Companies with business in California could face tough new cybersecurity mandates under draft regulations that are soon headed for formal rulemaking.

The California Privacy Protection Agency (CPPA) is expected to vote as early as Friday to launch the formal rulemaking process for a series of cybersecurity audit requirements on businesses. Once approved for formal rulemaking, the draft regulations would be open 45 days for public comment before being finalized. Businesses would then have two years to come into compliance with the rules.

Adrianne Appel writes regulatory news, policy, and trends for Compliance Week. She previously reported about policy developments for Bloomberg Law and Bloomberg Government. Email: adrianne.appel@complianceweek.com LinkedIn:...