Scrutineer · By framework
CCPA compliance software for CPRA audits and risk assessments
The CPRA regulations effective January 1, 2026 turned California privacy into an evidence exercise. Covered businesses now owe a cybersecurity audit, documented risk assessments and an annual filing.
Scrutineer maps the controls you already run to those obligations and keeps the evidence current, so the audit is a review rather than a rebuild.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with CCPA
The 2026 obligations, scoped
The cybersecurity audit, the risk assessments and the ADMT rules each have their own scope test and their own deadline. Scrutineer works out which ones apply to you from your revenue and processing volumes, so you are not preparing for a filing you do not owe.
Audit evidence that is already there
The regulations expect an audit performed against accepted audit standards. Read-only connections to your cloud, identity and ticketing systems keep the underlying control evidence current, so the auditor validates facts instead of waiting on screenshots.
One control set, every state law
Twenty states now have comprehensive privacy laws in force. Most of the operational work, data inventory, deletion and opt-out handling, vendor contracts, is shared. Scrutineer maps a control once and shows every regime it satisfies.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Tests whether the CCPA revenue and processing thresholds apply to you
- Scopes the CPRA cybersecurity audit and your April 1 deadline tier
- Tracks the risk assessments the regulations require, and what triggers each one
- Maps existing SOC 2 and ISO 27001 controls onto CCPA obligations
- Keeps evidence for opt-out handling, deletion and vendor contract terms
- Shows where California obligations overlap the other 19 state privacy laws
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Obligation reference
The CPRA 2026 obligations and when each one is due
The regulations took effect on January 1, 2026, but the filings are phased out over several years. The gap matters: the audit and assessment periods run before the dates below, so the evidence has to exist first.
| Obligation | Who is in scope | Reported deadline | What you produce |
|---|---|---|---|
| Cybersecurity audit | Businesses deriving 50 percent or more of revenue from selling or sharing personal information, or over the revenue threshold and processing personal information of 250,000+ consumers or households, or sensitive personal information of 50,000+ consumers. | April 1, 2028 above $100M revenue. April 1, 2029 for $50M to $100M. April 1, 2030 below $50M. | An annual audit by an audit professional using accepted audit standards, with a certification of completion. |
| Risk assessments | Businesses whose processing presents significant risk: selling or sharing personal information, processing sensitive personal information, using ADMT for significant decisions, or automated inference in sensitive contexts. | December 31, 2027 for activities that began before January 1, 2026 and continue. Before processing begins for anything newer. | A documented assessment per activity, retained, plus an annual summary filed with the CPPA from April 1, 2028. |
| ADMT rules | Businesses using automated decision-making technology for significant decisions about financial or lending services, housing, education, employment or compensation, or healthcare. | January 1, 2027 for systems already deployed. Before first use for anything new. | Pre-use notice, a working opt-out, an explanation on request, and an appeal path with human review. |
| Consumer rights and contracts | Every covered business, with no phase-in. | In force now. | Evidence that opt-out, deletion and correction requests were honored, and required terms in service provider and third-party contracts. |
| Readiness work behind all four | Every covered business, before any filing is due. | Continuous. This is where Scrutineer sits. | Mapped controls, current evidence, and a clear view of which obligations and which deadline tier apply to you. |
Scope tests and deadlines are as reported by privacy counsel summarizing the CPPA regulations effective January 1, 2026; confirm your own scope and dates with counsel. The revenue threshold of $26,625,000, the $2,663 and $7,988 penalty caps and the $107 to $799 consumer damages range come from the California Privacy Protection Agency announcement effective January 1, 2025, and are adjusted every odd-numbered January. Scrutineer prepares and maintains the control evidence behind these obligations. It does not perform the cybersecurity audit, which the regulations require an independent audit professional to conduct.
Good questions
Questions about CCPA
Keep reading
Guides that go deeper on privacy and the audits behind it
The GDPR checklist for US companies
The other privacy regime most US SaaS companies carry, and where its data inventory and vendor work overlaps California.
Read the guideRunning a cybersecurity risk assessment
The NIST SP 800-30 method in eight steps, which is the practical backbone of the risk assessments the CPRA regulations now require.
Read the guideWhat SOC 2 compliance actually is
The attestation most of these controls were already built for, and the evidence you can reuse against California obligations.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification