California’s new cybersecurity audit requirements under the CCPA are approaching, and companies that collect or process California residents’ personal information should be preparing now. Covington has been helping clients navigate these requirements in real time and has developed practical readiness materials, scoping frameworks, and benchmarking insights that companies can leverage when doing so. In this alert, we outline the new requirements, explain which companies may be in scope, identify key timing considerations, and highlight practical steps companies can take now to be audit-ready by January 1, 2027.
What the Requirements Are: Under the CCPA’s cybersecurity audit requirements, covered companies will need to conduct detailed annual cybersecurity audits across numerous control areas, document in written audit reports whether their cybersecurity programs and controls satisfy these requirements, and certify compliance to CalPrivacy. The requirements are phased in over time based on companies’ revenue and processing activities, with the first wave of certifications for audits covering calendar year 2027 due on April 1, 2028.
Why They Might Apply to You: The audit requirements apply based on the volumes of California residents’ personal information processed, and the definition of personal information is exceptionally broad, including data elements such as IP addresses, device identifiers, and other online identifiers. As a result, companies that may not view themselves as handling personal data (or that might have viewed themselves as out of scope because they don’t handle sensitive types of personal data) could still fall within scope depending on the volume and types of California residents’ data that they process.
Why Q3/Q4 2026 Is the Time to Act: Although the first certifications will not be due until 2028, the first audit period will cover the entirety of 2027. Companies should aim to be audit-ready by January 1, 2027 to reduce the risk that the required audit report could document cybersecurity weaknesses in a detailed and potentially discoverable format. Key questions to consider that may require significant lead time to resolve include not only whether a company’s cybersecurity program is compliant, but also how to structure and scope the audit and who should conduct it.
How Covington Can Help: Covington has been working through these issues with clients across sectors and has built a body of practical work product that can be tailored quickly to a company’s needs, including:
- Applicability and scoping analyses;
- Privileged readiness assessments;
- Benchmarking against emerging practices; and
- Audit preparation and structuring.
We can support this work efficiently, including through office-hour consultations, targeted privileged readiness assessments, template forms and documentation, and fixed-fee arrangements. If you would like to discuss how these requirements may apply to your organization or how Covington can help with readiness planning, please feel free to reach out to any of the points of contact below.