CCPA Compliance Consulting Services

The independent read on your CCPA compliance

CCPA compliance is no longer optional in California. Know where your program actually stands.

Does the CCPA audit apply to you?

Meet any one of these and an independent cybersecurity audit is now required:

250,000+ California consumers or households
Sensitive data of 50,000+ consumers
50%+ of revenue from selling or sharing data
Independent IT testing since 1988
Two Ways We Work

Get audit-ready, or bring us in as your independent auditor

TestPros works both sides of CCPA compliance, and most organizations need one or the other. We serve a single role per program, which is exactly what keeps the audit defensible.

Engagement 1

CCPA Readiness & Consulting

Independent CCPA consultants take you from where you stand today to a documented, audit-ready program. A project-based engagement, scoped to your data, thresholds, and timeline.

One-time readiness project For teams preparing to be audited

Engagement 2

Independent CCPA Cybersecurity Audit

When you need the audit itself, we perform the annual independent cybersecurity audit the CCPA regulations require. Each year you meet the thresholds, an independent auditor evaluates your program for the full prior calendar year.

Recurring every calendar year For teams who need the audit

Not sure which fits? Talk to an assessor ›

Consulting Services

What our CCPA compliance consulting covers

We take you from where you stand today to a documented, audit-ready program. You work with independent CCPA consultants who scope every engagement to your data, your thresholds, and your timeline.

  • Data Mapping & Inventory

    We find and document the personal information you collect, sell, and share, and map how it flows.

  • Consumer-Rights Readiness

    We review how access, deletion, correction, and opt-out requests are handled against the law.

  • Gap Assessment

    We measure your program against CCPA and CPRA and surface exactly what is missing.

  • Privacy Risk Assessments

    We document the risk assessments CCPA now requires before new high-risk processing or automated decision-making.

  • Cybersecurity Audit Readiness

    We prepare you for the independent cybersecurity audit, so nothing in the audit period catches you off guard.

  • Remediation Guidance

    We deliver a prioritized roadmap to close gaps, with independent verification along the way.

In Effect Since 2026

What CCPA now requires

California's updated privacy regulations are live. If your business meets the thresholds, two obligations now apply, and the cybersecurity audit can only be signed off by a qualified, objective, and independent auditor.

Obligation 1

Independent Cybersecurity Audit

A recurring annual audit of your information security program. Each year you meet the thresholds, findings must rest on evidence the auditor gathers directly, such as documents, sampling, and testing, not on your own assurances.

Audit periods begin 2027 Certifications due 2028 to 2030 by revenue

Obligation 2

Privacy Risk Assessments

Documented risk assessments before new high-risk processing, including selling or sharing personal data, handling sensitive data, profiling, and automated decision-making. Kept current within 45 days of a material change.

Required since January 2026 First submissions due 2028

The part you can't afford to miss

The auditor has to be independent. A firm that built or manages your privacy program cannot audit it.

California Consumer Privacy Act cybersecurity audit regulationsCal. Code Regs. tit. 11, §§ 7120-7124

The Process

How a TestPros CCPA assessment works

A defined path from "where do we stand?" to audit-ready documentation, with an independent assessor at every step.

Step 1 · Scope & Data Map

Define the assessment boundary and inventory the personal information you collect, sell, and share. Map data flows and identify the systems and processing activities in scope.

Output Documented Data Inventory

Step 2 · Assess & Verify

Independently test your program against CCPA and CPRA: consumer-rights handling, notices and disclosures, security controls, and the audit criteria. Every finding is manually verified against evidence.

Output Evidence-Linked Findings

Step 3 · Report & Remediate

Receive a findings report with gap analysis, risk ratings, and a prioritized remediation roadmap. Audit-ready documentation that holds up under regulator scrutiny.

Output Remediation Roadmap
The Deliverable

What you receive

A single, defensible report an auditor, a regulator, or your own board can rely on. Here is what the inside of a CCPA assessment looks like.

Inside the report

A CCPA assessment documents where your privacy program stands against the law, and what to fix first. Six sections, evidence-linked throughout.

  • Executive Summary

    Overall CCPA posture and the priorities that matter most to leadership.

  • Data Inventory & Mapping

    What personal information you collect, sell, and share, and where it flows.

  • Consumer-Rights Findings

    How access, deletion, correction, and opt-out requests are handled against the law.

  • Security & Audit Findings

    Controls tested against the CCPA cybersecurity audit criteria, evidence-linked.

