New Report: The State of AI Governance 2026

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Privacy Assessments

CCPA Cybersecurity Audits

Businesses meeting certain thresholds as defined under the CCPA are required to conduct annual audits of their cybersecurity program. 

Contact a Specialist Build Your Compliance Roadmap

Background and Overview of CCPA Rulemaking

The CCPA, passed in 2018, was amended in 2020 by the California Privacy Rights Act (CPRA). The CPRA established the California Privacy Protection Agency, the first dedicated state privacy authority in the United States tasked with enforcing the CCPA, developing regulations, and educating consumers and businesses about their privacy rights and obligations.

The CPRA also introduced new requirements under the CCPA, including for businesses “whose processing of consumers’ personal information presents a significant risk to consumers’ privacy or security to... perform a cybersecurity audit on an annual basis.” However, the specifics around the implementation were not provided within the amendments, and the onus for dictating the requirements was punted to the California Privacy Protection Agency with their responsibilities to develop regulations. The agency approved the regulations on July 24, 2025, and they became effective on January 1, 2026. 

FERPA-assessment

Applicability of the CCPA Cybersecurity Audit

The California Privacy Protection Agency has defined “significant risk” as follows:

  • The business derives 50% or more of its annual revenue from selling or sharing consumers’ personal information; OR
  • The business has an annual gross revenue more than $26,625,000* in the preceding calendar year, and:
  • Processed the personal information of 250,000 or more consumers or households in the preceding calendar year; OR
  • Processed the sensitive personal information of 50,000 consumers in the preceding calendar year   

*Please note: this amount is adjusted every other year to reflect increases in the Consumer Price Index. You can monitor those updates here. 

FERPA-assessment
schellman-ccpa-assessment

Readiness Assessments

Understanding the CCPA cybersecurity audit requirements and mapping them to your organization's existing security framework is one thing. Implementing a unified compliance strategy is another. The complexity lies not just in understanding the regulations, but in translating them into concrete security practices, audit procedures, and documentation processes that work for your specific organization, industry, and risk profile.

This is where expertise matters. Navigating the intersection of CCPA compliance, cybersecurity best practices, and alignment with multiple frameworks requires specialized knowledge and experience. That's where Schellman comes in. Our team can help you conduct comprehensive readiness assessments that evaluate your existing security controls against CCPA audit requirements, identifying gaps and opportunities for improvement before official audits begin.   

schellman-ccpa-assessment

CCPA Cybersecurity Assessment Process

Schellman performs each assessment with your end goals and preparation for future key compliance initiatives in mind.  Effective communication and timely coordination of project activities are central to our methodology.

1. Planning

2. Fieldwork

3. Reporting

CCPA Specialist

Chris Lippert

Chris is a Director and Privacy Technical Lead at Schellman based out of Atlanta, GA. With more than five years of experience in information assurance, Chris has a concentration in privacy-related engagements.

Meet Chris Contact Us

  • Using an outcome based, fixed-fee pricing model based on our extensive experience
  • Scope creep: we see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low overhead means a flexible financial structure

How much will your audit cost?

Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.

The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.

Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:

  • Using an outcome based, fixed-fee pricing model based on our extensive experience
  • Scope creep: we see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low overhead means a flexible financial structure

Talk to a Practice Leader