Free 90-Day Post-Audit Support

CCPA/CPRA Cybersecurity Audit

California requires an independent annual cybersecurity audit of businesses whose processing presents significant risk to consumers. Independent is the operative word: it cannot be performed by the people who run the controls being examined. Our Certified Information Systems Auditors do exactly that work.

Get Your Quote

An Audit California Asks For by Name

Most privacy regulation tells you what outcome to achieve and leaves the method to you. The California Consumer Privacy Act (CCPA), as amended by the CPRA, is unusual in naming the mechanism: where a business’s processing of personal information presents significant risk to consumers, it must have an independent cybersecurity audit performed annually, by someone outside the function being audited. That is an audit engagement, not a policy review, and it is the work this firm does.

The obligation reaches further than California addresses. It follows the personal information of California residents, so a business in Texas or Ontario handling enough of it can fall inside the rule while a business in San Jose handling very little does not. Whether it applies to you is a question about your processing, not your postcode, and it is the first thing we establish.

What the Audit Examines

The subject is the security of personal information: the controls that protect it, and whether they work in practice rather than on paper.

CCPA Compliance and the CCPA Cybersecurity Audit Are Not the Same Thing

This is the distinction that gets scoped wrong most often. Broad CCPA compliance is about consumer privacy rights and transparency: your notice at collection, honoring requests to know, delete, correct, and opt out, and the disclosures that go with them. That work is part of our privacy audit. The cybersecurity audit is a narrower and deeper thing: an independent examination of the security controls protecting personal information. A business can be scrupulous about honoring deletion requests and still have no audit of the safeguards around the data it keeps.

The California law most often confused with both is a third one again. Pixels, session replay, and chat widgets that can read what a visitor types raise wiretapping exposure under CIPA, which has nothing to do with the CCPA cybersecurity audit and is covered by our CIPA website tracking audit. Getting these three separated before an engagement starts saves scoping the wrong one.

Why It Has to Be Independent

An audit whose findings can be edited by the people responsible for the findings is not an audit, and California asks for independence for that reason. Our auditors hold the Certified Information Systems Auditor credential, report to you rather than to your IT function, and have no product, platform, or managed service to sell you afterwards. Where you need to show a customer or a board that the work was done and by whom, our auditor opinion letter states what was examined and what we found, under our own credential.

Deliverables

Audit Report

Each control examined, what we tested it against, what we found, and a risk rating. Findings come with remediation steps specific enough for your team to act on without further interpretation.

Evidence Record

The documentation an auditor has to be able to point to: what was examined, when, by whom, and on what basis each conclusion was reached. This is the part that matters if anyone ever asks you to prove the audit happened.

90 Days of Support

Ninety days of free post-audit support while you remediate, so questions reach the auditor who did the work rather than a help desk.

Frequently Asked Questions

It applies where a business’s processing of consumers’ personal information presents significant risk to their security. That is a question about what you process and how much, not about where you are based, and the thresholds are set by regulation rather than by us. Scoping it is the first thing we do, and we will tell you if the answer is that you do not need one.

Yes. The obligation follows the personal information of California residents rather than your own location, so businesses elsewhere in the United States and outside it can fall inside the rule. Conversely, being in California does not by itself put you inside it.

Not if it is to satisfy the requirement. The audit has to be independent of the function being audited, which rules out the people who build and run the controls, and in practice rules out an internal team reporting to the same leadership. This is the same reasoning that keeps a company’s finance team from auditing its own accounts.

No. Broad CCPA compliance covers consumer rights and transparency: notice at collection, and honoring requests to know, delete, correct, and opt out. The cybersecurity audit is a separate, narrower examination of the security controls that protect personal information. You can be doing the first well and have never had the second done.

Not on its own. A SOC 2 report is issued by a CPA firm against trust services criteria chosen for that engagement, and its scope is set by you and your auditor rather than by California. There is useful overlap in the control areas, and we are often asked to map the two so evidence is gathered once rather than twice, but one is not a substitute for the other.

Different California law, different problem. CIPA exposure comes from advertising pixels, session replay, and chat widgets that can read what a visitor types on your site, and it is assessed against your consent flow and disclosures. The CCPA cybersecurity audit examines the controls protecting personal information you hold. Both sit in our privacy audit, but they are scoped and reported separately.

Your data inventory and the systems holding personal information, access and authentication configuration, encryption and key management settings, logging and monitoring output, vulnerability and patch records, vendor contracts and oversight, incident response documentation, and training records. Where evidence does not exist yet, that absence is itself a finding, and it is better to discover it with us than later.

Annually, for as long as your processing continues to present significant risk. Repeat engagements are faster than the first, because the inventory, the evidence trail, and the scope are already established, and the second year focuses on what changed and on what the first year found.

Talk to a CISA-Certified Auditor

Other Services