Privacy Assessments
Businesses meeting certain thresholds as defined under the CCPA are required to conduct annual audits of their cybersecurity program.
The CCPA, passed in 2018, was amended in 2020 by the California Privacy Rights Act (CPRA). The CPRA established the California Privacy Protection Agency, the first dedicated state privacy authority in the United States tasked with enforcing the CCPA, developing regulations, and educating consumers and businesses about their privacy rights and obligations.
The CPRA also introduced new requirements under the CCPA, including for businesses “whose processing of consumers’ personal information presents a significant risk to consumers’ privacy or security to... perform a cybersecurity audit on an annual basis.” However, the specifics around the implementation were not provided within the amendments, and the onus for dictating the requirements was punted to the California Privacy Protection Agency with their responsibilities to develop regulations. The agency approved the regulations on July 24, 2025, and they became effective on January 1, 2026.
The California Privacy Protection Agency has defined “significant risk” as follows:
*Please note: this amount is adjusted every other year to reflect increases in the Consumer Price Index. You can monitor those updates here.
Understanding the CCPA cybersecurity audit requirements and mapping them to your organization's existing security framework is one thing. Implementing a unified compliance strategy is another. The complexity lies not just in understanding the regulations, but in translating them into concrete security practices, audit procedures, and documentation processes that work for your specific organization, industry, and risk profile.
This is where expertise matters. Navigating the intersection of CCPA compliance, cybersecurity best practices, and alignment with multiple frameworks requires specialized knowledge and experience. That's where Schellman comes in. Our team can help you conduct comprehensive readiness assessments that evaluate your existing security controls against CCPA audit requirements, identifying gaps and opportunities for improvement before official audits begin.
The planning phase occurs at least two months in advance of fieldwork in accordance with the timing outlined in the job arrangement letter (JAL) or statement of work (SOW) executed with the client. Planning includes the completion of an intake questionnaire, confirming timing of interviews with key points of contact, and deployment of and evidence gathering for the information request list provided via AuditSource 2.0. Schellman will be available to the client to answer any questions associated with the assessment to ensure both parties are aligned on scope and expectations.
Schellman will hold a kickoff meeting to start fieldwork. Fieldwork consists of various testing procedures to evidence the requirements are met. The testing procedures may include one of the following:
Schellman has a no surprises policy and regular contact with the client during fieldwork, allowing clients to be apprised at all times of conformance status.
Schellman's assessment is focused on creating a deliverable that is clear, concise, and accurate. The draft report is provided within 2-3 weeks of the last day of fieldwork. The final deliverable is available within 5 business days of the client approving the draft version.
Chris is a Director and Privacy Technical Lead at Schellman based out of Atlanta, GA. With more than five years of experience in information assurance, Chris has a concentration in privacy-related engagements.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: