The Next Move

Privacy becomes a cybersecurity imperative under California’s audit rule

  • July 2026

Mark Cornish

Assurance Partner, PwC US

Chris Santucci

Partner, Data Risk & Privacy, PwC US

Melissa Salzillo

Assurance Partner, PwC US

Adrian Christie

Principal, Cyber Strategy & Transformation, PwC US

The issue

A recently implemented cyber audit rule makes safeguarding consumer personal information a cybersecurity program imperative for many companies.

Article 9 of the California Privacy Protection Agency’s (CalPrivacy) regulations requires annual cybersecurity audits for businesses whose processing of personal information presents a “significant risk to consumers’ security.” The rule links cybersecurity rigor and control effectiveness directly to the protection of California consumers’ personal information. It also imposes specific requirements for audit scope, evidence, auditor independence, and executive certification.

Organizations subject to the earliest compliance deadline won’t submit their first certifications until April 1, 2028, but their audit period begins on January 1, 2027. That leaves little time to prepare cybersecurity programs before the audit period starts.

For covered businesses, this isn’t simply another cyber risk assessment or control-maturity exercise. The audit must evaluate whether the organization’s cybersecurity program is designed and operating effectively to safeguard personal information from “unauthorized access, destruction, use, modification, or disclosure.” Findings must be supported primarily by evidence, not management assertions. Executives responsible for the cybersecurity program must certify the audit’s completion.

More fundamentally, Article 9 changes how organizations should think about privacy and cybersecurity governance. Rather than evaluating cybersecurity controls in isolation, the effectiveness of an organization’s cybersecurity program is formally evaluated based on its ability to safeguard personal information. Privacy data inventories, sensitive-data classifications, consumer-processing controls, third-party data-sharing arrangements, governance processes, and cybersecurity controls must increasingly operate as a coordinated capability within an integrated compliance framework.

Affected companies can’t afford to treat privacy and cybersecurity as parallel compliance tracks. To prepare, they’ll need to show that their privacy commitments are supported by a cybersecurity program that’s appropriately scoped, governed effectively, and audit-ready. By doing this, you can better position your company for future, evolving compliance expectations across multiple regulatory regimes.

The regulator’s take

In September 2025, CalPrivacy issued final regulations covering cybersecurity audits, risk assessments, automated decision-making technology (ADMT), and updates to its existing regulations. The regulations implement and clarify requirements under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Article 9 establishes a cybersecurity audit requirement designed to confirm that organizations processing significant amounts of personal information maintain cybersecurity programs capable of safeguarding that information from security threats. This focus on personal information means an organization’s controls need to address this broader scope, a significant effort for companies that previously took a narrow approach to control compliance (e.g., payment card security compliance).

Who’s affected? The rule casts a wide net, applying to businesses whose data-processing activities pose a “significant risk to consumers’ security.” This includes businesses that, during the preceding calendar year:

  • Derived at least 50% of their revenue from selling or sharing consumers’ personal information, or
  • Generated over $26.625 million in revenue (as of 2025; to be adjusted every odd-numbered year based on CPI) and processed: (a) the personal information of at least 250,000 California consumers or households or (b) the sensitive personal information of at least 50,000 California consumers or households.

When is the audit report deadline? Implementation will happen in phases, with the largest organizations going first. Covered entities must complete their first audit report by:

  • April 1, 2028 (covering the 2027 calendar year), for companies with annual gross revenue exceeding $100 million as of January 1, 2027
  • April 1, 2029 (covering the 2028 calendar year), for companies with annual gross revenue between $50 million and $100 million as of January 1, 2028
  • April 1, 2030 (covering the 2029 calendar year), for companies with annual gross revenue under $50 million as of January 1, 2029

Key requirements at a glance

Article 9 section Topic Key requirements Impact on companies
§7120 Applicability Defines which businesses must conduct a cybersecurity audit Organizations must determine whether they meet applicable revenue and data processing thresholds and establish a process for monitoring applicability annually
§7121 Audit timing and deadlines Establishes phased implementation deadlines and annual audit reporting requirements Compliance becomes an ongoing operational disclosure obligation rather than a one-time event
§7122 Auditor independence Requires that audits be performed by qualified, objective, independent professionals using accepted audit standards and procedures Companies may need to reassess auditor roles, capacity, and skillsets; external assurance providers; and independence safeguards
§7123 Audit scope and content Specifies the cybersecurity program areas that must be evaluated and documented Existing cyber assessments may help, but organizations must demonstrate coverage of Article 9 requirements and alignment with required audit periods
§7124 Executive certification Requires annual certification of the audit’s completion by a member of the executive management team responsible for cybersecurity-audit compliance Executive accountability and governance expectations increase significantly

Auditor qualifications and independence. Audits must be completed “using a qualified, objective, independent professional” who may be internal or external to the company. The auditor must “exercise objective and impartial judgment on all issues” without influence by the business and without participating in activities that may compromise or appear to compromise the auditor’s independence. The auditor can’t, for example, participate in business activities that may be assessed in the current or future cyber audits, including developing procedures, preparing business documents, making recommendations regarding the cybersecurity program, or implementing or maintaining the program.

