In the prior Part 4 of this series, we explained how CCPA cybersecurity audits are likely to surface in CalPrivacy and California Attorney General enforcement actions, and how that regime impacts governance and executive responsibility.
Part 5 of this series focuses on how CCPA cybersecurity audits may be used in civil litigation, and walks through what that means for legal, security, and boards and executives. We focus on four core questions:
- Why do these audits matter beyond the CCPA’s private right of action? The reasonableness of a company’s information security program is often a central issue in data breach and privacy litigation. The new CCPA cybersecurity audit requirement creates a documented benchmark that courts may use to evaluate that reasonableness — not just under the CCPA, but in connection with negligence and consumer protection claims as well.
- How will CCPA cybersecurity audits show up in civil litigation? Audits will move from internal compliance paperwork to frontline evidence in data breach and privacy class actions. Plaintiffs’ counsel will attempt to use audit records to argue what the company knew, when it knew it, and how it responded (or failed to respond) to identified gaps, attempting to build a roadmap establishing an unreasonable information security program.
- What happens if audits are mishandled? If not structured carefully, CCPA audits risk exposing known critical vulnerabilities, repeat findings over extended periods of time, and “dangerous language” (e.g., “systemic failures” and “grossly inadequate”) that reads very differently in a complaint than it does in an internal report. Companies need to approach these audits with the understanding that they may later be used against them in litigation.
- How should privilege, work product, and governance be structured? We lay out a practical playbook: counsel-directed audits versus routine compliance reviews; separating privileged legal risk analyses from discoverable operational summaries; routing drafts and findings through counsel; and aligning board reporting, executive certifications, and public statements with what the audits actually show.
I. Executive Overview: Why CCPA Audits Matter for Litigation
The new CCPA cybersecurity audit requirement will generate detailed records of how a company identifies, assesses, and addresses cybersecurity risks. Those records are precisely the kinds of documents that plaintiffs’ counsel will seek in data breach and privacy class actions. Companies should expect that audits designed for compliance purposes may show up as exhibits attached to pleadings and expert reports, and they should structure their audit programs with that practical reality in mind.
From a legal and security perspective, the strategic goal is not to water down the audit or discourage candid findings. It is to design an audit program, and the documentation around it, with its potential litigation impact in mind so that audits:
- Support a reasonableness narrative. Findings are tied to recognized frameworks (NIST, ISO 27001, SOC 2, FTC guidance, and CPRA regulations) and placed in a risk-based, proportional context.
- Minimize “smoking gun” risk. Reports rely on fact-based descriptions, severity ratings, and clear remediation plans, rather than broad characterizations that are difficult to defend in a lawsuit.
- Preserve privilege where appropriate. Companies should distinguish between routine compliance audits and counsel-directed assessments tied to legal advice or anticipated litigation, and structure preparatory work accordingly.
The reasonableness of a company’s information security program is often the central issue in data breach and privacy class actions. Even outside the narrow CCPA private right of action, plaintiffs routinely invoke industry frameworks, certifications, and a company’s own prior audits and risk assessments to argue what constitutes “reasonable” security.
The new CCPA cybersecurity audit requirement adds a significant dimension to the previous landscape where, for example, CCPA-aligned obligations combined with Federal Trade Commission (FTC) guidance and industry frameworks help define the standard of care in negligence claims, and deviations from established practices are used to argue that privacy and security commitments were not met in support of consumer protection and contract claims. Specifically, the audit requirement will generate a structured, documented record that courts and experts may treat as a benchmark for evaluating reasonableness. A well-structured audit, tied to recognized frameworks and followed by documented remediation, can be powerful evidence of diligence. A poorly handled audit, especially one that surfaces serious, unaddressed issues over multiple years, can be equally powerful evidence for plaintiffs.
II. How CCPA Audits and Certifications Will Likely Show Up in Litigation
In civil litigation, CCPA cybersecurity audits are likely to surface at three practical inflection points: (1) early pleadings and case framing, (2) discovery targeting audit work, and (3) merits determinations. At each stage, the quality and structure of the audit record will shape whether it supports or undermines the company’s defenses.
