Cyber Risk Advisory

CCPA Readiness Starts with Three Scope Questions

Gwen Takagawa

Gwen Takagawa

Principal, Cyber Risk Advisory (FIP, CIPP/US, CIPP/E, CIPM, PMP)

September 29, 2026
CCPA Cybersecurity Audit Scoping 1

In Coalfire’s conversations with organizations preparing for CCPA cybersecurity audits, two questions come up repeatedly: what is actually in scope, and to what extent do existing audits address the requirements?

The starting point is deceptively simple: identify the systems that process or provide access to CCPA-covered data.

The second question is where the “deceptively simple” scope gets complicated. Most companies in scope for the first CCPA cybersecurity audit cycle already have a cybersecurity program covering at least some of their CCPA-covered data. The regulations explicitly authorize companies to make use of their existing cybersecurity audit programs to meet this obligation.

However, there is a caveat: prior audits satisfy the obligation only to the extent that these audits meet the defined requirements.

Understanding how well prior audits address the requirements comes down to three conversations about scope:

  1. Systems: CCPA cybersecurity audits follow in-scope data, often expanding the scope beyond boundaries defined for prior audits. Enterprise data (employment- or vendor-related personal information) and systems defined outside the boundary have traditionally not received the same level of scrutiny and may not be subject to the same cybersecurity control framework.
  2. Controls: CCPA cybersecurity audit requirements emphasize how personal data is used, not just stored. A security-driven approach identifies where data is so it can be secured. This privacy-driven audit goes beyond traditional security control frameworks to evaluate controls that reduce the risk of data (mis)use.
  3. Timeline: CCPA cybersecurity audits require calendar-year coverage. Existing audits frequently align to a different cycle, requiring additional evidence to cover the CCPA-defined timeline.

This blog reviews each of these areas, offering insight into opportunities to best prepare for these coming requirements.

1. Systems: CCPA Cybersecurity Audit Boundary Follows Personal Information Across the Enterprise

Each audit framework has a different approach for defining the system boundary. For ISO-based cybersecurity audits, the Information Security Management System (ISMS) defines the boundary. For SOC, the systems supporting the defined service are in scope. These approaches allow businesses to narrow the scope of a cybersecurity audit to a documented and defensible boundary.

The boundary for the CCPA cybersecurity audit instead follows the data: which systems process or provide access to CCPA personal information?

The regulation defines “information systems” broadly, to include “the resources (e.g., network, hardware, and software) organized for the processing of personal information or that can provide access to personal information.” The definition further includes systems owned and managed by third parties, if applicable, so the audit plan should also establish a defensible approach to vendor-managed systems. The boundary follows the data, going beyond customer data to include employment- and vendor-related personal information of California residents.

While existing cybersecurity audit evidence and conclusions can be leveraged for the CCPA cybersecurity audits, companies seeking to understand the additional evidence and analysis required for these new audits should begin by understanding the existing boundaries applied in current audits, identifying in-scope systems beyond that boundary, and confirming the cybersecurity controls that apply to these now in-scope systems.

2. Controls: How CCPA Cybersecurity Audits Go Beyond Traditional Security

The CCPA regulations set out 18 cybersecurity focus areas as the baseline for the audit. For the most part, these align with traditional cybersecurity frameworks: encryption, identity and access management, vulnerability management, and so on. The audit may also address additional cybersecurity controls that are appropriate and proportionate in light of the business’s size, complexity, and data processing.

As with any new framework, nuances emerge when comparing against existing requirements. In particular, section 7123 describes obligations specific to the relationship between cybersecurity controls and the use of personal information by the organization, such as:

  1. Inventories include not just hardware and software, but also the management of personal information, such as how tagging is used to control the use and disclosure of personal information.
  2. Secure configuration includes the masking of sensitive personal information as defined by the CCPA as the default setting in applications.
  3. Third-party risk management explicitly includes oversight of compliance with CCPA contract requirements, of which the first six listed items relate to their use of personal information.

These requirements extend beyond the scope of many traditional cybersecurity control frameworks.

3. Timeline: Planning for a Calendar-Year CCPA Cybersecurity Audit Cycle

For the most part, cybersecurity frameworks allow variation in reporting period, as long as companies maintain continuous coverage. By contrast, the regulations mandate calendar-year coverage for the audit report. All in-scope companies then submit a written certification of audit completion to CalPrivacy on April 1 following the covered period.

For an overview of applicability and phased deadlines, see California Board approves more CCPA regulations: What businesses need to know.

If an organization’s existing audit cycles do not align with the CCPA reporting period, they should plan early for a bridge period. A practical approach is to map the existing audit’s coverage window against the required calendar-year period, identify gaps or periods of partial coverage, and agree with the auditor on the supplemental evidence and testing needed to achieve complete coverage. Depending on the control and evidence required, this may involve roll-forward procedures, targeted testing, updated populations, or other supplemental procedures. Establishing the approach early helps coordinate internal control owners, third parties, and auditor requests and avoids discovering period-coverage gaps during report finalization.

Coalfire Helps Organizations Define Scope and Prepare for CCPA Cybersecurity Audits

Organizations preparing for the first CCPA cybersecurity audit cycle should begin by mapping existing audit boundaries, personal-information flows, third-party dependencies, and available evidence. Coalfire helps organizations develop defensible audit scopes and practical readiness plans that integrate with existing cybersecurity and compliance programs. 

Coalfire routinely works with customers on Coordinated Assessment Programs (CAPs), leveraging the proprietary Compliance Essentials tool to coordinate evidence collection across multiple audits, enabling seamless integration of CCPA Cybersecurity Audits with existing programs. 

Contact us to discuss your organization’s approach.