Obligation 1
Independent Cybersecurity Audit
An annual audit of your information security program. Findings must rest on evidence the auditor gathers directly, such as documents, sampling, and testing, not on your own assurances.
Tell us where your CCPA program stands, the thresholds that apply, and your timeline. A TestPros assessor will respond within one business day.
CCPA compliance is no longer optional in California. Know where your program actually stands.
Meet any one of these and an independent cybersecurity audit is now required:
No software. No conflicts.
We sell no software and don't build what we assess
One assessor, many laws
GDPR · CCPA · HIPAA, and more
Evidence-based findings
Manual verification against real evidence
ISO 27001 + CMMI ML3
Held to the standards we assess
We take you from where you stand today to a documented, audit-ready program. You work with independent CCPA consultants who scope every engagement to your data, your thresholds, and your timeline.
We find and document the personal information you collect, sell, and share, and map how it flows.
We review how access, deletion, correction, and opt-out requests are handled against the law.
We measure your program against CCPA and CPRA and surface exactly what is missing.
We document high-risk processing activities, as the CCPA regulations now require.
We prepare you for the independent cybersecurity audit, performed by a firm eligible to do it.
We deliver a prioritized roadmap to close gaps, with independent verification along the way.
California's updated privacy regulations are live. If your business meets the thresholds, two obligations now apply, and the cybersecurity audit can only be signed off by a qualified, objective, and independent auditor.
Obligation 1
An annual audit of your information security program. Findings must rest on evidence the auditor gathers directly, such as documents, sampling, and testing, not on your own assurances.
Obligation 2
Documented risk assessments for high-risk processing, including selling or sharing personal data, handling sensitive data, profiling, and automated decision-making.
The part most firms won't mention
The auditor has to be independent. A firm that built or manages your privacy program cannot audit it.
A defined path from "where do we stand?" to audit-ready documentation, with an independent assessor at every step.
Define the assessment boundary and inventory the personal information you collect, sell, and share. Map data flows and identify the systems and processing activities in scope.
Independently test your program against CCPA and CPRA: consumer-rights handling, notices and disclosures, security controls, and the audit criteria. Every finding is manually verified against evidence.
Receive a findings report with gap analysis, risk ratings, and a prioritized remediation roadmap. Audit-ready documentation that holds up under regulator scrutiny.
A single, defensible report an auditor, a regulator, or your own board can rely on. Here is what the inside of a CCPA assessment looks like.
Findings Summary
Findings
| Finding | Requirement | Severity |
|---|---|---|
| "Do Not Sell or Share" link missing from homepage | Consumer Rights | High |
| Data inventory does not cover third-party sharing | Data Mapping | High |
| Opt-out requests not honored within 15 business days | Consumer Rights | High |
| Service provider contracts missing required CCPA terms | Contracts | Medium |
| Risk assessment not documented for sensitive data | Risk Assessment | Medium |
| Privacy policy not updated in the last 12 months | Notice | Low |
A CCPA assessment documents where your privacy program stands against the law, and what to fix first. Six sections, evidence-linked throughout.
Overall CCPA posture and the priorities that matter most to leadership.
What personal information you collect, sell, and share, and where it flows.
How access, deletion, correction, and opt-out requests are handled against the law.
Controls tested against the CCPA cybersecurity audit criteria, evidence-linked.
High-risk processing evaluated and documented, as the regulations require.
Prioritized gaps with specific corrective actions and effort estimates.
If you handle the personal data of California residents at scale, the thresholds likely apply. These are the businesses they most often reach.
Loyalty programs, online tracking, and large customer bases push most retailers past the consumer threshold.
250,000+ consumersBusinesses that buy, sell, or share personal data are covered regardless of their size.
Sells or shares dataPlatforms with California users at scale, whether the data they hold is B2B or B2C.
250,000+ consumersSubscriber records and ad-driven tracking that reach California residents at volume.
250,000+ consumersConsumer financial data that falls outside what GLBA already covers.
Sensitive dataConsumer health and wellness data that HIPAA does not reach.
Sensitive dataThe cybersecurity audit must be performed by a qualified, objective, and independent professional auditor.California Consumer Privacy Act cybersecurity audit regulations Cal. Code Regs. tit. 11, §§ 7120-7124
Independence is written into the audit requirement itself. It is also how TestPros has always worked, with no software to sell and no program of ours to defend.
The thresholds, the new obligations, and what independence actually means for your audit.
CCPA compliance means meeting the requirements of the California Consumer Privacy Act, as amended by the CPRA. It covers how a business collects, uses, sells, and shares the personal information of California residents, the privacy rights it must honor, and, for larger businesses, an annual independent cybersecurity audit and documented risk assessments.
The CCPA applies to for-profit businesses doing business in California that handle residents' personal information and meet at least one threshold: more than $26.6 million in annual gross revenue (adjusted for inflation), handling the personal information of 100,000 or more consumers or households, or deriving 50% or more of revenue from selling or sharing personal information.
Under regulations effective January 2026, a subset of covered businesses must complete an annual cybersecurity audit. It applies if you derive more than half your revenue from selling or sharing personal information, or you meet the CCPA revenue threshold and process the personal information of 250,000 or more consumers or the sensitive personal information of 50,000 or more. First certifications phase in from 2028 to 2030 by revenue, but audit periods begin in 2027.
Often no. The audit must be performed by a qualified, objective, and independent auditor, and the regulations bar anyone who developed or maintains the program being audited. A firm that built, implemented, or manages your privacy or security program cannot also audit it. That structural independence is exactly what TestPros is built to provide.
The CCPA provides for civil penalties of up to $2,500 per violation, and up to $7,500 for each intentional violation or one involving the personal information of a consumer under 16. Enforcement is active, with recent settlements reaching into the millions, so the exposure is real and current.
They are the same law. The CCPA is the original 2018 statute. The CPRA, passed in 2020, amended and expanded it, adding new consumer rights, the category of sensitive personal information, and the regulations now taking effect. In common use, "CCPA" refers to the combined law.
Both govern personal data, but they differ in scope and approach. GDPR applies to the data of people in the EU and EEA; the CCPA applies to California residents. Many businesses fall under both, along with laws like HIPAA. TestPros assesses against each and maps the overlap, so you are not running separate engagements for separate laws.
Tell us where you stand, your thresholds, or your audit timeline. We respond within one business day with a scoped assessment plan.
Talk to an Independent Assessor