complianceiso-27001virginia-cdpacompliancedata-protectionbreach-recoverythreat-intelligence

ISO 27001 gap analysis for Virginia CDPA: what certification misses and what the AG will ask for

Amara OkaforAmara OkaforApril 29, 2026
Share:
ISO 27001 gap analysis for Virginia CDPA: what certification misses and what the AG will ask for

Key takeaways

  • ISO 27001 certification validates that an ISMS is documented and that management review processes exist — it does not validate that the technical controls protecting Virginia consumer data are working. 42% of CDPA-relevant vulnerabilities in assessed ISO 27001-certified environments went undetected by standard audit tooling. (Vulnox assessment data, 2024)

  • The Virginia CDPA requires data protection assessments for processing activities involving sensitive data, targeted advertising, and sale of personal data. ISO 27001 A.8.1.1 risk assessments can be mapped to this requirement, but the mapping requires explicit documentation — it does not happen automatically because the organization is certified.

  • Virginia CDPA penalties reach $7,500 per violation with no cap per enforcement action. The Attorney General's office asks for a complete incident timeline including timestamps, user actions, and affected data elements — not an ISO 27001 audit report.

  • The most consistent gap between ISO 27001 certification and CDPA compliance is the universal opt-out mechanism requirement. ISO 27001 has no control that addresses technical enforcement of consumer opt-out signals. Organizations that outsource this to a consent management platform and do not verify technical implementation are non-compliant regardless of certification status.

  • Third-party risk assessments under ISO 27001 A.8.1.1 are evaluated on documentation quality, not technical depth. An ISO 27001-compliant third-party risk process can fail to identify a critical vulnerability in a KYC provider's database instance and still pass surveillance audit.

  • A prediction with a named signal: by Q2 2027, Virginia AG enforcement actions will begin citing ISO 27001-certified organizations specifically, using certification status as evidence that the organization had the resources and intent to implement controls — making certification an aggravating factor rather than a mitigating one when controls demonstrably failed.

TL;DR

ISO 27001 certification is an audit of your ISMS documentation and management processes. Virginia CDPA compliance is a legal requirement for specific technical controls around consumer data rights, opt-out mechanisms, and breach notification. These overlap but are not the same thing. Certified organizations that have not explicitly mapped their ISO 27001 controls to CDPA requirements have a compliance gap they cannot see in their audit report. The gap shows up when the Attorney General asks questions the auditor never asked.

The surveillance audit that passed, and the AG investigation that followed

A healthcare analytics company, roughly 60 employees, held a current ISO 27001 certification. Their most recent surveillance audit had passed without findings. Six months later, a security researcher disclosed that the company's analytics database was accessible with default credentials and exposed patient-adjacent behavioral data for Virginia residents. The Virginia AG's office opened an inquiry. The company submitted their ISO 27001 audit report as evidence of reasonable security measures. The AG's response: the audit report confirmed that a vulnerability management process was documented. It did not confirm that the database was actually secured. The company was asked to provide the penetration test results from the prior 12 months. Those results had identified the default credential issue. The remediation record showed the finding as closed. The database still had default credentials because the remediation record had been updated without the fix being deployed. The AG assessed $340,000 in penalties.

Turning point:

The ISO 27001 auditor had reviewed the penetration test finding as closed in the remediation tracker. Auditors verify documentation of remediation. They do not re-test whether the remediation actually worked. The certification was current and legitimate. The control was not functioning. The Virginia CDPA does not ask whether your remediation process is documented — it asks whether Virginia consumer data was protected. The answer was no, and the certification did not change that.

What the numbers show about the gap between certification and control effectiveness

42%

Of CDPA-relevant vulnerabilities in ISO 27001-certified client environments went undetected by standard audit tooling used in surveillance audits. These were not novel attack techniques — they included unpatched software on data-processing systems, misconfigured access controls on consumer data stores, and consent management platforms that documented opt-out preferences without technically enforcing them. The certification was current. The controls were not effective. (Vulnox assessment data, 2024)

92 days

Average time to patch a critical vulnerability in a CDPA-compliance-relevant system in assessed ISO 27001-certified environments. The ISO 27001 control A.12.6.1 requires a vulnerability management process — it does not specify a patching SLA. Organizations with documented patch management processes that exceed 90 days on critical findings are ISO 27001-compliant and CDPA-exposed simultaneously. (Vulnox assessment data, 2024)

78 days

Average time from initial compromise to discovery in assessed environments that had experienced a breach involving Virginia consumer data. The CDPA requires breach notification within 60 days of discovery. Average time to discovery alone consumes most of that window, leaving organizations in notification breach before they have completed forensic scoping. (Vulnox assessment data, 2024)

$7,500

Maximum civil penalty per CDPA violation, with no statutory cap per enforcement action. An exposure affecting 10,000 Virginia consumers with an arguable single-processing violation produces a potential $7,500 penalty. An exposure affecting the same population with multiple processing violations — inadequate security, failure to honor opt-out, missing data protection assessment — multiplies accordingly. The AG's office has discretion on per-violation counting. (Virginia CDPA, Va. Code Ann. § 59.1-578)

Where ISO 27001 controls end and CDPA requirements begin

ISO 27001 is an ISMS framework. It specifies that organizations must have policies, conduct risk assessments, manage vulnerabilities, control access, and review management processes. It does not specify the outcome of any of those activities. An organization with a documented vulnerability management process that consistently takes 120 days to patch critical findings is ISO 27001-compliant if the process is documented and reviewed. The CDPA does not care about process documentation — it requires that Virginia consumer data be protected with reasonable security measures. The gap between these two requirements is where most CDPA exposure lives in ISO 27001-certified organizations. The second structural gap is in control specificity. ISO 27001 A.5.1 requires access controls. The CDPA requires data minimization, purpose limitation, and consumer rights implementation — including the right to opt out of targeted advertising, the right to delete, and the right to correct. There is no ISO 27001 control that maps cleanly to a universal opt-out mechanism. Organizations that treat ISO 27001 A.5.1 access control compliance as evidence of CDPA opt-out compliance have not read the CDPA requirement.

Example

OneTrust and similar consent management platforms are widely used to document consumer opt-out preferences. They record that a consumer opted out. They do not, by default, technically enforce that preference across all downstream data flows — tracking pixels, third-party advertising integrations, analytics platforms, and data sharing agreements with partners. The platform shows opt-out recorded. The consumer's data continues flowing to advertising partners because the platform's technical enforcement configuration was not completed at implementation. This is not a platform failure — it is a configuration and verification failure. ISO 27001 A.8.25 (secure development lifecycle) and A.5.23 (information security for use of cloud services) can be mapped to this requirement, but only if the organization explicitly made that mapping and verified technical enforcement. The surveillance audit checks whether the mapping documentation exists. It does not re-verify that the technical enforcement is working.

The CDPA's universal opt-out mechanism requirement references the Global Privacy Control (GPC) signal — a browser-level signal that communicates consumer opt-out preference to websites. Technically honoring GPC requires server-side code that reads the Sec-GPC request header and suppresses data flows accordingly. This is an application-layer implementation requirement. ISO 27001 has no control that audits application-layer header processing. An organization can have a fully current ISO 27001 certification and no GPC implementation and face CDPA enforcement.

What gap analysis finds that surveillance audits miss

Assessment base: Assessed ISO 27001-certified environments with Virginia CDPA applicability, 2023–2024

Remediation records closed without technical verification produce the most dangerous compliance gap

In the healthcare analytics case and in two other assessed environments, ISO 27001 vulnerability management findings were marked closed in the remediation tracker — satisfying the auditor's evidence requirement — without the underlying fix being deployed. In one case, a developer closed the Jira ticket when the fix was merged to a development branch, before the production deployment. In another, the system owner marked the finding closed when the vendor acknowledged the issue, before the patch was released. Auditors reviewing remediation evidence see a closed ticket with a timestamp. They do not re-test the production system.

Implication:

The ISO 27001 certification process creates an incentive structure where documented closure matters more than actual remediation. Organizations under audit deadline pressure close findings to avoid findings in the audit report. The result is a certification that reflects documentation quality, not control effectiveness. CDPA enforcement does not accept closed tickets as evidence of protection.

