CCPA Final Regulations: What We've Learned and What Comes Next
-
September 17, 2026
-
The California Consumer Privacy Act (“CCPA”) final regulations, which became effective on January 1, 2026, introduced three relatively new compliance obligations for in-scope organizations: mandatory annual cybersecurity audits under Article 9, formal risk assessments under Article 10 and governance requirements for automated decision-making technology (“ADMT”) under Article 11.1 As FTI Consulting works with clients across industries on CCPA compliance preparation, several practical realities have emerged that go beyond what the regulations themselves make explicit.
Article 9 Leaves Important Questions Unanswered
While Article 9 establishes the cybersecurity audit obligation and identifies 18 control domains,2 it leaves meaningful ambiguity around scoping and testing rigor. Organizations should begin aligning on these expectations now with a scoping exercise that identifies all of the systems storing, processing, transmitting or containing personal information related to California residents, and then determine the applicability of relevant cybersecurity domains to each system. For smaller or more modern environments, this typically yields a more targeted assessment footprint. For larger or complex legacy environments, the scope may be broader and require an enterprise-level approach.
Companies should work with external experts and outside counsel throughout the scoping process to ensure decisions are defensible and well-documented. Once scope is established, companies should use a risk-based approach to devise their testing strategy, considering domain applicability and the risk profile of each system or application.
The Qualified Auditor Shortage Is a Real Risk
One of the most underappreciated risks in the current compliance landscape is the availability of qualified auditors. The CCPA cybersecurity audit requirement is unprecedented in scope among U.S. state privacy laws, with a substantial number of organizations that will need to complete audits before the 2028 deadline.
Our expectation is that most qualified auditors will be fully committed by the summer of 2027. Organizations that have not secured an auditor by that point may find themselves unable to complete the audit on time, regardless of how well-prepared their internal programs are.
Start the Real Audit Planning Stage Now
Initially, FTI Consulting encouraged clients to conduct a full pre-audit in advance of the formal CCPA audit. That remains the right approach for many organizations, but at a minimum, every in-scope organization should complete the planning stage of the real audit this year, including:
- Scoping: Determine what systems and components are in scope and whether any can be defensibly carved out.
- Leveraging Prior Audit Findings: Assess whether existing SOC 2 examinations, ISO 27001 certifications or other prior audit work can satisfy portions of the Article 9 requirement.
- Aligning on Sample-Based Testing Approach: Reach agreement with the auditor on the level of scrutiny that will be applied during testing.
- Securing Auditor: Secure a formal engagement with a qualified auditor before the market becomes constrained.
- Securing Budget: Complete a planning project now to incorporate the full audit cost into next year’s budget as a planned expenditure rather than an emergency response.
The Benefit of Conducting a Mock Audit
In many cases, we recommend that organizations conduct a mock audit or a gap assessment against the Article 9 requirements in 2026, before the audit period begins in 2027. Most companies will uncover some gaps and weaknesses that should ideally be addressed before January 1, 2027. The full process of conducting a mock audit and remediating any identified gaps typically takes a minimum of 10-12 weeks.
If your organization conducts a mock audit and identifies gaps that cannot be remediated before January 1, 2027, be prepared to provide documentation for the remediation plan and/or highlight compensating and mitigation controls for that finding. Having these plans in place will reduce the potential for a significant finding during the official audit period.
Attestation Risk and the Role of Third Parties
Chief privacy officers and their peers have increasingly questioned whether engaging third parties to perform the work underlying the Article 9 audit might reduce the personal liability exposure of the executive who must sign the attestation under penalty of perjury. The reasoning is that if a qualified, independent third party has conducted the audit and produced the findings, then logically, the certifying executive is attesting to a process and outcome that was externally validated, rather than one that rests entirely on internal representations.
However, from a practical standpoint, the attestation requirement under Article 9 places personal liability on a named executive.3 The regulation does not eliminate that liability simply because a third party performed the audit work. The certifying executive is still attesting that the audit was completed in compliance with Article 9 and that the findings are accurate. What third-party involvement does provide is a stronger evidentiary foundation for the attestation that the executive can point to as the basis for their certification.
Whether that meaningfully reduces personal liability in an enforcement context is ultimately a legal question, and organizations should seek counsel on that point. Either way, a well-documented, independently conducted audit provides a stronger basis for an attestation than an internally managed process, and the quality of this underlying work may matter significantly if the California Privacy Protection Agency or the California Attorney General ever requests the full audit report.
Navigating the Independence Constraint
The independence requirements under Article 9 state that an external firm can perform an organization’s pre-audit and remediation work, or it can perform the pre-audit and the formal audit, but the same firm cannot perform both remediation and the formal audit.4 For most organizations, this means that two providers will be involved during the compliance lifecycle.
Organizations that understand this dynamic early can structure their engagements accordingly, retaining one firm for pre-audit and remediation work and a separate firm for the formal audit, or retaining one firm for pre-audit and formal audit work and a separate firm for remediation. Tri-party engagement structures in which outside counsel, the auditor and the client are all involved can provide additional clarity on roles, responsibilities and privilege considerations.
Don’t Forget Risk Assessments and ADMT
While much of the near-term urgency centers on Article 9, organizations should not lose sight of the parallel obligations under Articles 10 and 11. Risk assessments under Article 10 are already required for any new processing activities initiated after January 1, 2026, with the first certified report covering assessments conducted in 2026 and 2027 due April 1, 2028.5 The combination of a 45-day material change trigger, a three-year baseline refresh and annual certification requirements makes this a continuous program, not a one-time project. Organizations that treat 2026 and 2027 as a build-out window will reach the April 2028 deadline in a position of confidence.
ADMT compliance under Article 11 takes effect January 1, 2027.6 Organizations using machine learning, statistical analysis, artificial intelligence or other automated systems to make significant decisions about consumers in the areas of employment, financial services, housing, education or healthcare must have pre-use notices, opt-out mechanisms, explainability processes and human review options in place by that date.
The Key Theme: Urgency
The CCPA final regulations represent the most significant expansion of California’s privacy framework since the CCPA’s original enactment. While penalties for non-compliance are substantial, the most concerning risk organizations face today is waiting too long to prepare. The organizations that will navigate CCPA compliance successfully are the ones planning ahead by scoping their environments, assessing their programs, securing their auditors and building governance structures that will sustain compliance over time.
Footnotes:
1: “CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations,” California Privacy Protection Agency (July 24, 2025).
2: Cal. Code Regs. tit. 11, §§ 7120–7124 (2026).
3: Cal. Code Regs. tit. 11, § 7124 (2026).
4: Cal. Code Regs. tit. 11, § 7122 (2026).
5: Cal. Code Regs. tit. 11, §§ 7155–7157 (2026).
6: Cal. Code Regs. tit. 11, § 7200 (2026).
Related Insights
Related Information
Published
September 17, 2026
Key Contacts
Senior Managing Director
Senior Managing Director
Senior Managing Director
Managing Director