BLOG
September 29, 2026
decorative
Travis Good

CCPA Cybersecurity Audits Are Live - Does Your SaaS Need One?

Not every CCPA business needs an annual cyber audit. Significant-risk thresholds, the 2028 certification clock, and what SaaS vendors should prepare.
Illustration for CCPA cybersecurity audits and SaaS vendors

A California-covered customer asks whether you can support their CalPrivacy cybersecurity audit - SOC 2 Type II, PI flow maps, MFA evidence that reaches service providers, and a contractual promise that you will cooperate when their auditor shows up. Meanwhile your own counsel asks a different question: does your SaaS itself owe CalPrivacy an annual independent cybersecurity audit?

Short answer: Not every CCPA "business" needs an annual cybersecurity audit. The obligation hits businesses whose processing meets CalPrivacy's significant risk thresholds - not every company that already posts a CCPA notice. And even if you are below those thresholds, covered customers' audits reach third-party environments that process California personal information, so vendor cooperation and evidence packs become a GTM problem either way.

This post owns California's general-applicability cybersecurity audit regime and what covered customers demand from SaaS service providers. It is not a rewrite of the US state privacy patchwork, NYDFS Part 500 for NY financial TPSPs, or SEC cyber disclosure for public-company incident SLAs. ADMT and risk assessments appear only as related clocks.

Does every CCPA business need an annual cybersecurity audit?

No. Per Forvis Mazars (26 May 2026) and Troutman Pepper Locke (18 May 2026), the audit obligation applies when a CCPA business meets significant-risk thresholds, including:

1. Revenue from selling/sharing: 50% or more of annual revenue from selling or sharing personal information; or

2. Revenue + volume: more than $26.625 million in annual gross revenue in the preceding calendar year, and either processed personal information of 250,000+ consumers or households, or processed sensitive personal information of 50,000+ consumers.

Those dollar and volume figures are attributed to those 2026 write-ups - confirm with counsel for your facts and any later inflation adjustments. The thresholds can still catch teams that do not think of themselves as "high risk," including products that process large volumes of basic identifiers and contact data.

Run the analysis as a short written memo, not a hallway opinion. Pull prior-year gross revenue, decide whether any monetization path is "selling" or "sharing" under CCPA definitions, and count California consumers, households, and sensitive PI with the same inventory muscle you already need for notices and DSRs. If you are a SaaS service provider that does not hit these floors yourself, you may still sit inside a covered customer's audit scope whenever you store, process, or access their California PI. That vendor angle returns after the clock and the program components.

When do the rules bite - and when is the first certification due?

CalPrivacy finalized the cybersecurity-audit package (alongside risk-assessment and ADMT rules) in September 2025. The regulations became effective 1 January 2026. Program expectations start then. The phased schedule governs when formal audit periods begin and when certifications must be filed - not when the duty to protect California consumer data starts.

Troutman and Forvis Mazars summarize the revenue tiers as follows:

Group 1 (more than $100 million gross revenue): initial audit period from 1 January 2027; certification due 1 April 2028.

Group 2 ($50 million to $100 million): audit period from 1 January 2028; certification due 1 April 2029.

Group 3 (less than $50 million): audit period from 1 January 2029; certification due 1 April 2030.

After the first cycle, annual coverage continues with no intentional gaps. Waiting until late 2027 to invent a PI inventory or vendor-oversight trail for a Group 1 business is how teams miss an auditable period that already started. Auditor capacity is widely expected to tighten as April 2028 approaches - early engagement is a practical constraint, not marketing copy.

Related clocks, briefly: privacy risk assessments under the sibling Article 10 rules run on their own schedule (attestation themes commonly discussed toward April 2028 for covered businesses). ADMT obligations phase separately (consumer-facing automated decisionmaking rights often discussed from January 2027). Neither topic gets a full explainer here; treat them as calendar siblings to the cybersecurity audit, not substitutes for it. For California baseline context beyond audits, keep Workstreet's CCPA framework open beside this post.

What does the audit evaluate?

CalPrivacy does not replace SOC 2 or ISO with a brand-new checklist of mandatory products. Auditors evaluate roughly 18 cybersecurity program components on a risk-based, "to the extent applicable" standard that accounts for size, complexity, and processing. Troutman's five-framework comparison (NIST CSF 2.0, NYDFS Part 500, CIS Controls v8.1, ISO/IEC 27001:2022) is a useful map of where CCPA is similar and where it asks for California-specific supplements.

Representative components include authentication (with phishing-resistant MFA framing across employees, contractors, and - where applicable - service providers); encryption at rest and in transit; account management and least privilege (including physical access themes where relevant); personal information inventories tied to CCPA definitions and California PI/SPI categories; secure configuration and patch/change management; vulnerability scanning, penetration testing, and a vulnerability disclosure process (a VDP and/or bug bounty can satisfy); audit logging; network monitoring and defenses; malware protections; segmentation; port and protocol hygiene; cybersecurity awareness as distinct from education/training; secure development practices; oversight of service providers, contractors, and third parties with audit cooperation themes; retention and disposal of personal information; security-incident response (including samples of breach notifications during the audit period); and business continuity and recovery.

Independence matters. Internal or external auditors can qualify if they are objective and did not design or maintain the program under review. Internal auditors need a reporting line that is not grading its own homework - typically to an executive without direct cybersecurity-program responsibility. Forvis Mazars emphasizes evidence over assurances: documents, sampling, interviews, configs, logs, tickets, training records, and third-party reports such as SOC 2 where appropriate.

On filing mechanics, covered businesses typically certify completion to CalPrivacy by the April 1 deadline for the relevant cycle. The full audit report is retained (commonly discussed as five years by both business and auditor) and may be produced if CalPrivacy requests or subpoenas it - it is not automatically filed with every certification. That split matters for how you stage privileged gap work before a discoverable formal report exists.

