CPRA Regulations: The 2026 CCPA Rules and What They Require
The CPRA regulations changed materially in 2026, and the change is operational rather than definitional. California's rulemaking added three duties that did not exist before: documented risk assessments, annual cybersecurity audits certified to the regulator, and consumer rights over automated decisionmaking technology.
This post covers what those regulations require and the deadlines attached to each. If what you actually want is the statutory comparison between the two laws, that is a different question, answered in CCPA vs CPRA. Everything below assumes you already know CPRA amended the CCPA and are asking what the rules now make you do.
A note on dates. Rulemaking moves. Every date in this post was verified against the California Privacy Protection Agency's own announcement of September 23, 2025 and the agency's regulations page as of September 2026. Before you build a compliance calendar on any of it, confirm against the current text at cppa.ca.gov/regulations. The agency also uses the shorthand CalPrivacy in its own materials, which is the same body, not a new one.
What Actually Changed
The California Office of Administrative Law approved the regulation package on September 23, 2025. It covers cybersecurity audits, risk assessments, automated decisionmaking technology, insurance company obligations, and updates to the existing CCPA regulations.
The regulations took effect January 1, 2026, with compliance obligations phased in through 2030.
That phasing matters. The regulations being "in effect" does not mean every duty was enforceable that day. Each of the three main obligations has its own compliance date, and two of them sit years out.
| Obligation | Compliance begins | First filing to the agency |
|---|---|---|
| Risk assessments | January 1, 2026 | April 1, 2028 |
| ADMT consumer rights | January 1, 2027 | No standalone filing |
| Cybersecurity audit certification | Staggered | April 1, 2028 / 2029 / 2030 by revenue |
Risk Assessments
The requirement most likely to affect a SaaS company, and the one with the longest runway that quietly expires.
What it requires
Businesses whose processing presents significant risk to consumer privacy must conduct and document a risk assessment for that processing. The assessment weighs the benefits of the processing against the risks to consumers, and documents the safeguards that address them.
If that sounds familiar, it should. Structurally it is close to a GDPR Article 35 data protection impact assessment, which is the single most useful thing to know if you already run a GDPR program.
The dates
Risk assessment obligations begin January 1, 2026.
For processing that started before January 1, 2026 and continues after it, the risk assessment must be conducted and documented no later than December 31, 2027. That is the backlog clause, and it covers most of what an established business is already doing.
The first mandatory filing is due to the agency by April 1, 2028. It is not the assessments themselves: it is an attestation that the required assessments were completed, plus a summary of the assessment information, covering assessments conducted during 2026 and 2027.
Why the long runway is a trap
April 2028 reads as distant. The work is not.
You cannot attest in 2028 to assessments you never conducted in 2026 and 2027. The obligation to do the work starts now; only the paperwork to the regulator is deferred. A business that treats April 2028 as the start date arrives with an attestation it cannot honestly sign and a backlog it cannot retroactively create.
The practical move is to start the inventory of processing activities that may trigger an assessment, and to build the assessment template once, in a form that also satisfies GDPR if you have EU exposure.
Cybersecurity Audits
What it requires
Businesses whose processing presents significant risk to consumer security must complete an annual cybersecurity audit and certify completion to the agency.
The audit is a genuine assessment of the security program, and the certification to the regulator is what makes this different from every security audit you already run voluntarily. A SOC 2 report or ISO 27001 certificate is not a substitute, though a mature program built for either makes this audit considerably cheaper.
The dates
Certifications are due on a revenue-staggered schedule:
- April 1, 2028 for businesses with over $100 million in revenue
- April 1, 2029 for businesses with $50 million to $100 million in revenue
- April 1, 2030 for businesses under $50 million in revenue
Smaller businesses get more runway, which is sensible, but the same trap applies: the audit covers a period, and the period precedes the filing.
How it interacts with what you already have
If you hold SOC 2 or ISO 27001, most of the underlying control work exists. What does not exist is the specific audit scope and the certification mechanism to a state regulator. Plan for an incremental exercise scoped against the California requirements rather than a wholly separate program. The overlap between security frameworks is the reason this is additive rather than duplicative, and the SOC 2 service page and ISO 27001 service page both cover programs that carry most of the load.
Automated Decisionmaking Technology
The newest of the three, and the one that most directly touches product roadmaps.
What it requires
Businesses using ADMT to make significant decisions about consumers must meet specific obligations: pre-use notice explaining the technology and its purpose, the ability for consumers to opt out in defined circumstances, and the ability for consumers to access information about how the technology was used in a decision about them.
Significant decisions are the ones that change what a person can get: financial or lending services, housing, education enrollment or opportunity, employment or independent contracting opportunities, and healthcare services.
The date
ADMT compliance begins January 1, 2027.
