of 50,000 or more consumers.

A 60-person professional services firm doing $12 million in revenue is not going to hit that second trigger. A 150-person e-commerce or SaaS company doing $30 million in revenue with a large customer database might. If you are not sure which side of that line you fall on, it usually comes down to how many individual consumer records you actually touch in a year, not your headcount.

For businesses that do meet the threshold, the first certification deadlines are staggered: April 1, 2028 for companies over $100 million in revenue, April 1, 2029 for companies between $50 and $100 million, and April 1, 2030 for companies under $50 million. That is real lead time, but auditor engagement and the underlying gap analysis take months, not weeks.

The Risk Assessment Rule Catches More Businesses

The audit trigger is about size and volume. The risk assessment trigger is about what you are doing, and it does not care how many employees you have.

If your business sells or shares personal information, processes sensitive personal information (health, financial account numbers, precise geolocation, and similar categories), or uses automated decision-making for anything that produces a legal or similarly significant effect on a consumer, like credit decisions, employment screening, or pricing that varies by individual, you may already need a documented risk assessment before that processing starts. A growing business running an AI tool to screen job applicants or price services dynamically for different customers can trip this wire well before it ever approaches the audit revenue threshold.

Existing high-risk processing that started before January 1, 2026 has until December 31, 2027 to be assessed, with the first CPPA submission due by April 1, 2028.

Why This Applies Even If Your Office Is in Hoboken

The CCPA's reach is based on whose data a business processes, not where the business is headquartered. A company in Parsippany that sells nationally through an online store, or a professional services firm with California-based clients, can be a covered business under the CCPA regardless of physical location. Growing businesses that assumed state privacy laws were a California-only or a New York-only concern are increasingly finding that a single multi-state customer base pulls in several overlapping compliance regimes at once.

What to Actually Do About It This Quarter

Three things are worth doing now, whether or not you clearly trigger the audit requirement:

Figure out your actual numbers. Pull last year's data on consumer records processed and revenue from data sale or sharing. Most businesses have never calculated this and are guessing.

Inventory your automated decision-making. If any tool your business uses screens applicants, sets prices, or approves or denies anything for individual consumers without a human in the loop, that is a candidate for the risk assessment requirement regardless of your revenue.

Map the 18 audit components against what you already have. Even businesses years away from a mandatory audit benefit from knowing where their access controls, encryption, and logging stand against a recognized framework. It's the same work a managed IT partner already tracks as part of an ongoing security program, and closing gaps now costs far less than doing it under a certification deadline.

FAQ

Does the CCPA cybersecurity audit apply to small businesses? Only if a business meets specific revenue and data-volume thresholds, roughly $26.6 million in annual revenue combined with processing 250,000+ consumer records, or deriving half its revenue from selling personal data. Most businesses under 250 employees fall below this line, though fast-growing companies with large customer databases should check.

What is the difference between the audit requirement and the risk assessment requirement? The audit requirement is triggered by company size and data volume. The risk assessment requirement is triggered by the type of processing activity, like automated decision-making or selling sensitive data, and can apply to smaller businesses that engage in those specific activities.

When are the first CCPA cybersecurity audit deadlines? April 1, 2028 for businesses with 2026 revenue over $100 million, April 1, 2029 for businesses between $50 and $100 million, and April 1, 2030 for businesses under $50 million.

Does this apply to businesses outside California? Yes. The CCPA applies based on the personal information of California consumers a business processes, not where the business is physically located. A business with California customers can be covered regardless of headquarters location.

What counts as automated decision-making under the new rules? Tools that make or materially influence decisions with a legal or similarly significant effect on a consumer, such as credit approval, employment screening, or individualized pricing, without meaningful human review.

Figuring out whether your business trips these thresholds, and building the access controls, logging, and documentation an audit or risk assessment expects, is exactly the kind of ongoing work a managed IT partner handles. Get in touch to talk through where your business actually stands.