🎉 Launch offer — 20% off workbooks & bundles, applied automatically at checkout. Security Program Pillars guides are at list price.
ciso.diy
CCPA Cybersecurity Audit & Privacy Risk Assessment Kit preview
Compliance CCPACPPACalifornia privacycybersecurity audit

CCPA Cybersecurity Audit & Privacy Risk Assessment Kit

The assessment kit and audit workplan California actually asks for — applicability calculator, per-activity risk assessment template and register, ADMT addendum, the 18-component audit workplan with auditor-independence checklist, report skeleton, and the §7124 certification cover. Assessments for existing processing are due 31 December 2027.

What this actually gives you

  • California is the first US state to require a cybersecurity audit and documented privacy risk assessments by regulation rather than by contract. Assessments for processing already under way are due 31 December 2027; first certifications and submissions 1 April 2028.
  • All 18 components §7123(b) enumerates, with readiness scoring and the twelve-point auditor-independence checklist from §7122.
  • ADMT ships inside the kit rather than as an add-on: it is one of the six §7150(b) triggers, and an assessment that stops short of it is incomplete.
  • The crosswalk maps the 18 components to NIST CSF 2.0, ISO 27001:2022 and SOC 2 — including what a SOC 2 typically does not cover — so you reuse evidence you already hold.

California is the first US state to require a cybersecurity audit and documented privacy risk assessments by regulation rather than by contract, and the CPPA regulations that impose them took effect 1 January 2026. Assessments for processing already under way are due 31 December 2027; the first audit certifications and risk-assessment submissions are due 1 April 2028. Phase-in runs by revenue through 2030.

This kit is the practitioner toolset for both programmes and the ADMT layer that sits on top of them — scoping, running, documenting and filing.

What you get

01 Applicability & Phase-In Calculator (XLSX) — twelve questions per legal entity return your audit trigger, revenue tier under §7121(a), first audit period, certification date and risk-assessment deadlines. Run it once per entity; the phase-in is not group-wide.

02 Privacy Risk Assessment Template (DOCX) — one assessment per activity or comparable set, covering every element §7152 requires, with a DPIA-reuse appendix for anyone who already did the work under GDPR.

03 Risk Assessment Register (XLSX) — tracks every assessment and computes the three-year review and 45-day update dates for you, plus the count that goes in the annual §7157 submission.

04 ADMT Assessment Addendum (DOCX) — applicability test, logic and output description, the §7220 pre-use notice, §7221 opt-out and §7222 access rights, and training-data use. ADMT ships inside this kit rather than as an add-on: it is one of the six §7150(b) triggers, and an assessment that stops short of it is incomplete.

05 Cyber Audit Scoping & Workplan (XLSX) — all 18 components §7123(b) enumerates, with readiness scoring, the twelve-point auditor-independence checklist from §7122, and the evidence request list.

06 Cybersecurity Audit Report Skeleton (DOCX) — the report structure §7123(e) requires, one block per component, for the qualified, objective, independent auditor.

07 Certification & Submission Cover (DOCX) — the §7124 audit certification and §7157 submission field sets, with pre-signature checklists and a routing record.

08 Framework Crosswalk (XLSX) — the 18 components against NIST CSF 2.0, ISO 27001:2022 and SOC 2, including what a SOC 2 typically does not cover, so you reuse the evidence you already hold instead of starting over.

09 Board One-Pager (PPTX) — two slides: the obligation and the clock, then the plan, exposure and the ask.

10 Practitioner Guide (PDF) — who is covered, what is due when, how to run both programmes, a 90-day plan and an FAQ.

control-map.json — the machine-readable component, trigger and deadline map, with each audit component tagged to an ISMS-01 control domain and an ERR-01 hook for the register.

Pairs with the 2026 US Privacy Program Workbook for the wider state wave, the GDPR DPIA Workbook if you are reusing DPIAs under §7152(d), and the Living ISMS for the control plane the 18 components point at.

Attestations under these rules are made under penalty of perjury. This is a practitioner's toolset, not legal advice — have counsel review before signing, and decide privilege strategy before drafting assessments.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-03
Pages 10