PwC's accounting podcast
Listen in as PwC specialists discuss today’s most compelling accounting, reporting, and business issues. Whether financial reporting or sustainability reporting, each episode is packed with insights you won't find anywhere else.
PwC's accounting podcast
California’s new cybersecurity audit requirements – Are you ready?
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
New cybersecurity audit requirements under the California Consumer Privacy Act (CCPA) establish a recurring, independent assessment of certain organizations’ cybersecurity programs, with the first audit period beginning January 1, 2027. We discuss which organizations may be subject to the requirements, key considerations on audit scope and independence, and how existing cybersecurity, risk, and assurance activities can support readiness.
For more on California’s cybersecurity audit requirements, see our publication Privacy becomes a cybersecurity imperative under California’s audit rule.
Follow this podcast on your favorite podcast app and subscribe to our weekly newsletter to stay informed.
About our guests
Mark Cornish is a partner at PwC who provides assurance and consulting services to global and regional clients within the financial services industry. He is recognized for his experience in complex third-party assurance reporting, internal controls, and risk and compliance matters. His areas of expertise include internal control over financial reporting, SOC 1 and SOC 2 reporting, cybersecurity risk management, privacy, and regulatory compliance.
Chris Santucci is a partner in PwC’s Cyber, Data & Technology Risk practice who helps global companies across sectors build, operate, and assess data privacy and protection programs through technology-enabled solutions. His expertise spans global privacy program design and regulatory preparedness (including CCPA, GDPR, etc.), data discovery and risk analysis, program assessment and implementation, privacy impact assessments, third-party risk management, as well as sustainable risk and compliance services.
About our guest host
Diana Stoltzfus is a partner in PwC’s National Office who helps to shape PwC’s perspectives on regulatory matters, responses to rulemakings and policy development, and implementation related to significant new rules and regulations. She is also one of the firm’s technical experts on sustainability reporting. Prior to rejoining PwC, Diana was the Deputy Chief Accountant in the Office of the Chief Accountant (OCA) at the SEC where she led the activities of the OCA’s Professional Practices Group.
Transcripts available upon request for individuals who may need a disability-related accommodation. Please send requests to us_podcast@pwc.com.
Did you enjoy this episode? Text us your thoughts and be sure to include the episode name.
Thought leadership from PWC's national office.
SPEAKER_02Hello, and welcome to PWC's Accounting Podcast. I'm Heather Horn. Thanks for joining us today as we jump into current topics in accounting and reporting. For today's discussion, I'm pleased to welcome guest host, Diana Stoltzfitz, a partner in PWC's national office and a podcast regular. I'll hand it over to Diana for more details on today's episode.
SPEAKER_03Today, we're discussing California's Privacy Protection Agency's new cybersecurity audit requirements under the CCPA regulations. This is part of a broader regulatory package of updates that introduce new rules around automated decision-making technology and risk assessments. In this episode, we'll focus on the cybersecurity audit requirement, who may be subject to it, why scoping and auditor independence require careful planning, and how companies may be able to build on the work that they've already completed. Joining me today are Mark Cornish, a partner in PWC's digital assurance and transparency practice, and Chris Santucci, a partner in PWC's cyber data and technology risk practice. Thank you both so much for joining me today.
Overview of the California cybersecurity audit requirements
SPEAKER_03So, Mark, maybe we'll start with you and we'll start with the basics. So, what is the new cyber audit requirement?
SPEAKER_04Thank you, Diana. So this is a new recurring independent audit of a company's cybersecurity program that requires auditor and executive attestation. It's important to understand, though, that this is not a self-assessment. This is something new. It's not simply another privacy policy or consumer notice requirement. It introduces a recurring independent audit of the company's cybersecurity program. The audit report itself must identify relevant gaps or weaknesses, and management should document remediation plans and expected resolution timeframes for any matters arising. A member of executive management must certify completion of the audit to the CPPA, also known as Cal Privacy, under penalty of perjury. Oh wow. Meeting the requirement will require coordination across many functions. I think this is what also that makes this really different, to be honest, at the end of the day, is that it needs coordination across privacy, cybersecurity, legal, internal audit, finance, procurement, technology, and business leadership. So it's really like across the entire organization. So it's a it's a it's a it's not an easy check-the-box exercise here. It's not an easy undertaking. Um so the other aspect to this as well is that many companies are focused on the April 2028 reporting guideline. So that's when there's certification to the CPPA is required up to Cal privacy. But the more important preparation due date is January 1st, because January 1st, 27 is when the first audit period begins.
