Return to Glossary
Regulatory DefinitionCybersecurityAudit & AssurancePrivacy

Cybersecurity Audit

Plain-language explanation

Under California's CCPA regulations, a cybersecurity audit is the annual audit required for a business whose processing of consumers' personal information presents significant risk to consumers' security under the applicable regulation.

Why It Matters

The California requirement introduces defined scope, independence, evidence, reporting, and certification expectations for businesses that meet the regulatory threshold.

In Practice

The California requirement should be distinguished from generic uses of the phrase cybersecurity audit. Applicability, audit content, auditor independence, reporting, and certification are governed by the CCPA regulations.