Scrutineer.ai

Scrutineer · By framework

CCPA compliance software for CPRA audits and risk assessments

The CPRA regulations effective January 1, 2026 turned California privacy into an evidence exercise. Covered businesses now owe a cybersecurity audit, documented risk assessments and an annual filing.

Scrutineer maps the controls you already run to those obligations and keeps the evidence current, so the audit is a review rather than a rebuild.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with CCPA

The 2026 obligations, scoped

The cybersecurity audit, the risk assessments and the ADMT rules each have their own scope test and their own deadline. Scrutineer works out which ones apply to you from your revenue and processing volumes, so you are not preparing for a filing you do not owe.

Audit evidence that is already there

The regulations expect an audit performed against accepted audit standards. Read-only connections to your cloud, identity and ticketing systems keep the underlying control evidence current, so the auditor validates facts instead of waiting on screenshots.

One control set, every state law

Twenty states now have comprehensive privacy laws in force. Most of the operational work, data inventory, deletion and opt-out handling, vendor contracts, is shared. Scrutineer maps a control once and shows every regime it satisfies.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Tests whether the CCPA revenue and processing thresholds apply to you
  • Scopes the CPRA cybersecurity audit and your April 1 deadline tier
  • Tracks the risk assessments the regulations require, and what triggers each one
  • Maps existing SOC 2 and ISO 27001 controls onto CCPA obligations
  • Keeps evidence for opt-out handling, deletion and vendor contract terms
  • Shows where California obligations overlap the other 19 state privacy laws
CCPA readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Obligation reference

The CPRA 2026 obligations and when each one is due

The regulations took effect on January 1, 2026, but the filings are phased out over several years. The gap matters: the audit and assessment periods run before the dates below, so the evidence has to exist first.

Obligation Who is in scope Reported deadline What you produce
Cybersecurity audit Businesses deriving 50 percent or more of revenue from selling or sharing personal information, or over the revenue threshold and processing personal information of 250,000+ consumers or households, or sensitive personal information of 50,000+ consumers. April 1, 2028 above $100M revenue. April 1, 2029 for $50M to $100M. April 1, 2030 below $50M. An annual audit by an audit professional using accepted audit standards, with a certification of completion.
Risk assessments Businesses whose processing presents significant risk: selling or sharing personal information, processing sensitive personal information, using ADMT for significant decisions, or automated inference in sensitive contexts. December 31, 2027 for activities that began before January 1, 2026 and continue. Before processing begins for anything newer. A documented assessment per activity, retained, plus an annual summary filed with the CPPA from April 1, 2028.
ADMT rules Businesses using automated decision-making technology for significant decisions about financial or lending services, housing, education, employment or compensation, or healthcare. January 1, 2027 for systems already deployed. Before first use for anything new. Pre-use notice, a working opt-out, an explanation on request, and an appeal path with human review.
Consumer rights and contracts Every covered business, with no phase-in. In force now. Evidence that opt-out, deletion and correction requests were honored, and required terms in service provider and third-party contracts.
Readiness work behind all four Every covered business, before any filing is due. Continuous. This is where Scrutineer sits. Mapped controls, current evidence, and a clear view of which obligations and which deadline tier apply to you.

Scope tests and deadlines are as reported by privacy counsel summarizing the CPPA regulations effective January 1, 2026; confirm your own scope and dates with counsel. The revenue threshold of $26,625,000, the $2,663 and $7,988 penalty caps and the $107 to $799 consumer damages range come from the California Privacy Protection Agency announcement effective January 1, 2025, and are adjusted every odd-numbered January. Scrutineer prepares and maintains the control evidence behind these obligations. It does not perform the cybersecurity audit, which the regulations require an independent audit professional to conduct.

Good questions

Questions about CCPA

CCPA compliance means meeting the California Consumer Privacy Act as amended by the California Privacy Rights Act: honoring consumer rights to know, delete, correct and opt out of the sale or sharing of personal information, limiting use of sensitive personal information, putting required terms in contracts with service providers and third parties, and, since January 1, 2026, completing risk assessments and a cybersecurity audit if your processing meets the scope tests.
A for-profit business that does business in California and meets any one of three tests. Annual gross revenue above $26,625,000, the inflation-adjusted figure the California Privacy Protection Agency set effective January 1, 2025. Or buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year. Or deriving 50 percent or more of annual revenue from selling or sharing personal information. Meeting one test is enough.
Three, all from regulations effective January 1, 2026. Businesses whose processing presents significant risk must complete documented risk assessments. A narrower group must complete an annual cybersecurity audit. And businesses using automated decision-making technology for significant decisions owe pre-use notice, an opt-out, an explanation on request, and human appeal. The obligations start now; the first filings are dated later.
An annual audit, performed by an audit professional using audit-industry-accepted procedures and standards, of the safeguards protecting personal information. It applies to businesses that derive at least 50 percent of revenue from selling or sharing personal information, or that meet the revenue threshold and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers, in the prior year.
The regulations phase the first audit by company size. Businesses with more than $100 million in annual gross revenue are reported to owe theirs by April 1, 2028. Businesses between $50 million and $100 million by April 1, 2029, and businesses under $50 million by April 1, 2030. The audit covers the period before that date, so the control evidence has to exist well ahead of the filing.
For processing activities that began before January 1, 2026 and continue afterward, the initial risk assessments are reported due by December 31, 2027. The first annual summary submission to the California Privacy Protection Agency is reported due April 1, 2028. Activities started after January 1, 2026 need an assessment before the processing begins, not afterward.
Up to $2,663 for each violation and up to $7,988 for each intentional violation or one involving a consumer under 16, the amounts the CPPA set effective January 1, 2025 and adjusts every odd-numbered January. Consumers can also recover $107 to $799 per consumer per incident for certain breaches. Enforcement is real: California announced a $12.75 million settlement with General Motors in May 2026, the largest to date.
The GDPR requires a lawful basis before you process personal data at all, and applies to organizations of any size. The CCPA assumes processing is permitted and gives consumers rights to opt out after the fact, and only applies above the revenue and volume thresholds. The GDPR covers employee data comprehensively; California brought employee and B2B data into scope in 2023. If you already run a GDPR program, most of the CCPA work is mapping, not building.
No. No regulator issues a CCPA or CPRA certificate, and any badge claiming otherwise is marketing rather than an attestation. What the law does require of some businesses is an independent cybersecurity audit and documented risk assessments, which are filings and working papers rather than a certificate you display.
The recurring line items are outside counsel or a privacy lead, a consent and opt-out mechanism, data inventory tooling, and, for businesses in scope, the annual cybersecurity audit. The audit is the new variable and prices like any independent assurance engagement. The larger cost is almost always internal: finding where personal information actually sits and proving deletion and opt-out requests were honored end to end.
Probably, if you have California customers. The CCPA applies to a business that does business in California and meets a threshold, regardless of where it is headquartered. There is no physical presence requirement. A software company in Texas selling to Californians is covered on exactly the same terms as one in San Francisco.
No. Compliance is a legal conclusion about your business, and the cybersecurity audit has to be performed by an independent audit professional. Scrutineer is readiness and decision-support: it maps your controls to the CCPA and CPRA obligations, works out which deadline tier you fall into, and keeps the evidence current so the audit and the risk assessments are faster to complete.

Keep reading

Guides that go deeper on privacy and the audits behind it

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification