CCPA Compliance Consulting Services

The independent read on your CCPA compliance

CCPA compliance is no longer optional in California. Know where your program actually stands.

Does the CCPA audit apply to you?

Meet any one of these and an independent cybersecurity audit is now required:

250,000+ California consumers or households
Sensitive data of 50,000+ consumers
50%+ of revenue from selling or sharing data
Independent IT testing since 1988

No software. No conflicts.

We sell no software and don't build what we assess

One assessor, many laws

GDPR · CCPA · HIPAA, and more

Evidence-based findings

Manual verification against real evidence

ISO 27001 + CMMI ML3

Held to the standards we assess

Consulting Services

What our CCPA compliance consulting covers

We take you from where you stand today to a documented, audit-ready program. You work with independent CCPA consultants who scope every engagement to your data, your thresholds, and your timeline.

  • Data Mapping & Inventory

    We find and document the personal information you collect, sell, and share, and map how it flows.

  • Consumer-Rights Readiness

    We review how access, deletion, correction, and opt-out requests are handled against the law.

  • Gap Assessment

    We measure your program against CCPA and CPRA and surface exactly what is missing.

  • Privacy Risk Assessments

    We document high-risk processing activities, as the CCPA regulations now require.

  • Cybersecurity Audit Readiness

    We prepare you for the independent cybersecurity audit, performed by a firm eligible to do it.

  • Remediation Guidance

    We deliver a prioritized roadmap to close gaps, with independent verification along the way.

In Effect Since 2026

What CCPA now requires

California's updated privacy regulations are live. If your business meets the thresholds, two obligations now apply, and the cybersecurity audit can only be signed off by a qualified, objective, and independent auditor.

Obligation 1

Independent Cybersecurity Audit

An annual audit of your information security program. Findings must rest on evidence the auditor gathers directly, such as documents, sampling, and testing, not on your own assurances.

Audit periods begin 2027 Certifications due 2028 to 2030 by revenue

Obligation 2

Privacy Risk Assessments

Documented risk assessments for high-risk processing, including selling or sharing personal data, handling sensitive data, profiling, and automated decision-making.

Required since January 2026 First submissions due 2028

The part most firms won't mention

The auditor has to be independent. A firm that built or manages your privacy program cannot audit it.

The Process

How a TestPros CCPA assessment works

A defined path from "where do we stand?" to audit-ready documentation, with an independent assessor at every step.

Step One

Scope & Data Map

Define the assessment boundary and inventory the personal information you collect, sell, and share. Map data flows and identify the systems and processing activities in scope.

Output Documented Data Inventory
Step Two

Assess & Verify

Independently test your program against CCPA and CPRA: consumer-rights handling, notices and disclosures, security controls, and the audit criteria. Every finding is manually verified against evidence.

Output Evidence-Linked Findings
Step Three

Report & Remediate

Receive a findings report with gap analysis, risk ratings, and a prioritized remediation roadmap. Audit-ready documentation that holds up under regulator scrutiny.

Output Remediation Roadmap
The Deliverable

What you receive

A single, defensible report an auditor, a regulator, or your own board can rely on. Here is what the inside of a CCPA assessment looks like.

Inside the report

A CCPA assessment documents where your privacy program stands against the law, and what to fix first. Six sections, evidence-linked throughout.

  • Executive Summary

    Overall CCPA posture and the priorities that matter most to leadership.

  • Data Inventory & Mapping

    What personal information you collect, sell, and share, and where it flows.

  • Consumer-Rights Findings

    How access, deletion, correction, and opt-out requests are handled against the law.

  • Security & Audit Findings

    Controls tested against the CCPA cybersecurity audit criteria, evidence-linked.

  • Risk Assessment

    High-risk processing evaluated and documented, as the regulations require.

  • Remediation Roadmap

    Prioritized gaps with specific corrective actions and effort estimates.

Who This Is For

Which businesses need CCPA compliance?

If you handle the personal data of California residents at scale, the thresholds likely apply. These are the businesses they most often reach.

  • Retail & E-commerce

    Loyalty programs, online tracking, and large customer bases push most retailers past the consumer threshold.

    250,000+ consumers
  • AdTech & Data Brokers

    Businesses that buy, sell, or share personal data are covered regardless of their size.

    Sells or shares data
  • SaaS & Technology

    Platforms with California users at scale, whether the data they hold is B2B or B2C.

    250,000+ consumers
  • Media, Streaming & Publishing

    Subscriber records and ad-driven tracking that reach California residents at volume.

    250,000+ consumers
  • Consumer Finance & Fintech

    Consumer financial data that falls outside what GLBA already covers.

    Sensitive data
  • Health & Wellness Apps

    Consumer health and wellness data that HIPAA does not reach.

    Sensitive data
The cybersecurity audit must be performed by a qualified, objective, and independent professional auditor.
California Consumer Privacy Act cybersecurity audit regulations Cal. Code Regs. tit. 11, §§ 7120-7124

Independence is written into the audit requirement itself. It is also how TestPros has always worked, with no software to sell and no program of ours to defend.

FAQ

CCPA questions, answered

The thresholds, the new obligations, and what independence actually means for your audit.

What is CCPA compliance?

CCPA compliance means meeting the requirements of the California Consumer Privacy Act, as amended by the CPRA. It covers how a business collects, uses, sells, and shares the personal information of California residents, the privacy rights it must honor, and, for larger businesses, an annual independent cybersecurity audit and documented risk assessments.

Who has to comply with the CCPA?

The CCPA applies to for-profit businesses doing business in California that handle residents' personal information and meet at least one threshold: more than $26.6 million in annual gross revenue (adjusted for inflation), handling the personal information of 100,000 or more consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.

What is the CCPA cybersecurity audit requirement?

Under regulations effective January 2026, a subset of covered businesses must complete an annual cybersecurity audit. It applies if you derive more than half your revenue from selling or sharing personal information, or you meet the CCPA revenue threshold and process the personal information of 250,000 or more consumers or the sensitive personal information of 50,000 or more. First certifications phase in from 2028 to 2030 by revenue, but audit periods begin in 2027.

Can our current privacy vendor perform the CCPA audit?

Often no. The audit must be performed by a qualified, objective, and independent auditor, and the regulations bar anyone who developed or maintains the program being audited. A firm that built, implemented, or manages your privacy or security program cannot also audit it. That structural independence is exactly what TestPros is built to provide.

What are the penalties for CCPA non-compliance?

The CCPA provides for civil penalties of up to $2,500 per violation, and up to $7,500 for each intentional violation or one involving the personal information of a consumer under 16. Enforcement is active, with recent settlements reaching into the millions, so the exposure is real and current.

What is the difference between the CCPA and the CPRA?

They are the same law. The CCPA is the original 2018 statute. The CPRA, passed in 2020, amended and expanded it, adding new consumer rights, the category of sensitive personal information, and the regulations now taking effect. In common use, "CCPA" refers to the combined law.

How is CCPA compliance different from GDPR?

Both govern personal data, but they differ in scope and approach. GDPR applies to the data of people in the EU and EEA; the CCPA applies to California residents. Many businesses fall under both, along with laws like HIPAA. TestPros assesses against each and maps the overlap, so you are not running separate engagements for separate laws.

The Requirement Is Already In Effect

Get an independent read on your CCPA compliance.

Tell us where you stand, your thresholds, or your audit timeline. We respond within one business day with a scoped assessment plan.

Talk to an Independent Assessor
  • No software, no conflicts
  • ISO 27001 + CMMI ML3
  • Independent IT testing since 1988