California’s new cybersecurity audit requirements under the CCPA are approaching, and companies that collect or process California residents’ personal information should be preparing now. Covington has been helping clients navigate these requirements in real time and has developed practical readiness materials, scoping frameworks, and benchmarking insights that companies can leverage when doing so. In this alert, we outline the new requirements, explain which companies may be in scope, identify key timing considerations, and highlight practical steps companies can take now to be audit-ready by January 1, 2027.
Click here to read the full alert on cov.com.