Third-party risk assessments pass ISO 27001 audit and miss critical vendor vulnerabilities

A fintech client with ISO 27001 certification had a documented third-party risk assessment process compliant with A.8.1.1. Their KYC provider was assessed annually via questionnaire. The questionnaire confirmed that the provider had information security policies, conducted vulnerability scanning, and had an incident response plan. None of this surfaced that the provider was running MongoDB 3.6 — end of life since April 2021, with multiple CVEs without patches — on the database handling identity verification documents including Virginia resident data. The questionnaire-based assessment was documented, reviewed, and signed off. The database version was not asked about.

Implication:

ISO 27001 A.8.1.1 requires a risk assessment process for third parties. It does not require technical assessment of third-party infrastructure. A questionnaire-based process satisfies the audit requirement. It does not identify vulnerabilities that a technical assessment would find. For third parties processing Virginia consumer data, the CDPA's reasonable security standard extends to those processors — the organization is responsible for verifying adequate protection, not just documenting that they asked.

Logging infrastructure that satisfies ISO 27001 audit fails CDPA breach reconstruction requirements

Multiple clients described the same experience: spending significantly on SIEM infrastructure, receiving audit confirmation that logging was comprehensive, and then discovering during a breach that the specific logs needed to reconstruct which Virginia consumer data was accessed had never been enabled. The SIEM was ingesting firewall logs, authentication events, and system metrics. Application-layer logs that would record database queries, record-level access, and data export events were not configured. ISO 27001 A.8.15 (logging) requires that logging policies are implemented. It does not specify which application-layer events must be captured. The CDPA breach notification requirement asks for the specific personal data affected — which requires record-level access logs to determine.

Implication:

An organization that cannot tell the Virginia AG which specific consumer records were accessed has a notification problem and an evidence problem simultaneously. The logging infrastructure that satisfies ISO 27001 audit is not necessarily the logging infrastructure that supports CDPA breach reconstruction. These need to be designed together, not assumed to overlap.

ISO 27001 certification may become an aggravating factor in CDPA enforcement, not a mitigating one

Common belief

ISO 27001 certification demonstrates a commitment to information security that regulators and courts treat as evidence of good faith. Certified organizations that experience a breach are in a better enforcement position than uncertified organizations because they can demonstrate a structured security program.

What we found

In post-breach advisory work, Vulnox has observed that organizations with current ISO 27001 certification that experience CDPA-relevant breaches face more detailed regulatory scrutiny than uncertified organizations with comparable breaches. Regulators use the certification as a reference point: the organization's own ISMS documentation describes the controls that should have been in place. The gap between documented control and actual control becomes the enforcement case. Certification without technical verification of control effectiveness produces documentation that helps the regulator build their case.

This holds when the certification reflects genuine control effectiveness. It inverts when the certification is shown to have been current at the time controls demonstrably failed. A regulator looking at a certified organization that experienced a breach involving consumer data has a different question than they have for an uncertified organization: if you were certified, why did the controls fail? The certification sets a higher baseline expectation. Failing to meet that baseline while certified is a stronger evidence of inadequacy than failing while uncertified. The AG's office does not need to establish that the organization should have had controls — they already said they did. The question becomes why the certified controls did not protect Virginia consumer data.

What clients said before the gap analysis and what was underneath it

  • 'We spent a significant amount on Splunk and the auditors confirmed our logging was comprehensive. Then we had an incident and found out the logs we needed to identify affected Virginia residents had never been enabled. We thought having the SIEM meant we were logging the right things.'

    Root cause:

    The SIEM was purchased and configured to satisfy ISO 27001 A.8.15 — logging policies implemented, evidence available for audit. The configuration was done by the infrastructure team against the ISO 27001 requirement, not against the question: if we have a breach, what logs do we need to determine which Virginia consumer records were accessed? Those are different configuration objectives. Application-layer query logging, record-level access events, and data export tracking were not in scope for the ISO 27001 logging implementation. They are required for CDPA breach reconstruction. Nobody connected those requirements until the breach made the gap visible.

  • 'We use OneTrust for consent management. It records opt-out preferences. We assumed that meant we were compliant with the CDPA opt-out requirement. Our developer recently told us that the tracking pixels on our site are still firing for opted-out users because the server-side suppression was never configured.'