SPEAKER_03Okay, so companies have to be ready and have these controls. You know, we'll talk more about what it is, but in place throughout that entire period. So really looking more towards January 1, 2027. Correct. Okay,
Which organizations may be subject to the requirements
SPEAKER_03maybe Chris, turning to you now. So what companies are subject to this audit requirement?
SPEAKER_01Yeah, so Article 9 applies to businesses whose personal data processing presents significant risks to consumer security. And that's really defined in two different ways. One, a business derives at least 50% of its annual revenue from selling or sharing consumers' personal information, and that's not limited to revenue in California.
SPEAKER_03Okay, so you're looking at revenue generated. Period.
SPEAKER_01Okay. Yep. And two, a business meets the CCPA's CPI adjusted, so the consumer price index, uh, the revenue threshold. And this was $25 million when it started. It's now above 26. So definitely important for companies to monitor this threshold, especially if they're right on the border. And either processes personal information about 250,000 consumers or households, or processing sensitive personal information of at least 50,000 consumers. And so commonly overlooked areas are marketing data, human resource data, if you're acquiring a business, the data that they may have, uh especially around more and more digital experiences. So think about geolocation data. So non-traditional places where personal data might exist that would bring uh your numbers up and bring you into scope. And so, really, for companies near those thresholds, you can't just give a rough estimate to say you're out of scope. So you really need to do the work, work with finance, your privacy, your data teams to build that defensible view of scoping.
SPEAKER_03Okay. Okay, very helpful. So, Mark, why is this such a bigger lift than other security compliance work?
SPEAKER_04Yeah. No, that's a good question. Um, two two things I would highlight. One, the independence bar has been set high. So, for example, there needs to be real reporting line separation for Intel auditors. I mean, we'll talk about this more as we go through this um podcast here. And the other aspect is the evidence bar. So findings need documentation and support, and testing goes beyond interviews. So essentially it's going to require design and operating effectiveness testing. You know, so it's not just a management assertion process. Like there's full, you know, there's robust testing that needs to be done to support this audit requirement. This discipline will feel more familiar to the organizations accustomed that have, you know, are subject to SOCS as an example, or um, that go through SOC reporting. So, for example, SOC 2 reporting over security controls, or that go through robust intel audit testing, um, compared to those that maybe just go through like privacy questionnaires and other years. So that you know, the the the audit itself is really intended to be a robust audit that really challenges design and operating effectiveness ultimately over that period of time that we talked about earlier. Um, it's the one thing I would also add is it is critical under to understand that Article 9 has its own scope, independence requirements, reporting obligations, and certification requirements. So the organizer organizations need to fully understand those and be prepared for the future audit.
Auditor independence requirements and considerations
SPEAKER_03Okay. You've mentioned independence a couple of times. And when we think about independence, you know, my background is traditionally as an auditor. So you have like SEC independent or audit requirements, and you know, independence can kind of mean different things and different frameworks. So can you maybe speak a little bit about in this context what independence means?
SPEAKER_04Yeah, sure. So within Article 9, the rule lays out the independence requirements within the rule. Um so it, as I mentioned, it can be an independent auditor or an external auditor, but the requirements, the the rule itself actually goes through in details, these are the factors you need to consider. The bar itself, I would say, is actually defined, as I said earlier, it's real it is high. Um, because even if you know, so if we're applying SEC audit requirements, the this actually goes a bit further in certain aspects, believe it or not. So it talks about um the ability to provide recommendations and could that potentially be a conflict for the auditor if they were to do the assessment. So I think there's aspects of that that I think from if I'm kind of guiding organizations, I would say that you know, working with like with the chief legal officer and other parties in the organization to interpret this. But I think the the definition of the auditor for independence is actually a very important aspect of the kind of rule.
SPEAKER_03Yeah, and it's interesting because you're you know, there's like this external auditors that may or may not be able to do certain things, and then internal auditors can be used, but again, you have to have these certain reportings. So it sounds like it is an area to focus on when you're thinking about who's gonna do this and making sure that you meet those requirements.
SPEAKER_04At the end of the day, the the auditor, again, I'd just clarify this, has to be an internal or external party. But a key part of this is they have to be qualified, they have to be objective and they have to be independent in line with those Article 9 requirements. Um so as I said before, the auditor cannot participate in activities that can compromise independence. So that includes you can't develop documents or procedures related to the cyber program, or you can't implement or maintain certain parts of the program, which may seem obvious to many of us, but but the the part of it that's kind of even more restrictive is talks about the auditor can't be making recommendations beyond articulating audit findings. So even like a potential recommendation may create a potential audit conflict.
SPEAKER_03Sounds complicated.
SPEAKER_04Yeah. Yeah.
SPEAKER_03Okay. Well, that was very helpful. Maybe, Chris, turning to you and changing the subject a little bit, why should executive CFOs be focused on this new audit requirement?
SPEAKER_01I think primarily because it's not just a cyber or privacy issue. It's we're really talking about enterprise governance, enterprise risk, and it needs the proper investment. So the finance leaders that are on the podcast today, they understand annual compliance cycles, control testing, evidence levels. These are these are things that are very common today. They understand the discipline, the rigor that's needed. And so the CFO should be asking: are we in scope? What can we leverage? Who's on first for a lot of these activities from an accountability perspective? Do we know that we have big gaps in the requirements? How are we approaching remediation, et cetera? And as well as who's actually going to do the certification and are they properly prepared for that?
Scoping personal data, systems, and third parties
SPEAKER_03Right. And I guess one thing, you know, that we haven't talked in detail about is, you know, what what are the total kinds of like different aspects of the company that this covers, right? We've talked about, you know, that that we, you know, you need to invite lots of parties across the organization and it's not just limited to cybersecurity. So maybe can you give us some idea around like what are some of the complications or challenges that companies are facing as they're thinking about meeting this requirement?
SPEAKER_01Yeah, and this is this is where the work needs to be done, right? Because personal data that's in scope is really across the organization when you think about how today's organizations you know operate, including extending to your to your third parties. So a traditional SOC2 or audit that where the company might be looking to leverage is typically very focused, right? To a specific boundary of systems or processes. When we think about this, it's much broader. So they the first effort here around readiness really requires the organization to take a step back, understand that personal data flow and uh the related systems that support it and third party, and that becomes your initial boundaries. And the the Article 9 requirements also pull in service providers and contractors and vendors, right, directly. So they have an obligation to support your audit as well and provide information. So that's going to be a change uh for many of our clients and how they typically think about audits and how far they go. They're not just asking their employees who manage those relationships, they may actually may need to invoke some audit clause to gather some information to support their control environment.
SPEAKER_03So it's really any system, really, or even third party, as you're saying, that touches this privacy, this customer data that's moving throughout your organization.
SPEAKER_01So as it moves through the organization and different systems and maybe third parties interact, it's really all of that comes into that's where the work needs to be done because if you can tell where the data that's in scope um sits within a system, then great. If you're unsure, then you might have a risk of over-scoping or underscoping. So that's the hard work that needs to be done so that if you do a test and there is a failure, you can actually attribute it to the specific risk.
SPEAKER_04I mean, uh I would just add, I mean, I think from my perspective when talking to clients, I think this is one area that should not be underestimated. I think this is this is challenging and getting a full handle across the organization is not an easy task necessarily. So I think ensuring that you're spending appropriate time going through this exercise and understanding that flow is like really critical to the overall process. I mean, when it comes to the controls aspect of this, when you look at the requirements in the rule, I would say they're generally directionally standard cybersecurity hygiene areas. But the scoping of the systems is the most critical part because then you then you're required to make sure that those controls in place covering all these areas. And historically, maybe we've done similar engagements or reviews in this area, that's where we've seen issues arise where you know there isn't encryption in place on certain systems as an example, or um, they're not able to dispose of certain like customer information easily for certain systems, et cetera. So I think the the scoping piece from the outset is really what drives the extent of how detailed this review is going to be, and it is definitely the most challenging part, I think. I
Leveraging existing audits, assessments, and controls
SPEAKER_04agree.
SPEAKER_03Yeah, and I think you know, it seems like there could be systems maybe, and I think we'll get into this maybe in the next question, is that maybe have been in scope for other reasons. And so you might have a better understanding, and maybe this is bringing in new systems where you haven't done as maybe much historical testing or understanding. Yep. And so maybe playing on that is, you know, as we've talked about, companies may already have SOC 2 reports, NIST-based assessments, SOCS-related testing, maybe ISO. And so can companies leverage these different testings that maybe have been done for other reasons?
