How To Prepare for a CCPA Cybersecurity Audit
-
July 20, 2026
-
Cybersecurity audits under the California Consumer Privacy Act (“CCPA”) regulations have emerged as a priority for organizations across all industries.1 Although the April 2028 submission deadline may appear distant, meaningful preparation must begin well in advance to ensure a successful outcome. Regardless of an organization’s prior audit experience, there are substantive steps to prepare that must be taken now. This article discusses key planning considerations for the near term and what to expect moving forward.
Quick Refresher: What Is the CCPA Cybersecurity Audit Requirement?
Under regulations enacted by the California Privacy Protection Agency (“CPPA”), organizations operating in California that process consumers’ personal information and meet certain revenue and/or processing thresholds are now required to complete annual cybersecurity audits. The audits must be conducted by an independent and qualified auditor and must cover up to 18 specific components of a cybersecurity program.
A certification of compliance is required to be filed with the CPPA beginning on April 1, 2028 (deadlines for submission are staggered based on annual revenue).2
2026 Is the Year To Prepare
The most successful organizations will not spend 2026 building entirely new security programs – instead, they'll focus on identifying existing program documentation and leveraging other existing compliance activities.
These four key activities should be at the top of every organization's preparation checklist for 2026:
- Conduct a gap assessment relative to the requirements of a CCPA cybersecurity audit
- Perform a mock CCPA cybersecurity audit
- Identify existing audits, assessments, or reviews that can be leveraged
- Identify the independent auditor
Conduct a Gap Assessment
Before investing resources to build new processes or controls, organizations should first understand how their existing security program aligns with CCPA cybersecurity requirements.
A gap assessment should answer four important questions:
- Have in-scope systems been identified?
Organizations should first confirm that all in-scope systems have been properly identified. Accurate scoping is critical for audit readiness and for audit efficiency – in some cases, a well-defined scope can even limit the overall volume of systems subject to review. This process should encompass systems that store, process, or transmit California residents' personal information, as well as supporting infrastructure and critical security platforms. A comprehensive system inventory both defines the scope of the audit and helps reduce the likelihood of future disagreements between management and the auditor regarding what is considered in scope. - Are all required security domains covered?
The CCPA cybersecurity audit regulations require assessing a broad cybersecurity program—not simply reviewing a handful of technical safeguards. The 18 specific domains that organizations are required to be evaluated against are:
A gap assessment can determine which of the 18 domains are applicable to a given organization and measure how the current program aligns to each applicable domain. Even organizations with mature security programs should expect to find that certain domains have not been formally documented or are not built in a way that will successfully demonstrate compliance during an audit. - Are existing controls auditable?
Perhaps the most overlooked question is not whether controls exist, but whether their existence and operation can be proven. Auditors do not just review policies or responses to a questionnaire. They seek evidence that controls are functioning as intended, including through direct testing. Accordingly, organizations should be prepared to produce operational evidence, in addition to any governing policies and procedures, such as:- Vulnerability scan reports
- Patch management records
- Security monitoring alerts
- User access reviews
- Multi-factor authentication reports
- Security awareness training completion records
- Backup testing results
- Penetration testing reports
- Incident investigations
- Have relevant subject matter experts and stakeholders been identified?
Organizations should identify responsible control owners and individuals across key functional areas, such as:- Information security
- Information technology operations
- Application development
- Cloud infrastructure
- Vulnerability management
- Procurement/third-party risk management
- Business continuity and disaster recovery
What Good Audit Evidence Looks Like
A helpful way to think about audit readiness is as a three-legged stool.
Perform a Mock Cybersecurity Audit
Organizations should consider conducting a mock audit that simulates activities an independent auditor is likely to perform and helps answer questions, including:
- Are control owners prepared for interviews?
- Are policies aligned with actual practices?
- Is documentation complete and current?
- Can requested evidence be produced in a timely fashion?
- Would an independent reviewer reach the same conclusions as management?
- What remediation steps do we need to take before the audit?
Uncovering these issues in 2026 will help position organizations for an efficient and successful audit in 2027.
Leverage Existing Audits and Assessments
A common misconception about the CCPA cybersecurity audit requirement is that it demands an entirely separate compliance effort from the efforts organizations are currently undertaking. In reality, most organizations already have at least some of the required documentation or evidence they need from prior audits, assessments, or reviews. Relevant existing activities may include:
- SOC 2 examinations
- ISO 27001 certifications
- Internal audits
- NIST Cybersecurity Framework assessments
Many of these activities generate documentation and evidence that can be used to directly support a CCPA cybersecurity audit. Organizations should identify the timing of existing efforts and develop a unified evidence collection process to avoid duplication. This can significantly reduce cost and audit fatigue.
Selecting the Independent Auditor
Organizations should enter 2027 with a clear plan for completing the independent audit, and one of the most vital decisions in that process is the selection of the auditor. Some organizations may have an internal audit function, while others will engage an external firm. Regardless of who performs the audit, independence will be a critical area of scrutiny under the CCPA. The auditor must be able to demonstrate the ability to provide an objective assessment free from conflicts of interest.
Beyond independence, the selected auditor should have demonstrable subject matter expertise in evaluating enterprise cybersecurity programs, including with respect to governance, technical controls, and operational security practices. A qualified auditor should also understand California's evolving regulatory landscape and the intersection of privacy obligations with cybersecurity expectations.
Start Preparing Now
Organizations that wait until 2027 to start preparing will likely find themselves at a disadvantage – scrambling to collect documentation, identify evidence, and remediate gaps while an audit is already underway. The time to assess readiness is now. Early planning can reduce costs, minimize business disruption, and position an organization for a more efficient audit when the time comes. Identifying existing resources today creates a strong foundation for responding to auditor questions and producing a compliance report capable of withstanding regulatory scrutiny.
How FTI Consulting Can Help
FTI Consulting is actively supporting organizations as they prepare for the CPPA’s new regulatory requirements, including Article 10 Cybersecurity Audits, Article 11 Risk Assessments, and Article 12 Automated Decision-Making Technology compliance obligations. To learn more about how these requirements may affect your organization and how FTI Consulting can assist with readiness, assessment, and implementation efforts, please reach out.
Related Insights
Published
July 20, 2026