CCPA Assessments

4.9
Based on 100+ G2 reviews

California's privacy law. Navigate it with confidence.

The CCPA gives California consumers sweeping rights over their personal data — and imposes serious obligations on the businesses that collect it. With the CPPA's new regulations now in effect, the bar for demonstrating compliance is higher than ever. Johanson Group assesses your program against every requirement.

Market leaders choose Johanson Group:

Experienced Practitioners

Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.

Platform Experts

Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.

Integrated Audits

Your CSM and audit project lead guide the engagement from kickoff to final report — one seamless experience.

Expert Network

Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.

CCPA Services

CCPA compliance assessed thoroughly, documented defensibly.

Johanson Group conducts a single, comprehensive CCPA Assessment covering your full compliance posture against CCPA — including the 2025 regulatory updates. Every engagement is scoped to your specific situation before work begins.

Additional Services

SOC & ATTESTATION

SOC 2

Audit Timeline: 4-8 weeks*

The standard trust report for technology companies. Demonstrates that your security, availability, and data handling controls meet rigorous AICPA standards.

For: SaaS, cloud, and software companies selling to enterprise buyers

ISO Standards

ISO 27001

The internationally recognized information security management standard. Required by enterprise and government buyers globally — and a strong differentiator in competitive deals.

For: Companies operating globally or selling into regulated international markets

Government & Industry

PCI DSS

Audit Timeline: 4-8 weeks*

The mandatory security standard for any organization that processes, stores, or impacts the security of cardholder data. Non-compliance puts your payment processing, and customer trust, at risk.

For: Fintech, e-commerce, payments platforms, and retailers

Customer Success Stories

Cryptocurrency Exchange

Bitkub Exchange Becomes Thailand's First Digital Asset Exchange to Achieve SOC 2 Type II

Thailand's leading digital asset exchange became the country's first to earn SOC 2 Type II — validating security across all five Trust Services Criteria.

6 weeks
Biotech Company

Scisco Genetics Secures Data with SOC 2 Compliance

Seattle-based Scisco Genetics Inc. is a leader in genetic analysis, offering fast and accurate high resolution genotyping of complex immune regions.

4.9
Based on 100+ G2 reviews

Don't just take our word for it.

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

Frequently asked questions

Your answer not here? Feel free to contact us for more information.

The CCPA (California Consumer Privacy Act) was the original law, effective January 1, 2020. The CPRA (California Privacy Rights Act), passed by voters in November 2020, significantly expanded the CCPA — adding new consumer rights (right to correct, right to limit sensitive PI), creating the California Privacy Protection Agency (CPPA) to enforce the law, establishing employee data protections, strengthening opt-out requirements, and introducing new rulemaking authority. Most CPRA provisions took effect January 1, 2023. Today, "CCPA compliance" refers to compliance with the CCPA as amended and expanded by the CPRA.

Yes, if you do business in California — which generally means you collect personal information from California residents, including through a website accessible to Californians. Many companies based in Texas, New York, or outside the US entirely are subject to CCPA because they sell to California residents. The revenue threshold ($26.625M as of 2025) applies to global annual gross revenue, not just California revenue. If you're unsure whether CCPA applies, our coverage determination service can give you a definitive answer quickly.

Businesses must respond to verifiable consumer requests within 45 days of receipt. If reasonably necessary, you can extend this by an additional 45 days (90 days total), but you must notify the consumer of the extension within the initial 45-day period. Businesses must also maintain documentation of all consumer requests and their responses for 24 months. Setting up robust workflows, verification procedures, and tracking systems before requests arrive is essential — the timelines are strict and the documentation requirement is easily overlooked.

A service provider is an entity that processes personal information on behalf of a business under a written contract — and that contract must include specific CCPA provisions. Required terms include: processing personal information only for the specified business purpose; prohibiting selling or sharing the personal information; requiring the service provider to assist with consumer rights requests; and imposing the same restrictions on any sub-processors. If your vendor agreements don't include these terms, you remain liable for how that vendor uses the personal information you've shared with them. Service provider agreement review is one of the most common findings in our CCPA assessments.

Dark patterns are user interface design choices that make it difficult for consumers to exercise their privacy rights — for example, burying the "Do Not Sell" link in small text, requiring multiple clicks to opt out while allowing one click to opt in, or using confusing language that misleads consumers about the effect of their choice. The CPPA explicitly prohibits dark patterns and has made enforcement of UI design choices a priority. Our privacy notice reviews specifically check for dark patterns that could trigger CPPA regulatory action, including consent mechanisms, cookie banners, and opt-out flows.

CCPA and GDPR share many common elements — both require transparency, data subject rights, and documented legal bases for processing — but they differ in important ways. GDPR requires a legal basis for every processing activity; CCPA focuses primarily on disclosure and opt-out rights. GDPR's consent requirements are stricter; CCPA gives consumers an opt-out right rather than requiring opt-in consent for most processing. Both have breach notification requirements. Johanson Group designs combined CCPA + GDPR programs that satisfy both simultaneously — sharing documentation, data mapping, and control structures across both frameworks to reduce total compliance cost significantly.