California Consumer Privacy Act (CCPA) cybersecurity audit and risk assessment requirements in effect and Ecommerce Businesses Need to Pay Attention Today

California’s New Cybersecurity Audit Mandate: Why Ecommerce Businesses Need to Pay Attention Today

Ecommerce Innovation Alliance

April 16, 2026

If your ecommerce business processes significant volumes of consumer data in California, a new regulation now on the books may soon require you to conduct — and formally certify — an annual cybersecurity audit. The requirement, finalized under the California Consumer Privacy Act (CCPA) and approved by the California Office of Administrative Law in September 2025, took effect on January 1, 2026, and represents one of the most prescriptive cybersecurity accountability measures any U.S. state has imposed to date.…

READ FULL POST