
Gwen Takagawa
Principal, Cyber Risk Advisory (FIP, CIPP/US, CIPP/E, CIPM, PMP)
Cyber Risk Advisory


In Coalfire’s conversations with organizations preparing for CCPA cybersecurity audits, two questions come up repeatedly: what is actually in scope, and to what extent do existing audits address the requirements?
The starting point is deceptively simple: identify the systems that process or provide access to CCPA-covered data.
The second question is where the “deceptively simple” scope gets complicated. Most companies in scope for the first CCPA cybersecurity audit cycle already have a cybersecurity program covering at least some of their CCPA-covered data. The regulations explicitly authorize companies to make use of their existing cybersecurity audit programs to meet this obligation.
However, there is a caveat: prior audits satisfy the obligation only to the extent that these audits meet the defined requirements.
Understanding how well prior audits address the requirements comes down to three conversations about scope:
This blog reviews each of these areas, offering insight into opportunities to best prepare for these coming requirements.
Each audit framework has a different approach for defining the system boundary. For ISO-based cybersecurity audits, the Information Security Management System (ISMS) defines the boundary. For SOC, the systems supporting the defined service are in scope. These approaches allow businesses to narrow the scope of a cybersecurity audit to a documented and defensible boundary.
The boundary for the CCPA cybersecurity audit instead follows the data: which systems process or provide access to CCPA personal information?
The regulation defines “information systems” broadly, to include “the resources (e.g., network, hardware, and software) organized for the processing of personal information or that can provide access to personal information.” The definition further includes systems owned and managed by third parties, if applicable, so the audit plan should also establish a defensible approach to vendor-managed systems. The boundary follows the data, going beyond customer data to include employment- and vendor-related personal information of California residents.
While existing cybersecurity audit evidence and conclusions can be leveraged for the CCPA cybersecurity audits, companies seeking to understand the additional evidence and analysis required for these new audits should begin by understanding the existing boundaries applied in current audits, identifying in-scope systems beyond that boundary, and confirming the cybersecurity controls that apply to these now in-scope systems.
The CCPA regulations set out 18 cybersecurity focus areas as the baseline for the audit. For the most part, these align with traditional cybersecurity frameworks: encryption, identity and access management, vulnerability management, and so on. The audit may also address additional cybersecurity controls that are appropriate and proportionate in light of the business’s size, complexity, and data processing.
As with any new framework, nuances emerge when comparing against existing requirements. In particular, section 7123 describes obligations specific to the relationship between cybersecurity controls and the use of personal information by the organization, such as:
These requirements extend beyond the scope of many traditional cybersecurity control frameworks.
For the most part, cybersecurity frameworks allow variation in reporting period, as long as companies maintain continuous coverage. By contrast, the regulations mandate calendar-year coverage for the audit report. All in-scope companies then submit a written certification of audit completion to CalPrivacy on April 1 following the covered period.
For an overview of applicability and phased deadlines, see California Board approves more CCPA regulations: What businesses need to know.
If an organization’s existing audit cycles do not align with the CCPA reporting period, they should plan early for a bridge period. A practical approach is to map the existing audit’s coverage window against the required calendar-year period, identify gaps or periods of partial coverage, and agree with the auditor on the supplemental evidence and testing needed to achieve complete coverage. Depending on the control and evidence required, this may involve roll-forward procedures, targeted testing, updated populations, or other supplemental procedures. Establishing the approach early helps coordinate internal control owners, third parties, and auditor requests and avoids discovering period-coverage gaps during report finalization.
Organizations preparing for the first CCPA cybersecurity audit cycle should begin by mapping existing audit boundaries, personal-information flows, third-party dependencies, and available evidence. Coalfire helps organizations develop defensible audit scopes and practical readiness plans that integrate with existing cybersecurity and compliance programs.
Coalfire routinely works with customers on Coordinated Assessment Programs (CAPs), leveraging the proprietary Compliance Essentials tool to coordinate evidence collection across multiple audits, enabling seamless integration of CCPA Cybersecurity Audits with existing programs.
Contact us to discuss your organization’s approach.