Operational Evidence is Key: Preparing for the New CCPA Cybersecurity Audits
-
August 28, 2026
-
The regulations enacted by the California Privacy Protection Agency to implement the California Consumer Privacy Act (“CCPA”) include new cybersecurity audit regulations that represent a meaningful shift in how regulators approach privacy-related oversight. Where prior compliance frameworks have typically focused on written policies, disclosures, and procedural documentation, the CCPA cybersecurity audit framework evaluates programs on a comprehensive basis to determine whether an organization’s cybersecurity program is actually working.1 Organizations that approach a cybersecurity audit under the new regulations as a documentation exercise are likely to find themselves underprepared and at risk of failing. In order to successfully prepare for a CCPA cybersecurity audit, an organization must be able to demonstrate that its controls are consistently operating as designed in practice.
Moving Beyond Documentation
While typical compliance audits require documentation review, the CCPA audit seeks to move from reviewing the expectations covered in policies to reviewing evidence that demonstrates execution. CCPA auditors are expected to seek objective evidence that controls have been implemented and are functioning throughout the applicable audit period. Organizations should be prepared for personnel interviews, process walkthroughs, and technical validation, in addition to documentation reviews. The types of evidence likely to be requested span a range of operational activities, including:
- Access reviews
- Security monitoring reports
- Vulnerability scan results
- Incident response records
- Security awareness training completion reports
- Vendor due diligence documentation
- Change management records
- Risk assessments
Together, these artifacts paint a picture of whether a cybersecurity program is functioning as an operational discipline or exists primarily as a set of written commitments.
Assessments vs. Audits
One of the most important conceptual distinctions organizations can internalize before engaging with the CCPA audit process is the difference between an assessment and an audit. While these terms are often used interchangeably, they serve fundamentally different purposes:
- Assessment: Collaborative and advisory in nature, with the goal of identifying gaps, evaluating readiness, and helping an organization improve its security program. The outputs (gap analyses, risk rankings, remediation roadmaps) are oriented toward improvement.
- Audit: Evidence-based, objective, and formal, with the goal of providing an independent evaluation of whether controls are compliant and operating effectively during a defined audit period. The outputs (findings, exceptions, observations, management responses) are oriented toward accountability.
Organizations that have only conducted assessments may believe they are better prepared for a CCPA cybersecurity audit than they are. Having an audit-ready posture means an organization is prepared to be evaluated and provide evidence demonstrating how the program is actually functioning, rather than just being able to identify what needs to be fixed.
Operational Evidence
Collecting evidence is frequently the most time-consuming aspect of an audit. Evidence rarely lives in one place; security, information technology (“IT”), human resources, procurement, privacy, legal, and compliance teams all contribute artifacts that may be relevant to demonstrating control effectiveness. Additionally, auditors are not typically looking for a single snapshot of a control in action, but rather are looking for evidence that spans the audit period to demonstrate that controls operated consistently. The evidence organizations produce should reflect repeatability, management oversight, timely execution, and appropriate exception handling. A one-time access review completed the week before an audit request is a very different artifact than a series of quarterly reviews conducted throughout the year. Controls testing in a cybersecurity audit context may involve:
- Sampling user access reviews to confirm they were completed accurately and on schedule
- Verifying that multi-factor authentication is implemented across relevant systems
- Reviewing vulnerability remediation timelines to assess whether identified risks were addressed promptly
- Examining security event monitoring for evidence of active oversight
- Testing incident response documentation for completeness and timeliness
- Evaluating backup and recovery testing records
- Reviewing vendor risk assessments for depth and recency
Providing a written policy stating a control exists is not the same as demonstrating it operated effectively throughout the audit period. Organizations that conflate the two are likely to encounter findings that could have been avoided with earlier operational investment.
