Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Audits And Risk Assessments topic

No spam. Unsubscribe anytime.

Businesses urge CPPA to narrow cybersecurity audit and risk‑assessment rules; some call for affirmative defense for compliance

2669665 · March 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

At Feb. 19 CPPA public hearing, industry groups said draft cybersecurity‑audit and risk‑assessment rules duplicate existing frameworks and impose undue costs; some asked that compliance with final audits serve as an affirmative defense to liability

SACRAMENTO, Feb. 19, 2025 — Commenters at the California Privacy Protection Agency's Feb. 19 public hearing criticized proposed cybersecurity audit and risk‑assessment regulations as overly prescriptive, duplicative of existing standards and costly to implement, with several business groups asking the CPPA to narrow scope or defer to established frameworks.

Why it matters: The cybersecurity audit and risk‑assessment proposals would set new disclosure and audit obligations for entities covered by California privacy law. Industry witnesses said the requirements could force firms to divert resources from threat mitigation to compliance and could expose sensitive business details.

Industry testimony and requests

Willie Martinez, representing the State Privacy and Security Coalition, said the proposed cyberaudit rules "disregard widely accepted frameworks such as NIST" and criticized a requirement under section 7123(b) that would force justification for many security controls. Martinez urged that businesses complying with final cybersecurity audit requirements be "deemed to have met the reasonable standard of care," and recommended the agency explicitly allow compliance to serve as an affirmative defense against private‑right claims under the CCPA.

Lucy Chinchesian of the Civil Justice Association of California argued the audit and reporting requirements could expose sensitive information and that annual risk assessments for low‑risk activities would be excessive. Multiple commenters warned auditors' reporting frequency and content could create security or competitive risks if not narrowly tailored.

Concerns about cost and timing

Commenters pointed to the CPPA's impact assessment and independent analyses asserting multi‑billion dollar statewide costs and substantial annualized burdens on businesses. BIOCOM California and other life‑science commenters asked the agency to avoid duplicating federal or sectoral cybersecurity requirements and to limit audit scope to genuine privacy risks.

Agency process and next steps

Agency staff reiterated that all comments will be part of the rulemaking record under the Administrative Procedures Act and that the CPPA may amend proposed text in response. Several industry groups asked for extended implementation timelines and clearer alignment with recognized frameworks such as NIST to reduce duplication.

Ending: No formal action was taken at the hearing; the CPPA will review submitted comments and may revise the draft regulations before any final rule adoption.