SPEAKER_04Um I mean, yes, 100% they can. Like I think the rule actually explicitly talks about that, about leveraging other audits and assessments. So Article 9 allows um for companies to leverage an audit or assessment built for other purposes as long as it meets all the requirements of the rule.
SPEAKER_03And so maybe that gets back to kind of this evidence-based testing, too.
SPEAKER_04Yeah. So if if you're having uh like as an example of SOC 2 cover, that that may cover generally, we're seeing probably 60 to 70 percent of the controls that may be required overall for this cyber audit. But there's also a delta there in terms of systems, because like as an example of SOC 2, not only may only cover 20, 25 systems, but if you've defined 100, 200 systems in a scope for this rule, there's obviously a delta there as well. So, really, what's expected is that um the client organization should should go through an assessment to understand that mapping in terms of what can potentially be leveraged and really what the delta is. And and also the question becomes is like how do you get coverage and get comfortable throughout the calendar year period, which is the requirement or the rule, because not all those reports are going to align with that period as well. So, you know, a NIST giving another example, and this comes up a reasonable about a NIST CSF maturity assessment. Um, many of our clients get those done. Um, we have had some conversations with clients where they're like, oh, we should be good. We have a NIST maturity assessment, and we're like, well, it's a bit more complicated that. Right. Um, you know, I think that's a great starting point to highlight your cyber audit needs. However, our clients really need to go deeper than that and um perform evidence-based audit procedures at a level sufficient to support auditor findings. And that really at the end of the day, what does that mean? That includes like sample testing across the environment of controls to make sure they are designed and operating effectively over that period.
SPEAKER_01So and it's efficiency opportunity as well, right? We're encouraging clients not to start over, given the regulation allows you to leverage this testing, but also don't assume that you have the right coverage if you have a number of these uh reports in place already today. So we're we're encouraging doing that mapping early to identify the testing that's already been done, mapping out the scope, the time periods, all these different items, and then identify where there's gaps where you have to do testing. And even if you find that you can leverage those reports, the auditor might need to supplement. Uh, finance leaders are very aware of using the work of others and the standards that you need to follow. So you might need to supplement some of the existing testing as well. Okay, making sure it meets the requirements of this regulation.
SPEAKER_04I mean, at the end of the day, like every client and organization is different. Um, you know, so that's why this needs to go through a thoughtful process from the outset to really ensure you're defining a scope, identifying leverage leverageability, you know, thinking about you know next steps and how do you address gaps, etc. So it's it's again, I I couldn't we couldn't highlight more, like like this is not an easy undertaking, right? Being prepared for
Steps organizations can take to prepare
SPEAKER_04this.
SPEAKER_03So I guess starting with that, I mean, I think you've given a lot of good advice, but if we think about you know companies maybe wanting to take action soon, now within the next 90 days, maybe starting with you, Chris, what what would you highlight as kind of a first step in starting this process?
SPEAKER_01Yeah, maybe I'll start and then Mark, you can you can add on. I think first, if you're a CFO listening to this or a finance leader, if this is new to you, I would act quickly and ask the questions, given that again, these these regulations were finalized uh last September and came into effect recently here. So first confirm applicability and document the basis for all your conclusions. Second, establish the right governance and accountability structure. So think privacy, cyber, legal, IT, internal audit, et cetera. All the impacted parties, get them on board with the scope and the effort and making sure that everybody's accountable. Third, really make sure, as we've been talking about today, define the scope, right? Where is the data that's that's applicable to CCPA article nine, right? Where is that information being processed? And don't forget about your vendors and third parties. And then you're really setting that boundary for everything to come in your audit program.
SPEAKER_04Mark. Yeah, I would say that the next stage after that is um to perform some form of readiness assessment, including evidence review. Again, we keep talking about evidence, evidence, evidence is important. If you can't prove it, you know, if there's no supported. It's not supported exactly. So um organizations should be going through a mapping of current controls um to the Article 9 requirements. I think that's the first stage after the scoping exercise. And then really going through a process to identify gaps and obviously then assuming there are gaps, which most likely will occur across most of these reviews, we suspect, um, is then determine what are the remediation plans that need to be in place to address those gaps. You know, ideally trying to remediate prior to the start of the audit period. Um the one other thing I would say though is the organization should also decide early who's actually going to perform the audit. So who's going to perform the audit for that calendar year 27? Um, independence questions can affect both readiness support and the eventual assurance model that you adopt. So that really shouldn't be deferred. I mean, I think there's various ways that an organization can approach this, whether it's using Intel audit or external audit, but I really think that's something you should organizations really should be thinking about now and shouldn't leave that to a 27 question.
