§ 7120RegulationReference only

Requirement to Complete a Cybersecurity Audit

In force from January 1, 2026Reviewed September 2026

Reference only: This requirement is not currently tested by the Privisy scanner. It is included for reference. Consult a qualified attorney to assess your compliance posture.

What it requires

Article 9, added by the CCPA Updates rulemaking operative January 1, 2026, makes an annual independent cybersecurity audit a standing obligation rather than an enforcement remedy. Two triggers put a business in scope under subsection (b): deriving 50 percent or more of annual revenue from selling or sharing personal information, or meeting the § 1798.140(d)(1)(A) revenue threshold ($26,625,000 as adjusted) and having processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the preceding calendar year. The audits phase in by size under § 7121(a): the first report is due April 1, 2028 for a business whose 2026 annual gross revenue exceeded $100,000,000, April 1, 2029 where 2027 revenue was between $50,000,000 and $100,000,000, and April 1, 2030 where 2028 revenue was under $50,000,000. Section 7124 then requires a written certification of completion, signed by a member of executive management, submitted to the Agency by April 1 following each year an audit was required.

Legal text (excerpt)

(a) Every business whose processing of consumers’ personal information presents significant risk to consumers’ security as set forth in subsection (b) must complete a cybersecurity audit. (b) A business’s processing of consumers’ personal information presents significant risk to consumers’ security if any of the following is true: (1) The business meets the threshold set forth in Civil Code section 1798.140, subdivision (d)(1)(C), in the preceding calendar year; or (2) The business meets the threshold set forth in Civil Code section 1798.140, subdivision (d)(1)(A); and (A) Processed the personal information of 250,000 or more consumers or households in the preceding calendar year; or (B) Processed the sensitive personal information of 50,000 or more consumers in the preceding calendar year.

California Consumer Privacy Act / California Privacy Rights Act: § 7120, Regulation, in force from 2026

Primary source

California Privacy Protection Agency (CalPrivacy): § 7120: Requirement to Complete a Cybersecurity Audit

Legal notice: This page is for informational purposes only and does not constitute legal advice. The legal text excerpt is reproduced from official public sources and is current as of the stated effective date. Laws change: verify against the authoritative source and consult a licensed attorney for compliance guidance.

Stop Guessing. Start Knowing.

Find out exactly where your website stands before a regulator does.

Get My Compliance Audit