Can SOC 2 or ISO carry the load?

Often as a foundation - not as a free pass. CalPrivacy's Regulatory Impact Assessment, as summarized by Troutman, estimates that organizations with existing frameworks (CSF, CIS, ISO 27001, SOC 2 Type II) can reduce compliance cost by roughly 30% when they leverage overlap instead of rebuilding from zero. Attribute that estimate to the RIA / Troutman write-up; do not treat it as a guarantee for your stack.

Troutman flags three supplementation areas that mature SOC 2 / ISO programs still miss most often:

1. PI inventories and classification mapped to CCPA personal information and sensitive PI definitions - more granular than a generic asset inventory. If you already keep EU processing records, ROPA-style records are reusable muscle, not a substitute label.

2. A formal vulnerability disclosure process - something many Type II reports never sample because the control was never designed.

3. Phishing-resistant MFA scope that auditors will evaluate for broader user populations, including contractors and service-provider access patterns - not only privileged admins on a laptop fleet.

Use your existing Type II report, ISO statement of applicability, and NIST CSF profile as the control spine. Then add CCPA-specific evidence: California PI data maps, VDP submissions and SLAs, MFA rollouts that cover the populations the auditor will sample, and vendor files that prove oversight - not just a signed DPA PDF. For how buyers already ask for this packaging day to day, see SOC 2 vs security questionnaires.

What will covered customers demand from SaaS vendors?

Forvis Mazars is explicit: the audit follows California personal information wherever it travels - company systems, cloud apps, backups, and third-party environments used to process or access that data. Troutman notes that contractual audit cooperation is a CCPA-distinct theme compared with several voluntary frameworks that stop at supplier questionnaires.

Expect covered customers - and their outside auditors - to ask SaaS vendors for more than a marketing Trust badge:

Fresh SOC 2 Type II (and ISO where you have it), with CCPA-relevant carve-outs explained in plain language rather than buried in exceptions. Recent penetration-test executive summaries and vulnerability remediation status for the product surfaces that touch California PI. PI-flow maps showing where California consumer data sits in your product, subprocessors, support tooling, analytics, and AI features. Evidence that MFA, logging, incident response, and retention controls actually cover the environments touching their tenants. Contract language: timely evidence packs, cooperation with customer audits, subprocessor flow-downs, and incident collaboration consistent with the customer's CalPrivacy clock.

If your MSA still treats "reasonable assistance with customer audits" as a one-line courtesy, counsel should reopen it before Group 1 customers enter their 2027 audit windows. Put the same artifacts on a diligence-ready Trust page so Sales is not inventing a new ZIP file per RFP. Security questionnaire portals will keep asking overlapping questions; answer them from one bank instead of three conflicting emails.

This is also where sibling regimes diverge operationally. NY financial buyers harden Part 500.11 TPSP clauses around MFA, encryption, and event notice. Public-company customers flow down SEC cyber disclosure incident clocks into notification SLAs. CalPrivacy's angle is general-applicability privacy-law cybersecurity audits plus service-provider reach - different buyer statute, overlapping evidence pack. Multi-state privacy programs still sit in the US state privacy laws post; do not collapse those jobs into this one.

A practical readiness sequence for SaaS teams

1. Threshold memo. Document whether you meet significant-risk thresholds yourself using the Forvis Mazars / Troutman framing above. Keep counsel's analysis with the same discipline you use for CCPA "business" status.

2. California PI map. Categories, systems, vendors, support paths, and cross-border flows. Identify potentially exempt federally regulated data sets with legal - then document what remains in scope.

3. Eighteen-component gap pass. Score each component against your SOC 2 / ISO evidence. Flag PI inventory, VDP, and MFA scope first, then vendor oversight and incident-notification samples.

4. Vendor and contract pass. Identify customers likely in Group 1. Update audit-cooperation and evidence-SLA language. Refresh subprocessors and make sure flow-downs are real, not aspirational.

5. Evidence engineering. Tickets, configs, training records, pen-test archives, and breach-notification samples organized so an annual cycle is boring and repeatable.

6. Questionnaire answer bank. One consistent story for "Do you support CCPA cybersecurity audits?" covering cooperation clauses, turnaround times, and which artifacts you share under NDA.

Litigation and discoverability themes around audit reports are real and contested. Troutman discusses California's private right of action and the possibility that audit documentation becomes discoverable in breach litigation. Treat privileged gap assessments and careful documentation as risk management with counsel. This post is not legal advice. It does not invent fine tallies, settlement forecasts, or claims that "X% of SaaS is already audited."

Soft next step

If you need help turning CalPrivacy's clock into an operable privacy and security program - PI inventories, vendor oversight, and diligence packaging customers can actually use - talk to Workstreet about privacy. When the bottleneck is answering the same audit-cooperation and control questions across portals rather than building the controls themselves, layer security questionnaire automation on top. Keep the US patchwork, NYDFS, and SEC posts open for their own jobs; this one stays on California's cybersecurity audit mandate and the SaaS vendor evidence trail it creates.

Turn compliance into a growth engine: Workstreet delivers full-stack solutions that transform security and compliance into growth accelerators. Talk to an expert →
Build trust, accelerate growth.
Workstreet offers Al-first security solutions that help high growth technology companies get compliant, scale securely, and close bigger deals.
Get started
Ready to Transform Security into a Growth Advantage
Schedule a consultation with our trust solutions experts to see how we can accelerate your security program and compliance journey.
Talk to an engineer
Travis Good

Architect of security and privacy programs for 1,000+ hypergrowth companies. Author of "Complete Cloud Compliance," HITRUST 3rd Party Council member, and recognized speaker on startup security.