The Independence Requirement
Closely related to the assessment-versus-audit distinction is the CCPA’s requirement that audits be conducted by a qualified, independent auditor. This reflects a deliberate regulatory emphasis on ensuring audit conclusions are objective and free from conflicts of interest, which can arise when organizations evaluate their own controls. The CCPA requires that the auditor must not have a relationship with the organization that could compromise objectivity (e.g., financial ties, prior substantive engagements involving the systems being audited, reporting relationships). The auditor must also exercise professional skepticism, follow evidence where it leads, and report findings accurately regardless of how the organization might prefer it be characterized.2
For many organizations, the independence requirement will necessitate a meaningful shift in how they think about their audit function. Internal audit teams, while valuable for ongoing monitoring and readiness assessments, will not satisfy the CCPA independence standard unless they can demonstrate sufficient separation and lack of bias. Organizations that have historically relied on self-assessments or assessments conducted by existing security vendors should carefully evaluate whether those arrangements will survive regulatory scrutiny.
The independence requirement also impacts how organizations should prepare for audits. Because the audit focuses on reflecting the operational state of controls during the audit period, organizations cannot expect the kind of collaborative back-and-forth that exists in a typical advisory engagement. This dynamic reinforces the importance of entering the audit period with controls operating effectively, rather than relying on the audit process itself to surface and resolve deficiencies in real time. Organizations should also consider the timing and selection of their auditor carefully. Engaging a qualified firm early allows time to align on scope, establish evidence collection procedures, and ensure that both parties understand the regulatory expectations before the audit period begins.
Identifying In-Scope Systems
Scoping is one of the most consequential decisions an organization will make in its audit preparation, with direct implications for the volume of evidence required, the number of controls subject to testing, and the overall complexity of the engagement. The CCPA cybersecurity audit is focused on systems and processes that collect, process, store, or transmit the personal information of California consumers.3 Organizations should begin by mapping their data flows to identify where personal information resides and how it moves through the enterprise. This data inventory becomes the foundation for a defensible scoping determination.
A well-defined scope focuses audit activity on the systems and controls that are most relevant to the regulatory objective of protecting personal consumer information and provides a rational basis for excluding systems that do not touch personal information. Auditors and regulators will scrutinize scope boundaries, and organizations that appear to have drawn them narrowly for convenience rather than based on a principled data-flow analysis risk having their scoping rationale challenged. The goal is to define scope accurately rather than to minimize it at all costs, so that audit resources are directed where they matter most and the resulting audit opinion reflects a credible evaluation of the controls that protect personal information.
Scoping work should involve collaboration across an organization’s security, IT, privacy, and legal teams. The organization’s data inventory and data flow diagrams, system classification framework, and existing records of processing activities should all play a role in informing the scope. Organizations that have not yet developed a mature data inventory will find that addressing this gap is a prerequisite to conducting a credible audit.
Preparation Should Begin Now
Organizations cannot wait until the CCPA cybersecurity audit submission deadline is on the horizon to begin preparations. Many cybersecurity controls require months of operational history before they can generate the kind of evidence an auditor will find credible, and some evidence must demonstrate recurring activities over an extended period. Deficiencies identified after the audit period has begun may not be fully remediable before evidence is evaluated, leaving organizations exposed to findings that earlier preparation could have prevented. Meaningful preparation activities include:
- Conducting readiness assessments to identify control gaps
- Closing gaps and implementing missing governance processes
- Establishing evidence retention procedures to ensure artifacts are captured and preserved systematically
- Performing mock audits to stress-test the organization’s ability to respond to evidence requests
- Training control owners on responsibilities and the types of documentation to maintain
- Organizing documentation repositories so evidence can be located and produced efficiently under audit conditions
The CCPA’s cybersecurity audit regulations move beyond asking whether organizations have cybersecurity policies and toward evaluating if those policies translate into consistently effective controls. The independence requirement ensures a credible evaluation, while thoughtful scoping decisions allow organizations to focus audit resources where they matter most. Organizations that begin preparation early will have the opportunity to remediate deficiencies, build the operational history needed to support controls testing, and enter the audit period with confidence.
Footnotes:
1: Cal. Code Regs. Tit. 11, §§ 7120–7124 (2026)
2: “CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations,” California Privacy Protection Agency (July 24, 2025)
3: ibid;
Related Insights
Related Information
Published
August 28, 2026