United States of America: Office of Administrative Law adopted regulations under California Consumer Privacy Act on cybersecurity audits

Description

Office of Administrative Law adopted regulations under California Consumer Privacy Act on cybersecurity audits

On 23 September 2025, the California Office of Administrative Law adopted the regulations under the California Consumer Privacy Act (CCPA) on cybersecurity audits, with phased compliance deadlines linked to annual gross revenue. Beginning on 1 January 2026, the regulations will enter into force, and businesses subject to audit obligations must prepare to submit certifications to the CPPA within specified timeframes. The cybersecurity audit requirements are designed as part of the wider regulatory framework alongside risk assessments and automated decision-making technology obligations, providing the CPPA with formal supervisory mechanisms to monitor compliance. The phased deadlines establish a structured sequence for businesses of varying sizes to certify completion of required cybersecurity audits and formally report compliance to the CPPA.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2023-08-28
under deliberation

On 28 August 2023, the California Privacy Protection Agency (CPPA) released materials ahead of its …

2024-11-22
in consultation

On 22 November 2024, the California Privacy Protection Agency (CPPA) opened the public consultation…

2025-01-14
processing consultation

On 14 January 2025, the California Privacy Protection Agency (CPPA) closes the public consultation …

2025-03-28
under deliberation

On 28 March 2025, the California Privacy Protection Agency (CPPA) published its revised draft regul…

2025-09-23
adopted

On 23 September 2025, the California Office of Administrative Law adopted the regulations under the…

2026-01-01
in grace period

On 1 January 2026, the regulations adopted under the California Consumer Privacy Act (CCPA) enter i…