Compliance matrix
California Consumer Privacy Act, as amended by the CPRA
California, United States · Updated 2026-07-19
Applies to: For-profit businesses meeting revenue or data-volume thresholds that handle California residents' personal information.
Vendor certification snapshot
CCPA readiness status across the 48 vendors we track, read live from each profile. This field reflects vendor-stated readiness, not an independent audit.
45
Certified
1
Partial
2
Not stated
Certified / supported
- Akamai Identity Cloud
- Amazon Cognito
- Auth0
- Authentik
- Authress
- Authsignal
- BetterAuth
- Beyond Identity
- Clerk
- Corbado
- Curity
- CyberArk Identity
- Descope
- Firebase Authentication
- ForgeRock
- Frontegg
- FusionAuth
- Hanko
- IBM Verify
- Keycloak
- Kinde
- Logto
- Microsoft Entra External ID
- miniOrange
- MojoAuth
- Oracle IAM Identity Domains
- Ory
- Ping Identity
- PropelAuth
- Rownd
- SAP Customer Data Cloud
- Scalekit
- SlashID
- SSOJet
- Stack Auth
- Strivacity
- Stytch
- Supabase Auth
- SuperTokens
- Tesseral
- Transmit Security
- WorkOS
- Wristband
- WSO2 Identity Server
- Zitadel
Partial
Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.
Requirements mapped to CIAM
Right to know and access
Consumers can request the categories and specifics of personal information you hold about them.
CIAM controls
- Verified-identity request flow before disclosure
- Self-service data access
Evidence
- Request verification records
- Disclosure logs
Ask the vendor
- How is the requester's identity verified before data is disclosed?
Right to delete and correct
Consumers can have their personal information deleted or corrected, subject to exceptions.
CIAM controls
- Self-service deletion and profile correction
- Verified deletion with confirmation
Evidence
- Deletion logs with timestamps
- Correction audit trail
Ask the vendor
- Can consumers self-serve deletion and correction with an audit trail?
Right to opt out of sale / sharing
Consumers can opt out of the sale or sharing of personal information, including via the Global Privacy Control signal.
CIAM controls
- Opt-out preference capture
- Recognition of Global Privacy Control (GPC)
- Consent / preference center
Evidence
- Opt-out records
- GPC handling configuration
Ask the vendor
- Do you capture and honor opt-out preferences and GPC signals?
Take this into procurement
Turn these requirements into vendor questions.
The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.
Go deeper
Where it bites hardest
FAQ
- How is CCPA different from GDPR for CIAM?
- Both grant access, deletion, and portability-style rights, so the same self-service identity flows serve both. CCPA/CPRA adds an explicit opt-out of sale/sharing and requires honoring the Global Privacy Control browser signal, which GDPR does not.
- Do we need to verify identity before a deletion request?
- Yes. The regulations require reasonable verification of the requester before acting, which is why a CIAM platform's identity-verification and authentication controls are central to compliant request handling.
Source
California Privacy Protection Agency (CPRA regulations)
This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.