A. Pleadings and Initial Motion Practice
At the outset of a case, plaintiffs mine public materials to frame a conflict between what the company represented and what security controls were actually in place. Where CCPA cybersecurity audit reports or summaries have been made publicly available, plaintiffs will seize on them to shape these allegations in their complaints.
At the motion to dismiss stage, courts assess the sufficiency of the complaint based on the allegations pleaded. As a practical matter, this means that a plaintiff’s common law and statutory claims are more likely to survive a pleadings challenge where the plaintiff’s allegations are bolstered by audit reports or summaries showing deficiencies and/or gaps in security.
B. Discovery Targeting Audit Work
Once a case proceeds to discovery, plaintiffs focus on the company’s information security program, which will now include the company’s CCPA cybersecurity audit history and certification strategy. This is where decisions made and documents created years earlier are tested. Plaintiffs routinely seek:
- Internal cybersecurity, CCPA, and privacy audits and gap analyses — including any internal reviews that purport to assess compliance with statutory requirements, regulatory guidance, or internal policies.
- Third-party assessments — ISO/IEC 27001 surveillance and recertification files, SOC 2 reports (and underlying workpapers, where obtainable), and other framework-based reviews performed by external consultants.
- Board and committee materials — presentations, dashboards, and minutes referencing audits, certifications, key findings, and management responses, especially where they show escalation of significant issues.
- Vendor risk assessments and due diligence reports — records reflecting how the company evaluated its own vendors’ certifications and audits.
“Audit” in litigation rarely means just the final report. Instead, plaintiffs push not just for the audit report itself but everything surrounding it: scoping documents, testing plans, interview notes, issue trackers, and management responses. Companies should assume that some portion of their CCPA audit and certification record will be discoverable in a future dispute.
C. Merits Determinations
At the merits stage, audits evolve from background context to substantive evidence on core questions. Experts and courts look to audit reports and established frameworks as reference points for evaluating the reasonableness of a company’s information security program during the relevant time period. In a data breach case, plaintiffs often focus their causation arguments on prior findings of security vulnerabilities closely connected to the security incident, such as chronic issues with patch management, remote access, or identity and access management in an environment later exploited. While documentation showing an issue was identified, prioritized, and remediated before the security incident will support the defense, a long record of “accepted risk” for a control later implicated in the security incident will damage it. Causation turns less on the existence of findings and more on the company’s response to those findings.
III. The Litigation Risk of Mishandled Audits
Audits and framework alignment can be powerful evidence that a company took cybersecurity and privacy seriously. But courts treat them as relevant data points, not automatic defenses. The focus will be on what the company actually did and how it handled known issues.
A. Audits as Evidence of Reasonableness or Unreasonableness
When designed and executed thoughtfully, audits and certifications can demonstrate strong governance, structured risk assessment, and continuous improvement, evidence that can help defend against allegations that a company failed to implement reasonable security controls. But the greater concern for most companies is the litigation risk that arises when audits are not handled carefully. If audit records reveal known critical vulnerabilities left unremediated, repeat findings over multiple years, or gaps between the company’s representations concerning security and what the audit actually showed, plaintiffs will use those records to build their case.
Findings labeled “critical” or “high” that remain open for long periods without a clear rationale or compensating controls are among the most powerful pieces of evidence plaintiffs can put before a jury. Repeated findings over multiple years invite arguments that the company normalized known weaknesses rather than addressing them.
Language choice in audit reports also matters. Phrases such as “systemic failures,” “grossly inadequate controls,” or “material noncompliance” may resonate in a litigation setting far beyond what the author intended, especially if not accompanied by specific context or a clear remediation roadmap. The goal is not to sanitize reports but to ensure that descriptions are fact-based and do not contain sensational or unsupported characterizations that add no analytical value.
IV. Privilege and Work-Product Strategy Around Audits
Privilege and work-product protection around audit materials is one of the highest-stakes decisions in the CCPA compliance lifecycle. The CCPA cybersecurity audits will generate the kind of detailed, candid documentation that is extremely valuable for improving a company’s information security program but at the same time can be extremely dangerous if produced to plaintiffs. Getting the structure right from the beginning is more effective than trying to assert privilege after the fact.
