
CPRA Regulations: The 2026 CCPA Rules and What They Require
The CPRA regulations took effect January 1, 2026, adding cybersecurity audits, risk assessments, and ADMT duties. What each one requires, and the deadlines.
Frameworks
Management Systems
Privacy
Security Testing
Plus CCPA, ISO 27701, regional privacy laws, GRC advisory, and compliance training.
California’s Consumer Privacy Act (CCPA) and its 2023 amendment (CPRA) apply to for-profit businesses meeting any one of three thresholds: annual gross revenue over $25 million, buying or selling the personal data of 100,000 or more California consumers or households, or deriving 50% or more of revenue from selling personal data. If you serve California users at scale and have web analytics, ad tracking, or a data broker relationship, you are likely in scope.
CCPA gives California consumers the right to know what data is collected, the right to delete it, the right to opt out of its “sale or sharing,” and the right to non-discrimination for exercising those rights. CPRA added sensitive personal information as a protected category, created a right to correct inaccurate data, and established the California Privacy Protection Agency (CPPA) as a dedicated enforcement body. Unlike GDPR, CCPA is opt-out by default — not opt-in.
The brief below covers the requirements and what CCPA compliance looks like in practice for SaaS. If you’re ready to assess your exposure, visit the CCPA service page.
No deck. No sales pitch. We scope the programme, give you the gap analysis, and you decide if there’s a fit.

The CPRA regulations took effect January 1, 2026, adding cybersecurity audits, risk assessments, and ADMT duties. What each one requires, and the deadlines.



If one of these briefs reflects where you are right now, we run scoping calls without a deck. Book a scoping call.