Why this one needs engineering lead time
The other two obligations are largely governance work: assessments, documentation, audits. ADMT is different, because the access right means being able to tell a consumer how a decision about them was reached.
That is a product requirement. If a model makes a significant decision and your system keeps no record of the inputs and logic applied to that individual case, you cannot answer the request, and the fix is in the application rather than in a policy document. Retrofitting decision logging into a live scoring pipeline is not a quarter-end task.
If you also use AI for these decisions, the governance scaffolding overlaps heavily with an AI management system. ISO 42001 certification covers that path.
Does This Apply to You?
Two separate questions, and businesses conflate them.
Are you a covered business under CCPA? The applicability thresholds are the gate. If you do business in California, determine the purposes and means of processing California residents' personal information, and meet a threshold, you are covered. Your own location is irrelevant.
Does each new duty apply to you? Not every covered business owes all three. The risk assessment and cybersecurity audit duties attach to processing that presents significant risk, defined in the regulations. The ADMT duties attach to using the technology for significant decisions. A covered business doing none of those may owe none of the three while still owing the core CCPA obligations.
Work out which bucket each of your processing activities falls into before scoping anything. Confirm the threshold and definitional detail against the current regulation text, because this is precisely the kind of provision that secondary sources summarize loosely.
Build One Assessment Process, Not Two
The most valuable planning insight here is the overlap with GDPR.
A company with EU customers and California consumers now faces two risk assessment regimes with a shared analytical core:
- Describe the processing and the data
- Identify who is affected and how
- Weigh benefits against risks to individuals
- Document safeguards and residual risk
The differences are at the edges: what triggers an assessment, the mandated content, retention, and whether anything gets filed with a regulator. California's April 2028 attestation is an affirmative filing. GDPR's Article 36 consultation is exception-driven, triggered only when high residual risk remains.
Build one template carrying the union of the required fields, with jurisdiction-specific sections that switch on based on where the data subjects are. One owner, one review cadence, one backlog to work through. Running two parallel programs over the same product features is how both go stale.
The data protection impact assessment guide covers the GDPR half in detail, including the Article 35(7) content requirements that should anchor the shared template.
What to Do in the Next Quarter
- Confirm applicability. Covered business, yes or no. Then, per processing activity, which of the three duties attach.
- Inventory processing that may trigger a risk assessment. You cannot assess what you have not listed.
- Build the assessment template once. Union of California and GDPR fields if you have EU exposure.
- Start clearing the pre-2026 backlog. December 31, 2027 covers processing that started before 2026 and continues, and that is most of what you run.
- Scope the cybersecurity audit against what you already hold. Find your revenue tier, work back from the filing date.
- Check whether any model makes significant decisions. If yes, decision logging is an engineering item with a January 1, 2027 date on it.
For the statutory comparison between the two laws, see CCPA vs CPRA. For the operational baseline, the CCPA compliance checklist and the CCPA service page cover the core obligations these regulations build on. If you run both California and EU programs, the data protection impact assessment guide and the GDPR service page are the companion reads, and GDPR and CCPA compliance covers running the two together.
Frequently Asked Questions
What do the current CPRA regulations require? Beyond existing CCPA obligations, three new duties: documented risk assessments for defined high-risk processing, annual cybersecurity audits certified to the agency on a revenue-based schedule, and consumer rights around automated decisionmaking technology used for significant decisions. Each has its own compliance date.
When do the new CCPA regulations take effect? They took effect January 1, 2026, with compliance phased through 2030. Risk assessments begin January 1, 2026 with the first attestation due April 1, 2028, and pre-2026 processing assessed by December 31, 2027. ADMT compliance begins January 1, 2027. Cybersecurity audit certifications fall on April 1, 2028, 2029, or 2030 by revenue.
Does CPRA only apply to California residents? It protects California residents but binds businesses wherever they are located. A company anywhere is in scope if it does business in California, meets an applicability threshold, and determines the purposes and means of processing California residents' personal information.
What does CCPA compliance mean in practice? Notice at or before collection, honoring rights requests within statutory windows, contracts with every service provider and third party receiving personal information, and under the current regulations the governance artifacts: risk assessments, cybersecurity audits, and ADMT disclosures where those duties apply.
Is CCPA the same as GDPR? No, but they overlap enough that one program can serve both. GDPR requires a lawful basis before processing; CCPA runs on notice and opt-out. The closest convergence is assessments: California's risk assessment is structurally near enough to a GDPR Article 35 DPIA that one assessment process can satisfy both.
Need a California and GDPR Assessment Program That Shares One Process?
ShieldKey Solutions builds privacy governance for US SaaS companies facing both regimes. We work out which of the three California duties actually attach to your processing, build one assessment template that satisfies California and GDPR together, and back-plan from the filing dates so the attestation is something you can honestly sign.