Skip to content

CCPA / CPRA: ADMT, risk assessment and cybersecurity audit regulations approved

Tech · Compliance deadlines · Mon, September 22, 2025 · California · US

Source

OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State. Not legal advice.

Every year

DateEventWhen
Jan 1, 2020CCPA / CPRA: CCPA takes effect7 yr ago
Jan 1, 2023CCPA / CPRA: CPRA amendments operative4 yr ago
Jan 1, 2025CCPA / CPRA: CPI adjustment of thresholds and fines2 yr ago
Sep 22, 2025CCPA / CPRA: ADMT, risk assessment and cybersecurity audit regulations approved12 mo ago
Jan 1, 2026CCPA / CPRA: New CCPA regulations take effect9 mo ago
Jan 1, 2027CCPA / CPRA: ADMT requirements compliance datein 3 mo
Jan 1, 2027CCPA / CPRA: Browsers must support opt-out preference signal (AB 566)in 3 mo
Dec 31, 2027CCPA / CPRA: Risk assessments for pre-existing processing duein 15 mo
Apr 1, 2028CCPA / CPRA: First risk assessment submission to CPPAin 2 yr
Apr 1, 2028CCPA / CPRA: Cybersecurity audit due: revenue over $100Min 2 yr
Apr 1, 2029CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100Min 3 yr
Apr 1, 2030CCPA / CPRA: Cybersecurity audit due: revenue under $50Min 4 yr

Also on Sep 22, 2025

DateEventWhen
Sep 22, 2025Sharad Navaratri12 mo ago
Sep 22, 2025September equinox12 mo ago
Sep 22, 2025Mabon12 mo ago
Sep 22, 202550th anniversary: Sara Jane Moore attempted to assassinate U.S. president Gerald Ford, but failed...12 mo ago
Source, method and history
Source
Regulations
How we know
From the Regulations API (regulations.fru.dev), which cites the official text.
Recurs
one-off
More on fru.dev
regulations.fru.dev
Feed
Subscribe to Compliance deadlines
Changes
  • 2026-09-25: added to 2025-09-22

Calendar by email

Sunday mornings: a look ahead at the week’s major dates, only when there are some.

Double opt-in. Unsubscribe any time.