If a company uses an internal auditor, the highest-ranking auditor must report directly to an executive management leader who doesn’t have direct responsibility for the cybersecurity program.

The audit findings can’t rely primarily on management’s assertions or attestations. Instead, findings must rely primarily on specific evidence (including documents reviewed, sampling and testing performed, and interviews conducted) that the auditor deems appropriate.

Audit scope and contents. The audit must assess how the cyber program safeguards personal information from unauthorized access, destruction, use, modification, or disclosure, as well as unauthorized activity resulting in the loss of availability of personal information. It must also assess how the company established, implemented, and maintains its program (including the written policies and procedures), and how the company enforces compliance.

The rule includes a long list of program components subject to the audit. Examples include:

  • Multifactor authentication
  • Encryption of personal information, at rest and in transit
  • Account management and access controls
  • Inventory and management of personal information and the company’s information system
  • Vulnerability scans, penetration testing, and vulnerability disclosure and reporting
  • Audit-log management
  • Segmentation of an information system
  • Cybersecurity awareness, education and training
  • Oversight of service providers, contractors, and third parties
  • Retention schedules and proper disposal of personal information no longer required to be retained
  • Incident response management
  • Business continuity and disaster recovery plans, including data recovery capabilities and backups

For each component, the audit must describe its effectiveness in safeguarding personal information, describe any gaps or weaknesses, and document the company’s plan to address those gaps or weaknesses.

Reusing existing assessments. A business may leverage a cybersecurity audit or assessment prepared for another purpose if it meets all the Article 9 requirements, either on its own or through supplementation. This suggests that SOC 2, ISO 27001, NIST CSF, internal audit, PCI, or cyber maturity assessments may be useful inputs so long as their scope aligns with the CCPA cybersecurity audit scope. Companies shouldn’t assume existing assessments satisfy Article 9. They should map existing efforts to the CCPA cybersecurity audit scope and evidence requirements to help identify efficiencies or areas requiring more work.

Third-party input and compliance. Article 9 requires organizations to evaluate how effectively they govern service providers and contractors that process or have access to consumer personal information. The regulations also contemplate these entities assisting the company in completing its cybersecurity audit (see §7051(a)(5)). Vendor contracts may require this help and may obligate service providers to implement their own reasonable security procedures and practices “appropriate to the nature of the personal information” they have access to.

Executive certification. Covered businesses must submit a written certification―not the audit report―to CalPrivacy via its website by the report’s deadline. The statement must come from an executive leader directly responsible for the cybersecurity program. It must certify under penalty of perjury that the company completed the audit as required by Article 9 and hasn’t tried to influence the auditor’s decisions or assessments.

Your next move

First determine whether the cyber audit rule applies to your organization and, if so, begin preparing now. That means assessing audit readiness, remediating gaps, and establishing a repeatable process for annual audits and executive certification. Consider these priority actions.

  1. Determine applicability now. Assess whether your organization meets the relevant Article 9 thresholds, including revenue levels, dependence on selling or sharing personal information, total consumers or households processed, and volumes of sensitive personal information processed.
  2. Align key stakeholders. Successful compliance will likely require coordinated ownership across multiple functions, including privacy, information security, legal, procurement, enterprise risk management, internal audit, and business control owners.
  3. Define the audit scope. Identify your systems, applications, business units, third parties, and data flows that process or provide access to California consumers’ personal information.
  4. Assess your readiness. Map current controls to Article 9 requirements and understand current coverage from existing “audits” (e.g., SOC2 reporting). Compare existing cybersecurity frameworks, policies, procedures, and testing activities against the specific requirements of the regulation. Evaluate both whether third-party governance practices are sufficient to satisfy Article 9 and whether your existing vendor agreements provide the support needed to complete the audit. Identify gaps that will require remediation.
  5. Build an evidence strategy. Prepare documentation and operating evidence for key cybersecurity controls, including access management, vulnerability management, incident response, third-party oversight, remediation tracking, and governance activities. Retain this documentation for the full audit period.
  6. Evaluate auditor independence. Determine whether the audit will be performed by internal audit, an external provider, or a hybrid model. Carefully assess independence considerations where individuals have participated in designing, implementing, or operating controls.
  7. Prepare executives for certification. Identify the executive responsible for annual certification, define review expectations, and establish governance processes that support informed attestations.
  8. Remediate before your audit period begins. For organizations subject to the earliest compliance deadlines, the first audit period begins January 1, 2027. That makes the remainder of 2026 a critical window for remediation, evidence design, control stabilization, and operating-model development.

Privacy becomes a cybersecurity imperative under California’s audit rule

Follow us