Direct Answer: As of January 1, 2026, California businesses have 30 calendar days to notify affected residents after discovering a data breach. A separate CPRA rule now requires annual cybersecurity audits for businesses above certain data thresholds.
If you run a business in Salinas, Monterey, or anywhere in the Monterey Bay Area, two new California laws changed your compliance picture as of January 1, 2026 — and most local business owners haven’t heard about either one yet.
SB 446 cut the data breach notification window from a vague “expedient” standard down to a hard 30 calendar days. At the same time, finalized regulations under the California Privacy Rights Act (CPRA) created a new annual cybersecurity audit requirement for businesses that cross certain data thresholds. These aren’t proposed rules. They’re live.
The practical question isn’t whether your attorney knows about these laws. It’s whether your business could actually execute a breach response in 30 days with no warning — and whether you’d even know if you fall under the audit requirement. Those are two very different problems, and both deserve a clear look.
What SB 446 Actually Changed — and Why 30 Days Is Shorter Than It Sounds
Before January 1, 2026, California’s breach notification law required businesses to notify affected residents “in the most expedient time possible and without unreasonable delay.” That language gave organizations room to investigate before acting. SB 446 eliminated the wiggle room.
Now the clock is fixed: 30 calendar days from the date you discover the breach. If 500 or more California residents are affected, you also owe the California Attorney General a notice within 15 days of sending consumer notifications. That’s not 15 days from discovery — it’s 15 days after you’ve already notified consumers.
For a financial services firm in Monterey or a healthcare-adjacent practice in Salinas, that timeline is aggressive. Consider what has to happen inside that window:
- Identify that a breach occurred
- Determine what data was exposed and whose
- Confirm which individuals are California residents
- Draft and send compliant consumer notifications
- File with the AG if the threshold is met
None of that is possible without a documented incident response plan already in place before the breach happens. Businesses that are trying to figure out their process at the same time they’re managing an active incident will almost certainly miss the deadline. And missing it isn’t just a legal problem — under the CPRA’s enforcement structure, the cost of waiting until something breaks applies in a very literal sense when penalties are calculated per record.

The CPRA Audit Requirement: Do You Actually Fall In Scope?
The California Privacy Protection Agency finalized regulations requiring mandatory annual cybersecurity audits for covered businesses. Two thresholds determine whether you’re in scope:
- Processing personal information for 250,000 or more California residents annually
- Handling sensitive personal information for 50,000 or more individuals annually
A lot of Monterey Bay Area business owners read those numbers and move on, assuming they’re too small to qualify. That assumption deserves a second look.
“Sensitive personal information” under CPRA includes financial account data, health information, and precise geolocation data. Those categories show up far more often than most people expect. An agricultural operation in the Salinas Valley managing payroll data for hundreds of seasonal workers may be collecting precise location information through field management software. A nonprofit handling donor payment histories stores financial account data. A professional services firm in Carmel or Pacific Grove with years of client financial records could cross the 50,000-record threshold without realizing it.
The audit itself must align with NIST Cybersecurity Framework 2.0 or an equivalent ISO standard. First certifications for larger organizations are due April 1, 2028, with phased deadlines extending through 2030 for smaller ones. But “phased” does not mean “start later.” Building a cybersecurity program that meets those frameworks — documenting controls, running gap assessments, correcting deficiencies — takes 12 to 24 months for most small businesses. If your IT staff is already stretched thin, adding a framework-aligned audit program without outside support is a serious operational lift.
SB 446 and CPRA Audit Requirements at a Glance
Here’s a side-by-side look at the two requirements, their triggers, and the key deadlines Monterey Bay Area businesses need to track.
| Requirement | Who It Applies To | Key Deadline |
|---|---|---|
| SB 446 — 30-Day Breach Notification | Any business that collects CA resident data and experiences a qualifying breach | 30 days from breach discovery; AG notice within 15 days of consumer notification if 500+ affected |
| SB 446 — AG Notification Threshold | Breaches involving 500+ CA residents | 15 days after consumer notifications are sent |
| CPRA Cybersecurity Audit — Large Org Threshold | 250,000+ CA residents’ personal info processed annually | First certification due April 1, 2028 |
| CPRA Cybersecurity Audit — Sensitive Data Threshold | 50,000+ individuals’ sensitive personal info annually | Phased deadlines through 2030; program build should begin now |
| CPRA Penalty Range | Any covered business in violation | $2,663 to $7,988 per violation; each consumer record can be a separate violation |
The 30-Day Breach Response Timeline
This timeline shows what a business needs to execute — in sequence — from the moment a breach is discovered to the final Attorney General filing.