A. Counsel-Directed vs. Routine Compliance Audits
Counsel-directed audits are undertaken to obtain legal advice and prepare for potential regulatory inquiries or litigation. Counsel retains and instructs the auditor or forensic firm, defines the scope with reference to legal risk, and directs the flow of deliverables. The purpose is to enable counsel to assess legal exposure and prepare for the possibility that the company’s security and privacy posture will be challenged in a legal proceeding, not just to evaluate technical controls in the abstract.
Routine compliance reviews, by contrast, are primarily operational or regulatory housekeeping. Annual SOC 2 audits, recurring ISO 27001 surveillance assessments, and periodic internal compliance reviews undertaken as part of standard company operations are far less likely to be protected by privilege, even if legal counsel is consulted or copied. Courts look past the involvement of counsel if the audit would have been conducted in substantially the same form regardless of any legal risk.
B. Structuring Preparatory Work to Limit Discoverability
Before the formal CCPA cybersecurity audit begins, companies should conduct privileged preparatory work under the direction of counsel to identify and remediate gaps in a protected setting. The goal is to ensure that the candid, internal process of assessing where the program falls short happens within the cloak of privilege, so that the formal audit record reflects a program the company is prepared to defend.
Courts have emphasized the importance of the contemporaneous record in establishing privilege, and the same principle applies to pre-audit work. To support a privilege claim, internal reviews and gap-finding exercises should be conducted under the direction of in-house or outside counsel, with engagement letters and statements of work expressly tying the assessment to legal advice and anticipated litigation or regulatory risk.
Counsel should be in the driver’s seat. That means counsel retains the cybersecurity or audit firm; the engagement letter states that the purpose of the engagement is to assist counsel in assessing legal risk and preparing for reasonably anticipated regulatory inquiries or litigation; and counsel defines the scope, participates in investigative briefings, and directs how findings are documented and circulated.
The most effective strategy is a deliberate separation between the legal track and the operational track. Factual audit reports that may go to regulators or be discovered in litigation belong on the operational track. Legal memoranda assessing how those findings affect litigation risk, regulatory exposure, or defense strategy belong on the legal track and should remain in counsel’s files.
V. Practical Checklists: Turning This into Action
The principles discussed in this article touch companies’ legal and security teams as well as their boards and executives. The checklists below are actionable items for each team when preparing to address CCPA cybersecurity audits.
For Legal
- Pre-Audit
- Decide when pre-audit work should be conducted at the direction of counsel. Establish criteria for shifting from a routine compliance audit to a counsel-directed assessment. Common triggers include significant security incidents, regulatory inquiries, material changes in data processing, or high-risk compliance gaps. When appropriate, counsel retains the auditor and deliverables flow through counsel.
- Create a scope memo template. Require a memo that documents the purpose of the assessment, the legal basis for any privilege claim, counsel’s role in directing the engagement, and the intended use and distribution of deliverables. This template serves as the foundation for the contemporaneous record that courts require to support privilege claims.
- Audit
- Set expectations for the audit. Work with the auditor to set clear expectations that all findings and reporting will be fact-based with no opinion or speculation.
For Security
- Integrate audit findings into a documented remediation plan. Every significant finding should have an owner, a remediation timeline, and a documented interim risk treatment or, where possible, compensating control where full remediation will take time. The plan should be reviewed and updated regularly to close findings following remediation.
- Track and escalate repeat findings. Maintain a tracking mechanism that identifies repeat findings, escalates them, documents the reasons for any delay in remediation, and, to the extent possible, sets forth an expedited remediation plan.
For Boards and Executives
- Incorporate the eventual CCPA audit results into enterprise risk reporting. Audit findings and remediation status should be integrated into broader enterprise risk management reporting so that the board and relevant committees have visibility into the cybersecurity and privacy risk landscape.
- Ensure executive certifications are factually grounded. Executives who sign certifications should be briefed on unresolved findings, ongoing remediation timelines, and any material gaps between the certification’s representations and the current state of the program.
VI. Conclusion
For many companies, the first CCPA cybersecurity audit will also be the first audit in the hands of plaintiffs. The question in litigation will not be whether the audit exists, but whether the record it creates tells a coherent story about a thoughtfully designed information security program. Legal and security should approach CCPA audits now as the dual-use instruments they will become: compliance tools that will be evidence in litigation, for better or for worse.