CCPA Assessments
California's privacy law. Navigate it with confidence.
The CCPA gives California consumers sweeping rights over their personal data — and imposes serious obligations on the businesses that collect it. With the CPPA's new regulations now in effect, the bar for demonstrating compliance is higher than ever. Johanson Group assesses your program against every requirement.
Market leaders choose Johanson Group:
























Experienced Practitioners
Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.
Platform Experts
Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.
Integrated Audits
Your CSM and audit project lead guide the engagement from kickoff to final report — one seamless experience.
Expert Network
Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.
CCPA Services
CCPA compliance assessed thoroughly, documented defensibly.
Johanson Group conducts a single, comprehensive CCPA Assessment covering your full compliance posture against CCPA — including the 2025 regulatory updates. Every engagement is scoped to your specific situation before work begins.
CCPA Assessment
A comprehensive assessment of your organization's data practices, consumer rights programs, vendor agreements, and privacy notices against the full CCPA requirement set — including the 2025 CPPA regulatory updates covering cybersecurity audits, privacy risk assessments, and ADMT governance. Delivered as a prioritized findings report with a clear remediation roadmap and documentation suitable for CPPA attestation requirements.
- Coverage determination — confirms whether CCPA applies based on revenue, data volume, and business model thresholds
- Data inventory and mapping — identifies all California consumer personal information collected, used, disclosed, and sold or shared
- Consumer rights program review — right to know, delete, correct, opt-out, and limit sensitive PI with 45-day response window compliance
- Privacy notice and opt-out mechanism review — assessed against CCPA transparency requirements and CPPA dark patterns prohibitions
- Service provider and vendor agreement review — confirms all required CCPA contractual provisions are present and compliant
Additional Services
SOC 2
The standard trust report for technology companies. Demonstrates that your security, availability, and data handling controls meet rigorous AICPA standards.
For: SaaS, cloud, and software companies selling to enterprise buyers
ISO 27001
The internationally recognized information security management standard. Required by enterprise and government buyers globally — and a strong differentiator in competitive deals.
For: Companies operating globally or selling into regulated international markets
PCI DSS
The mandatory security standard for any organization that processes, stores, or impacts the security of cardholder data. Non-compliance puts your payment processing, and customer trust, at risk.
For: Fintech, e-commerce, payments platforms, and retailers
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
Frequently asked questions
Your answer not here? Feel free to contact us for more information.
The CCPA (California Consumer Privacy Act) was the original law, effective January 1, 2020. The CPRA (California Privacy Rights Act), passed by voters in November 2020, significantly expanded the CCPA — adding new consumer rights (right to correct, right to limit sensitive PI), creating the California Privacy Protection Agency (CPPA) to enforce the law, establishing employee data protections, strengthening opt-out requirements, and introducing new rulemaking authority. Most CPRA provisions took effect January 1, 2023. Today, "CCPA compliance" refers to compliance with the CCPA as amended and expanded by the CPRA.
Yes, if you do business in California — which generally means you collect personal information from California residents, including through a website accessible to Californians. Many companies based in Texas, New York, or outside the US entirely are subject to CCPA because they sell to California residents. The revenue threshold ($26.625M as of 2025) applies to global annual gross revenue, not just California revenue. If you're unsure whether CCPA applies, our coverage determination service can give you a definitive answer quickly.
Businesses must respond to verifiable consumer requests within 45 days of receipt. If reasonably necessary, you can extend this by an additional 45 days (90 days total), but you must notify the consumer of the extension within the initial 45-day period. Businesses must also maintain documentation of all consumer requests and their responses for 24 months. Setting up robust workflows, verification procedures, and tracking systems before requests arrive is essential — the timelines are strict and the documentation requirement is easily overlooked.
A service provider is an entity that processes personal information on behalf of a business under a written contract — and that contract must include specific CCPA provisions. Required terms include: processing personal information only for the specified business purpose; prohibiting selling or sharing the personal information; requiring the service provider to assist with consumer rights requests; and imposing the same restrictions on any sub-processors. If your vendor agreements don't include these terms, you remain liable for how that vendor uses the personal information you've shared with them. Service provider agreement review is one of the most common findings in our CCPA assessments.
Dark patterns are user interface design choices that make it difficult for consumers to exercise their privacy rights — for example, burying the "Do Not Sell" link in small text, requiring multiple clicks to opt out while allowing one click to opt in, or using confusing language that misleads consumers about the effect of their choice. The CPPA explicitly prohibits dark patterns and has made enforcement of UI design choices a priority. Our privacy notice reviews specifically check for dark patterns that could trigger CPPA regulatory action, including consent mechanisms, cookie banners, and opt-out flows.
CCPA and GDPR share many common elements — both require transparency, data subject rights, and documented legal bases for processing — but they differ in important ways. GDPR requires a legal basis for every processing activity; CCPA focuses primarily on disclosure and opt-out rights. GDPR's consent requirements are stricter; CCPA gives consumers an opt-out right rather than requiring opt-in consent for most processing. Both have breach notification requirements. Johanson Group designs combined CCPA + GDPR programs that satisfy both simultaneously — sharing documentation, data mapping, and control structures across both frameworks to reduce total compliance cost significantly.



.png)
.jpg)
.avif)