Why ‘Per Record’ Enforcement Changes the Math Entirely
The CPPA has been clear: there is no grace period for first-time violations. Enforcement is already underway.
The penalty structure is what makes this genuinely dangerous for smaller organizations. Fines range from $2,663 to $7,988 per violation — and the CPPA treats each affected consumer record as a potential separate violation. That’s not a hypothetical extreme. If a business in Seaside or Hollister experiences a breach affecting 1,000 customer records and misses the 30-day notification deadline, the potential fine exposure starts at $2.6 million.
Most small businesses in Monterey County don’t have that kind of liability buffer. And most don’t have the data mapping in place to even know how many records were exposed within the first 48 hours of discovering an incident.
This is why the compliance question is really an operational readiness question. The law doesn’t care whether you have a good attorney or good intentions. It cares whether you executed the process on time. Understanding your full network security posture — including where personal data lives and how it’s protected — is the foundation that makes a 30-day response even possible.
What Operational Readiness Actually Looks Like for a Local SMB
“Operational readiness” sounds abstract, but for a 25-person financial services firm in Monterey or a mid-sized nonprofit in Watsonville, it comes down to three specific things:
1. A documented incident response plan. This is a written procedure — not a general IT policy — that defines exactly who gets called first when a breach is suspected, who has authority to trigger notifications, and what steps happen in what order. Most small businesses don’t have one.
2. Current data mapping. You cannot notify affected individuals in 30 days if you don’t know where their data lives. Data mapping means knowing which systems hold personal information, what categories of data those systems store, and how many records are involved. For businesses running a mix of cloud applications, on-premise servers, and employee devices — which describes most Monterey Bay Area SMBs — this requires an honest audit of your current environment.
3. Accountable ownership. Someone in your organization has to be responsible for pulling the trigger. Not “IT” in the abstract — a named individual with the authority and the access to execute the process. For businesses without in-house IT leadership, a Virtual Technology Officer arrangement or a co-managed IT relationship can fill that accountability gap.
None of these are expensive to build in isolation. But without all three working together, the 30-day clock will beat you. Proactive monitoring helps detect incidents earlier — which buys you more working time inside that window — but detection alone doesn’t replace the response infrastructure.
Frequently Asked Questions About California’s Breach and Audit Requirements
Does the 30-day notification rule apply to my business if we’re small?
Yes. SB 446 applies to any business that collects personal information from California residents and experiences a qualifying breach — there’s no small-business exemption. Size affects your resources, not your legal obligation.
We don’t think we hit the CPRA audit thresholds. Do we still need to worry about the 30-day rule?
The two requirements are separate. The 30-day breach notification rule under SB 446 applies regardless of whether you meet the CPRA audit thresholds. You can be below the audit threshold and still face serious liability if you miss a breach notification deadline. Work through both questions independently.
What counts as ‘sensitive personal information’ under CPRA?
The list is broader than most people expect. It includes Social Security numbers, financial account data, precise geolocation data, health information, biometric data, and information about a person’s sex life or sexual orientation. If you run payroll for field workers in the Salinas Valley, store client payment histories, or use any location-tracking in your operations, you likely handle sensitive personal information — even if you’ve never thought of it that way.
The CPRA audit deadline is 2028. Can we start planning in 2027?
Not realistically. Building a cybersecurity program that satisfies NIST Cybersecurity Framework 2.0 or ISO 27001 standards — which the CPPA requires — takes most small to mid-sized businesses 12 to 24 months. That includes gap assessments, control documentation, policy development, staff training, and a validation cycle before you can certify. Starting in 2027 for a 2028 deadline is a very tight window with no margin for the complications that always come up.
Is there a fine reduction if it’s our first violation?
No. The CPPA has explicitly stated there is no grace period for first-time violations. Penalties of $2,663 to $7,988 per violation are active and enforcement is already underway. The per-record structure means even a modest breach can generate significant total liability.
What’s the first thing we should actually do?
Start with a data inventory — understand what personal and sensitive personal information your business collects, where it’s stored, and how many records you hold. From there, you can assess your true exposure under both SB 446 and CPRA and prioritize accordingly. If you don’t have internal IT leadership to run that assessment, it’s a reasonable place to bring in outside support.
Ready to Know Where Your Business Actually Stands?
Adaptive Information Systems works with small and mid-sized businesses across Monterey County — from Salinas to Carmel to Watsonville — to build the incident response infrastructure, data mapping, and cybersecurity programs that make compliance timelines survivable. If you’re not sure whether SB 446 or the CPRA audit requirement applies to your organization, or if you know it does and haven’t started yet, reach out to the team at Adaptive directly: call (831) 644-0300 or visit adaptiveis.net to start the conversation.