Engagement 1
CCPA Readiness & Consulting
Independent CCPA consultants take you from where you stand today to a documented, audit-ready program. A project-based engagement, scoped to your data, thresholds, and timeline.
Tell us where your CCPA program stands, the thresholds that apply, and your timeline. A TestPros assessor will respond within one business day.
CCPA compliance is no longer optional in California. Know where your program actually stands.
Meet any one of these and an independent cybersecurity audit is now required:
TestPros works both sides of CCPA compliance, and most organizations need one or the other. We serve a single role per program, which is exactly what keeps the audit defensible.
Engagement 1
Independent CCPA consultants take you from where you stand today to a documented, audit-ready program. A project-based engagement, scoped to your data, thresholds, and timeline.
Engagement 2
When you need the audit itself, we perform the annual independent cybersecurity audit the CCPA regulations require. Each year you meet the thresholds, an independent auditor evaluates your program for the full prior calendar year.
We take you from where you stand today to a documented, audit-ready program. You work with independent CCPA consultants who scope every engagement to your data, your thresholds, and your timeline.
We find and document the personal information you collect, sell, and share, and map how it flows.
We review how access, deletion, correction, and opt-out requests are handled against the law.
We measure your program against CCPA and CPRA and surface exactly what is missing.
We document the risk assessments CCPA now requires before new high-risk processing or automated decision-making.
We prepare you for the independent cybersecurity audit, so nothing in the audit period catches you off guard.
We deliver a prioritized roadmap to close gaps, with independent verification along the way.
California's updated privacy regulations are live. If your business meets the thresholds, two obligations now apply, and the cybersecurity audit can only be signed off by a qualified, objective, and independent auditor.
Obligation 1
A recurring annual audit of your information security program. Each year you meet the thresholds, findings must rest on evidence the auditor gathers directly, such as documents, sampling, and testing, not on your own assurances.
Obligation 2
Documented risk assessments before new high-risk processing, including selling or sharing personal data, handling sensitive data, profiling, and automated decision-making. Kept current within 45 days of a material change.
The part you can't afford to miss
The auditor has to be independent. A firm that built or manages your privacy program cannot audit it.
California Consumer Privacy Act cybersecurity audit regulationsCal. Code Regs. tit. 11, §§ 7120-7124
A defined path from "where do we stand?" to audit-ready documentation, with an independent assessor at every step.
Define the assessment boundary and inventory the personal information you collect, sell, and share. Map data flows and identify the systems and processing activities in scope.
Independently test your program against CCPA and CPRA: consumer-rights handling, notices and disclosures, security controls, and the audit criteria. Every finding is manually verified against evidence.
Receive a findings report with gap analysis, risk ratings, and a prioritized remediation roadmap. Audit-ready documentation that holds up under regulator scrutiny.
A single, defensible report an auditor, a regulator, or your own board can rely on. Here is what the inside of a CCPA assessment looks like.
Findings Summary
Findings
| Finding | Requirement | Severity |
|---|---|---|
| "Do Not Sell or Share" link missing from homepageConsumer Rights | Consumer Rights | High |
| Data inventory does not cover third-party sharingData Mapping | Data Mapping | High |
| Opt-out requests not honored within 15 business daysConsumer Rights | Consumer Rights | High |
| Service provider contracts missing required CCPA termsContracts | Contracts | Medium |
| Risk assessment not documented for sensitive dataRisk Assessment | Risk Assessment | Medium |
| Privacy policy not updated in the last 12 monthsNotice | Notice | Low |
A CCPA assessment documents where your privacy program stands against the law, and what to fix first. Six sections, evidence-linked throughout.
Overall CCPA posture and the priorities that matter most to leadership.
What personal information you collect, sell, and share, and where it flows.
How access, deletion, correction, and opt-out requests are handled against the law.
Controls tested against the CCPA cybersecurity audit criteria, evidence-linked.
High-risk processing evaluated and documented, as the regulations require.
Prioritized gaps with specific corrective actions and effort estimates.
If you handle the personal data of California residents at scale, the thresholds likely apply. These are the businesses they most often reach.
Loyalty programs, online tracking, and large customer bases push most retailers past the consumer threshold.
250,000+ consumersBusinesses that buy, sell, or share personal data are covered regardless of their size.
Sells or shares dataPlatforms with California users at scale, whether the data they hold is B2B or B2C.
250,000+ consumersSubscriber records and ad-driven tracking that reach California residents at volume.
250,000+ consumersConsumer financial data that falls outside what GLBA already covers.
Sensitive dataConsumer health and wellness data that HIPAA does not reach.
Sensitive dataThe thresholds, the new obligations, and what independence actually means for your audit.
CCPA compliance means meeting the requirements of the California Consumer Privacy Act, as amended by the CPRA. It covers how a business collects, uses, sells, and shares the personal information of California residents, the privacy rights it must honor, and, for larger businesses, an annual independent cybersecurity audit and documented risk assessments.
The CCPA applies to for-profit businesses doing business in California that handle residents' personal information and meet at least one threshold: more than $26.6 million in annual gross revenue (adjusted for inflation), handling the personal information of 100,000 or more consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
Under regulations effective January 2026, a subset of covered businesses must complete an annual cybersecurity audit. It applies if you derive more than half your revenue from selling or sharing personal information, or you meet the CCPA revenue threshold and process the personal information of 250,000 or more consumers or the sensitive personal information of 50,000 or more. First certifications phase in from 2028 to 2030 by revenue, but audit periods begin in 2027.
Often no. The audit must be performed by a qualified, objective, and independent auditor, and the regulations bar anyone who developed or maintains the program being audited. A firm that built, implemented, or manages your privacy or security program cannot also audit it. That structural independence is exactly what TestPros is built to provide.
Yes. TestPros performs the annual independent cybersecurity audit the CCPA regulations require, as an evidence-based engagement resting on documents, sampling, and testing. Because the regulations require the auditor to be independent of the team that built or runs the program, we serve a single role for any one organization: we either help you get audit-ready, or we act as your independent auditor, not both on the same program.
Yes, in principle. The regulations permit an internal auditor, so you are not required to hire an outside firm. But the independence bar is high: the auditor cannot have designed or operated the controls being reviewed, and the most senior auditor must report to an executive who is not responsible for the security program. In a small or mid-sized organization that separation is hard to create cleanly, so many businesses bring in an outside firm. TestPros can support your internal team's readiness work, or serve as your independent external auditor.
The CCPA provides for civil penalties of up to $2,500 per violation, and up to $7,500 for each intentional violation or one involving the personal information of a consumer under 16. Enforcement is active, with recent settlements reaching into the millions, so the exposure is real and current.
They are the same law. The CCPA is the original 2018 statute. The CPRA, passed in 2020, amended and expanded it, adding new consumer rights, the category of sensitive personal information, and the regulations now taking effect. In common use, "CCPA" refers to the combined law.
Both govern personal data, but they differ in scope and approach. GDPR applies to the data of people in the EU and EEA; the CCPA applies to California residents. Many businesses fall under both, along with laws like HIPAA. TestPros assesses against each and maps the overlap, so you are not running separate engagements for separate laws.
Tell us where you stand, your thresholds, or your audit timeline.
Talk to an Independent Assessor