SPEAKER_01Right. Especially given the volume of organizations that are going to fall into the first wave trying to get ahead, especially if you want to go external or need internal support. There's going to be a race to find the right provider for you. And Mark, one more thing to add. Also preparing the executive who will certify. And that might be a different role within different organizations. But that person definitely needs a governance process that provides timely visibility into the scope, findings, remediation efforts, and auditor independence, not just a package deliverable at the last second.
SPEAKER_03Okay. Maybe, Chris, anything from the privacy program side that you'd want to add?
SPEAKER_01I think it's a primary, it's a collaboration between all the different stakeholders that we mentioned earlier, right? And when we talk about identifying the boundaries of personal data, there's nobody better than the privacy team to understand that they've been data flow mapping for years for different regulations globally. They should they should be your first stop. Um second, I'd say make sure to involve the service providers early. Have conversations. Do you have the right to audit? Are they aware of these requirements and the timelines so that you know you're not asking those questions, you know, late in the audit period or even after the audit period?
SPEAKER_03Okay. I think that's a great point. Well, as we wrap up our conversation here, maybe any last thoughts? I'll turn Mark first to you.
SPEAKER_04Sure. Yeah. So I think three things that I would kind of highlight here. First of all, organizations should be treating this like a new regulatory audit requirement. I mean, essentially that's what it is. And it might sound obvious, but treat it like with importance. Early scoping and, you know, performing assessments around this, getting prepared for the rule can save a significant amount of time and pain later. So I think that's point number one that I would highlight. Number two, do not reinvent the wheel for this, you know, and leverage existing reporting that you have across the organization. So we touched upon that earlier. Um, but SOC 2 reporting, ISO certifications, NISPATUTE assessments, let leverage information you have in place for your existing programs as much as possible because that helps drive efficiency. And I'll also help um identify potential gaps more timely as well from the outset. And the third thing I would say is this is not hypothetical. An independent audit will surface gaps. Gaps will be identified, observations will be made, and it is possible that a regulator could request results, you know, from these reviews that are getting done. So preparation around this is really critical, um, from my view. I mean, Chris, what what else do you think from your perspective?
SPEAKER_01Yeah, I think historically, when we talk about audits that have been required by regulatory bodies, it's after an incident or after a complaint or investigation where the regulator, whether it's federal, state, or otherwise, steps in and mandates it. Now this is a shift. We're seeing a requirement for proactive compliance, right? Being able to demonstrate that you have a program that operates over time and there's evidence to support it. That's a shift for many of our clients, especially with the broad scope that we talked about before. And then second, I'd say this is this is just the beginning. California specifically has already explored extending independent audit concepts to other areas and other requirements. Most recently, the data brokers processing requests through the delete request and opt-out platform, the drop platform. So, again, if you think about demonstrating the accountability of your programs, needing to prove that you have those controls in place is just going to continue and expand into other areas. So companies that build integrated governance, reliable evidence, and a repeatable compliance model now will not just be ready for Article 9. It will be better prepared for where privacy and cyber regulation is going in the future.
SPEAKER_03Okay. Well, that's really helpful. Well, I think obviously very important for uh companies to understand that the filing date's going to be in 2028. The reporting period will start on January 1, 2027. So coming up soon. And so the time to get ready is now. So thank you both so much for joining me today.
SPEAKER_01Thank you.
SPEAKER_02That's our show for today. Tune in next week for more fresh episodes so that you never miss any of our audio content. Follow the PWC Accounting Podcast wherever you listen to your podcasts. And to stay up to date on all our latest accounting and reporting news, sign up for our newsletter at viewpoint.pwc.com. From Thought Leadership at PwC, I'm Heather Horn. Thanks for tuning in.
SPEAKER_00This podcast is brought to you by PwC, All Rights Reserved. PWC refers to the U.S. member firm or one of its subsidiaries or affiliates, and they sometimes refer to the PwC network. Each member firm is a separate legal entity. Please see www.pwc.com slash structure for further details. This podcast is for general information purposes only and should not be used as a substitute for consultation with professional advisors, including accountants and lawyers.
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.