CCPA Cybersecurity Audits: What SaaS Vendors Need to Do Before 2027

LinkedIn
X
WhatsApp
Facebook
Email
Print

CCPA audit requirements checklist for SaaS vendors, Aber Law Firm

If you are a SaaS vendor with a real California footprint, the CCPA audit requirements probably reach you, and the first audit period starts January 1, 2027. Covered businesses have to run an annual, independent cybersecurity audit, write up every gap they find, and certify completion to CalPrivacy. The first certifications are due April 1, 2028.

I represent lots, literally 100s and 100s, of software and SaaS vendors, and most of them read “CCPA” and think privacy policy and opt-out links. This one is different. It is a security audit with a regulator on the other end, and it hits you twice: once for your own data, and again when your customers start asking you to help with theirs.

Covington put out a good alert on this in September, and I agree with the headline. Get ready now. Here is the vendor side of it.

Who Has to Do One.

The CCPA audit requirements are in Article 9 of the CCPA regulations (11 CCR sections 7120 to 7124), and they took effect January 1, 2026. You are in scope if either of these is true:

  • Data broker math. You make 50% or more of your annual revenue from selling or sharing personal information.
  • Size plus volume. You clear the CCPA revenue threshold (about $26.6 million after the inflation adjustment), and in the prior year you processed the personal information of 250,000 or more California consumers or households, or the sensitive personal information of 50,000 or more.

Here is the part that catches software companies. “Personal information” includes IP addresses, device IDs, and other online identifiers. So a product that logs devices, a marketing site with serious traffic, or a telemetry pipeline can put you over 250,000 without anyone at the company thinking of it as “customer data.” Data you handle purely as a service provider for your customers is a harder counting question. Start with what you collect for your own purposes and work outward.

When the First Audits Are Due.

The deadlines phase in by revenue (section 7121):

  • Over $100 million in 2026 revenue. Audit covers calendar year 2027. Certification due April 1, 2028.
  • $50 million to $100 million in 2027 revenue. Audit covers 2028. Due April 1, 2029.
  • Under $50 million in 2028 revenue. Audit covers 2029. Due April 1, 2030.

After 2030 it is every year. And the certification is signed by a member of your executive team under penalty of perjury (section 7124). That tends to get the CFO’s attention.

What the Auditor Looks At.

This is not a questionnaire you fill out yourself. The auditor has to be qualified, objective, and independent. They can be internal, but only if they report to an executive who does not run your security program. And no finding can rest “primarily on assertions or attestations by the business’s management.” The auditor needs documents, testing, and sampling.

Section 7123 lists 18 areas to assess where they apply, including multi-factor authentication, encryption at rest and in transit, access controls, data inventories, patch management, penetration testing, logging, vendor oversight, incident response, and backups. It also covers retention schedules and disposal, which is one more reason to get your data retention policy in order.

Good news if you already have a SOC 2 or ISO 27001 program. Section 7123(f) lets you reuse an audit prepared for another purpose (the rule’s own example is NIST CSF 2.0) as long as it meets the Article 9 requirements on its own or with supplementation. Expect to supplement. The California report has specific contents a SOC 2 report does not.

Why January 1, 2027 Matters.

The report has to “identify and describe in detail” every gap or weakness the auditor finds, plus your plan and timeline to fix it. You and the auditor keep the audit records for five years.

Think about what that document is. It is a written list of your security weaknesses, made in the ordinary course of business. If you have a breach in 2028, that is the first thing a plaintiff’s lawyer asks for. The audit report is not privileged.

So fix the known gaps before the audit period starts, not during it. A readiness review run through counsel before January 1, 2027 lets you find and close gaps in a setting that has a real shot at privilege. After January 1, whatever is broken goes in the report.

What Your Customers Will Ask For.

This is where most of my clients will actually feel it. Your enterprise customers are CCPA businesses too, and many of them are in scope. Their auditors will want evidence about you, because vendor oversight is one of the 18 areas.

The regulations already require you to help. Section 7050(h) says a service provider “shall… cooperate” with the business’s cybersecurity audit, make available relevant information in its possession, and not misrepresent any fact the auditor deems relevant. I covered that duty briefly in my post on automated decision making. The accuracy piece is real. Security questionnaires filled out by a sales engineer at 11 p.m. are now a regulatory problem.

Customers will not stop at the regulation. Expect DPA and MSA drafts with on-site audit rights, unlimited frequency, audits at your cost, and fix-everything-in-30-days language. Here is where I would land for a vendor:

  • Tie it to the rule. Cooperation covers personal information you collected under that customer’s contract. That is the scope of section 7050(h), and it should be the scope of your clause.
  • Paper first. Lead with your SOC 2 or ISO report, a standard security package, and one questionnaire a year. On-site audits only after a breach or a regulator’s request.
  • Protect the rest. Auditors sign an NDA. No access to other customers’ data. No duty to create new documents.
  • Price the extras. Reasonable notice, business hours, and customer pays for anything beyond the standard package.
  • No open-ended remediation. Agree to fix material findings on a reasonable, agreed plan. Do not attach indemnity or uncapped liability to audit findings.

Decide your standard position now and put it in your paper, so it is the same answer every time. This is the same discipline we bring to any SaaS contract negotiation: bound the obligation, then price it. A good trust site also cuts down how often you get asked.

Questions I Get.

  • We are not a California company. Does this apply? Yes, if you hit the thresholds. It turns on California residents’ data, not where you are based.
  • We are under $50 million in revenue. Can we wait? Your first audit covers 2029, so you have time. But your customers’ audits start in 2027, and they will come to you for evidence first.
  • Can our SOC 2 auditor do it? Often, yes, as long as they meet the independence rules and the report covers what section 7123 requires.
  • Is this the same as the risk assessment rule? No. Risk assessments are a separate article with a separate April 2028 submission. Same regulation package, different duty.
  • Does this apply outside California? Not as written. Other state privacy laws require reasonable security, but none has an annual certified audit like this one.

The practical move is boring. Count your California identifiers, run a readiness review before year end, and write your audit-cooperation clause before a customer writes it for you.

I hope this helps.

Resources:

Disclaimer:

This post is for informational and educational purposes only, and is not legal advice. You should hire an attorney if you need legal advice, which should be provided only after review of all relevant facts and applicable law.


Discover more from Aber Law Firm

Subscribe to get the latest posts sent to your email.

Free Initial Consultation

Get started with a free initial consultation. Fill out the form below to connect with our experts today!