
Gwen Takagawa
Senior Consultant, Coalfire (CIPP/US, CIPP/E, CIPM, PMP)
Cyber Risk Advisory


On July 24, 2025, the California Privacy Protection Agency (CPPA) approved new regulations defining the requirements for annual cybersecurity audits, routine privacy risk assessments, and the applicability of the California Consumer Privacy Act on automated decision-making technology (ADMT).
This blog summarizes key elements for cybersecurity audits, privacy risk assessments, and ADMT, including:
Update: As of September 23, 2025, the California Office of Administrative Law (OAL) has officially approved the regulations discussed in this blog. After OAL approval, the CPPA summarized the critical timelines as follows:
The new CCPA regulations mandate an annual cybersecurity audit completed by a qualified, objective, independent, professional cybersecurity auditor.
Coalfire discussed previous versions of California’s regulations on cybersecurity audits here. The earlier analysis remains relevant in that it highlights which aspects of these requirements are mandatory, and which may be changed at the CPPA’s discretion.
The CPPA Board has repeatedly indicated concern over the financial burden of the regulations on businesses. The analysis accompanying the final regulations estimates 71% of the financial burden on businesses will come from the annual cybersecurity audit obligation.
Those businesses whose processing of consumer’s personal information (PI) presents a “significant risk” are in scope. Such “significant risk” includes business that either:
That being said, all businesses in-scope for the CCPA have a mandate to implement “reasonable security.” The CPPA reduced the estimated financial burden of the cybersecurity audit requirements based on an assumption that: “All businesses should already be using an existing cybersecurity framework to comply with these existing requirements.”
The first deadline isn’t until April 2028, although preparation and documentation must begin at least a year prior. The regulations include a ramp-up period between 2025 and 2030, to allow smaller companies a longer window to come into compliance.
This table summarizes the timelines by business size:
| Annual Gross Revenue Threshold | First Annual Audit Reporting Period | Due Date to Certify Audit Completion |
|---|---|---|
| >$100M in 2026 | 1/1/2027 – 1/1/2028 | April 1, 2028 |
| $50-100M in 2027 | 1/1/2028 – 1/1/2029 | April 1, 2029 |
| <$50M in 2028 | 1/1/2029 – 1/1/2030 | April 1, 2030 |
After April 1, 2030, businesses must assess at the beginning of each calendar year if they are in-scope by the annual-gross-revenue definition. If so, they must then complete a cybersecurity audit covering the next 12 months, due on April 1 of the following year.
The new CCPA regulations require formal, written assessments when businesses propose to use consumers’ personal information in ways that present “significant risk” to consumers’ privacy. The regulations define six cases that constitute “significant risk,” summarized below:
The goal is to restrict or prohibit processing of personal information where the risks to consumers’ privacy outweigh the benefits resulting from processing to the consumer, the business, other stakeholders, and the public.
Additional obligations include:
Coalfire discussed previous versions of regulations on privacy risk assessments here. This analysis compares California’s proposed risk assessment requirements with similar requirements in other states. California’s regulations explicitly seek to streamline multistate compliance and encourage businesses to use risk assessments prepared for other jurisdictions, supplemented if necessary to capture all California requirements.
All businesses in-scope for the CCPA need to assess whether their processing of consumers’ personal information presents “significant risk,” discussed above.
The CPPA reduced the estimated financial burden of the privacy risk assessments by removing behavioral advertising from the list of cases constituting significant risk.
The effective data is still being determined. After the effective date risk assessments are required to be completed prior to processing activities that lead to “significant risk,” as described above.
For any processing activities in effect prior to the effective date, the regulations allow businesses a grace period until December 31, 2027.
Businesses are required to review risk assessments at least every three years, or within 45 calendar days of a material change relating to the processing activity.
Businesses are also required to submit an annual report summarizing the risk assessments conducted in the reporting period. The first report is required April 1, 2028, covering risk assessments completed in 2026 and 2027.
The new regulations add two significant ADMT requirements:
As noted under privacy risk assessments, certain uses of ADMT trigger requirements for risk assessments. ADMT is broadly defined as using “computation to replace ... or substantially replace human decision making.” Systems with human oversight are not included, though the human must be able to interpret system outputs, analyze outputs and other information necessary to make or overturn a decision, and have the authority to make or change the decision based upon the analysis.
In addition to the requirements for privacy risk assessments more broadly, ADMT-specific assessments should note:
In addition to risk assessments, companies using ADMT for significant decisions must also:
All businesses in-scope for CCPA should assess their use of ADMT for potential triggers.
The regulations focus on “significant decisions.” In brief, these include “a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services.” Each of these components is defined in the regulations.
The scope of the CCPA regulations, and the extent to which artificial intelligence technologies should be regulated by the CPPA, has been a subject of much debate, by the CPPA’s Board, as well as in public comment and by legislators. By substantially narrowing the definition of ADMT included in the regulations, the CPPA estimates that only 10% of in-scope businesses will have responsibilities under the ADMT rules.
Businesses that use ADMT for significant decisions prior to January 1, 2027, must be in compliance no later than that date. Subsequent use must be in compliance with the regulations at the time ADMT is used for significant decisions.
While final dates for enforcement await confirmation by the OAL, businesses should begin preparing now.
The phased timelines offer organizations the opportunity to build or enhance their compliance programs. Leveraging existing frameworks, such as the NIST Cybersecurity Framework and the NIST Privacy Framework, can help streamline these efforts and support cross-functional coordination. Maintaining an accurate data inventory, assigning clear accountability, and establishing procedures to assess and document privacy risks are all essential steps.
Taken together, these regulations underscore the increasing convergence of privacy and security. Businesses that invest early in aligning their programs to these expectations will be better positioned to demonstrate compliance, manage risk, and uphold consumer trust as enforcement begins.
***
Coalfire specializes in supporting businesses at every stage of cybersecurity and privacy program development. From readiness assessments and framework-based implementation to formal audit attestations, our team can help you navigate the new CCPA requirements. Whether this is your first formal privacy program or your fifteenth cross-mapped standard, Coalfire is prepared to meet your needs.