New cybersecurity audit requirements under the California Consumer Privacy Act (CCPA) establish a recurring, independent assessment of certain organizations’ cybersecurity programs, with the first audit period beginning January 1, 2027. We discuss which organizations may be subject to the requirements, key considerations on audit scope and independence, and how existing cybersecurity, risk, and assurance activities can support readiness.
For more on California’s cybersecurity audit requirements, see our publication Privacy becomes a cybersecurity imperative under California’s audit rule.
Follow this podcast on your favorite podcast app and subscribe to our weekly newsletter to stay informed.
About our guests
Mark Cornish is a partner at PwC who provides assurance and consulting services to global and regional clients within the financial services industry. He is recognized for his experience in complex third-party assurance reporting, internal controls, and risk and compliance matters. His areas of expertise include internal control over financial reporting, SOC 1 and SOC 2 reporting, cybersecurity risk management, privacy, and regulatory compliance.
Chris Santucci is a partner in PwC’s Cyber, Data & Technology Risk practice who helps global companies across sectors build, operate, and assess data privacy and protection programs through technology-enabled solutions. His expertise spans global privacy program design and regulatory preparedness (including CCPA, GDPR, etc.), data discovery and risk analysis, program assessment and implementation, privacy impact assessments, third-party risk management, as well as sustainable risk and compliance services.
About our guest host
Diana Stoltzfus is a partner in PwC’s National Office who helps to shape PwC’s perspectives on regulatory matters, responses to rulemakings and policy development, and implementation related to significant new rules and regulations. She is also one of the firm’s technical experts on sustainability reporting. Prior to rejoining PwC, Diana was the Deputy Chief Accountant in the Office of the Chief Accountant (OCA) at the SEC where she led the activities of the OCA’s Professional Practices Group.
Transcripts available upon request for individuals who may need a disability-related accommodation. Please send requests to us_podcast@pwc.com.
Did you enjoy this episode? Text us your thoughts and be sure to include the episode name.