Annual independent cybersecurity audits
Summary
Businesses that meet specified revenue and data-volume thresholds must complete an annual independent cybersecurity audit and certify completion to the CPPA, with first certification dates staggered by revenue from 1 April 2028.
Read the full official text: https://www.cppa.ca.gov/regulations/ccpa_updates.html
← Section 0
Risk assessments for processing that presents significant risk
Section 0 →
ADMT notice, opt-out and access rights
Track CCPA section 0 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial