Risk Assessments & Cybersecurity Audit Certification Requirements (Rolling Deadlines: 2026–2030)
Regulations from the California Privacy Protection Agency (CPPA) require businesses to conduct a risk assessment before starting any processing of personal information that presents a "significant risk" to consumer privacy. For covered processing activities that began before January 1, 2026, and continue on or after that date, assessments must be completed by December 31, 2027. Annual summary reporting and attestation to the California Privacy Protection Agency (CPPA) begins April 1, 2028. Businesses must also amend their service provider agreements to require their service providers to assist them in completing their cybersecurity audits, risk assessments, and complying with the new Automated Decision-Making Technology requirements. Unlike the risk assessment, the cybersecurity audit submission deadlines vary between April 1, 2028 and April 1, 2030 depending on the size of the business’s gross revenue.
Related Content