  • Risk Assessment

    High-risk processing evaluated and documented, as the regulations require.

  • Remediation Roadmap

    Prioritized gaps with specific corrective actions and effort estimates.

Who This Is For

Which businesses need CCPA compliance?

If you handle the personal data of California residents at scale, the thresholds likely apply. These are the businesses they most often reach.

  • Retail & E-commerce

    Loyalty programs, online tracking, and large customer bases push most retailers past the consumer threshold.

    250,000+ consumers
  • AdTech & Data Brokers

    Businesses that buy, sell, or share personal data are covered regardless of their size.

    Sells or shares data
  • SaaS & Technology

    Platforms with California users at scale, whether the data they hold is B2B or B2C.

    250,000+ consumers
  • Media, Streaming & Publishing

    Subscriber records and ad-driven tracking that reach California residents at volume.

    250,000+ consumers
  • Consumer Finance & Fintech

    Consumer financial data that falls outside what GLBA already covers.

    Sensitive data
  • Health & Wellness Apps

    Consumer health and wellness data that HIPAA does not reach.

    Sensitive data
FAQ

CCPA questions, answered

The thresholds, the new obligations, and what independence actually means for your audit.

What is CCPA compliance?

CCPA compliance means meeting the requirements of the California Consumer Privacy Act, as amended by the CPRA. It covers how a business collects, uses, sells, and shares the personal information of California residents, the privacy rights it must honor, and, for larger businesses, an annual independent cybersecurity audit and documented risk assessments.

Who has to comply with the CCPA?

The CCPA applies to for-profit businesses doing business in California that handle residents' personal information and meet at least one threshold: more than $26.6 million in annual gross revenue (adjusted for inflation), handling the personal information of 100,000 or more consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.

What is the CCPA cybersecurity audit requirement?

Under regulations effective January 2026, a subset of covered businesses must complete an annual cybersecurity audit. It applies if you derive more than half your revenue from selling or sharing personal information, or you meet the CCPA revenue threshold and process the personal information of 250,000 or more consumers or the sensitive personal information of 50,000 or more. First certifications phase in from 2028 to 2030 by revenue, but audit periods begin in 2027.

Can our current privacy vendor perform the CCPA audit?

Often no. The audit must be performed by a qualified, objective, and independent auditor, and the regulations bar anyone who developed or maintains the program being audited. A firm that built, implemented, or manages your privacy or security program cannot also audit it. That structural independence is exactly what TestPros is built to provide.

Can TestPros perform our CCPA cybersecurity audit?

Yes. TestPros performs the annual independent cybersecurity audit the CCPA regulations require, as an evidence-based engagement resting on documents, sampling, and testing. Because the regulations require the auditor to be independent of the team that built or runs the program, we serve a single role for any one organization: we either help you get audit-ready, or we act as your independent auditor, not both on the same program.

Can we do the CCPA cybersecurity audit ourselves, internally?

Yes, in principle. The regulations permit an internal auditor, so you are not required to hire an outside firm. But the independence bar is high: the auditor cannot have designed or operated the controls being reviewed, and the most senior auditor must report to an executive who is not responsible for the security program. In a small or mid-sized organization that separation is hard to create cleanly, so many businesses bring in an outside firm. TestPros can support your internal team's readiness work, or serve as your independent external auditor.

What are the penalties for CCPA non-compliance?

The CCPA provides for civil penalties of up to $2,500 per violation, and up to $7,500 for each intentional violation or one involving the personal information of a consumer under 16. Enforcement is active, with recent settlements reaching into the millions, so the exposure is real and current.

What is the difference between the CCPA and the CPRA?

They are the same law. The CCPA is the original 2018 statute. The CPRA, passed in 2020, amended and expanded it, adding new consumer rights, the category of sensitive personal information, and the regulations now taking effect. In common use, "CCPA" refers to the combined law.

How is CCPA compliance different from GDPR?

Both govern personal data, but they differ in scope and approach. GDPR applies to the data of people in the EU and EEA; the CCPA applies to California residents. Many businesses fall under both, along with laws like HIPAA. TestPros assesses against each and maps the overlap, so you are not running separate engagements for separate laws.

The Requirement Is Already In Effect

Get an independent read on your CCPA compliance.

Tell us where you stand, your thresholds, or your audit timeline.

Talk to an Independent Assessor
  • No software, no conflicts
  • ISO 27001 + CMMI ML3
  • Independent IT testing since 1988