Since Jan. 1, 2026, some businesses have focused on more immediate obligations under the updated California Consumer Privacy Act (CCPA) regulations, including risk assessments and automated decision-making technology (ADMT) requirements. However, for the largest businesses, another deadline is quickly approaching — the first audit period under the CCPA’s new cybersecurity audit rules.
The first audit period begins Jan. 1, 2027, and advance preparation may help businesses demonstrate a reasonable, well-documented cybersecurity program when the CPPA comes calling. Organizations subject to a CCPA cybersecurity audit should consider completing a cybersecurity readiness assessment under attorney-client privilege before recording any deficiencies in formal audits.