    Root cause:

    OneTrust and equivalent platforms record consent and opt-out preferences. Technical enforcement of those preferences — suppressing tracking pixels, blocking data flows to advertising partners, honoring the GPC signal — requires application-layer configuration that is separate from the platform setup. The platform was implemented by a compliance team focused on documentation. The technical enforcement configuration required developer involvement that was never scheduled. The CDPA does not accept documented opt-out preferences as compliance — it requires that the opt-out is technically honored. ISO 27001 has no control that would have caught this gap.

  • 'Our ISO 27001 auditor reviewed our third-party risk assessments and had no findings. Six months later we discovered our KYC provider had been running end-of-life software on the database holding our customers' identity documents. We asked our auditor why this wasn't caught and they said questionnaire-based assessments are standard practice for the control.'

    Root cause:

    The auditor is correct that questionnaire-based third-party assessment satisfies ISO 27001 A.8.1.1. The standard does not require technical assessment of vendor infrastructure. It requires a documented process for assessing third-party risk. The questionnaire process is documented and reviewed — it passes audit. It does not find infrastructure vulnerabilities that a technical assessment would find. For third parties processing Virginia consumer data under CDPA, the reasonable security standard requires more than questionnaire confirmation. The organization is responsible for the security of consumer data regardless of which vendor holds it.

The CDPA requirements that ISO 27001 controls do not address

Data protection assessments for high-risk processing activities

The Virginia CDPA requires data protection assessments before initiating processing activities that present a heightened risk — targeted advertising, sale of personal data, processing sensitive data, and processing that presents a reasonably foreseeable risk of harm. ISO 27001 A.8.1.1 risk assessments can be adapted to meet this requirement, but the adaptation requires explicit documentation: the risk assessment must address the specific processing activity, the specific data subjects affected, the specific risks to those subjects, and the safeguards implemented. A generic ISMS risk assessment that covers organizational information security risks does not satisfy this requirement. In assessed environments, 0 of 8 organizations that were conducting ISO 27001 risk assessments had produced a CDPA-compliant data protection assessment for their targeted advertising activities.

Consumer rights fulfillment timelines and technical infrastructure

The CDPA gives Virginia consumers the right to access, correct, delete, and obtain a portable copy of their personal data, with 45-day response windows and a 45-day extension available with notice. ISO 27001 has no control addressing consumer rights response infrastructure. Organizations that have documented privacy policies describing these rights but have not built the technical infrastructure to fulfill requests — database queries to locate consumer records, deletion workflows that propagate across backups and third-party processors, portability export formats — will fail the first DSR they receive. The policy passes audit. The technical capability is what the consumer tests.

The GPC signal requirement is an application development requirement, not a policy requirement

Honoring the Global Privacy Control signal under CDPA requires reading the Sec-GPC HTTP request header server-side and suppressing data collection and sharing for requests carrying that signal. This is code, not policy. It requires a developer to implement it, test it, and maintain it across application updates. ISO 27001 A.8.25 (secure development lifecycle) can be cited as the applicable control, but only if the organization explicitly included GPC implementation in its secure development requirements. The default is that no ISO 27001 control requires GPC implementation, and organizations with full certification can be entirely non-compliant with this specific CDPA technical requirement.

How to close the gap between ISO 27001 certification and CDPA compliance

Commonly skipped:

Step 2. Organizations document opt-out preferences and consider the requirement met. Technical verification of enforcement is treated as a consent platform vendor responsibility. It is not. The CDPA requires that the opt-out is honored — technically, not administratively. Testing whether opted-out users are actually not tracked is a five-minute browser network inspection test that almost no assessed organization had conducted before Vulnox ran it.

  1. 1Compliance lead or DPO

    Produce an explicit control mapping document: for each CDPA requirement, identify the ISO 27001 control that addresses it and document the gap where no control applies. The mapping must be specific — not 'A.8.1.1 covers risk assessment' but 'A.8.1.1 covers risk assessment; CDPA data protection assessment for targeted advertising requires the following additional documentation elements not covered by A.8.1.1 risk assessment template.' This document becomes the gap analysis baseline and the evidence document if the AG asks how you mapped your ISMS to CDPA requirements.

    Expected outcome

    A documented list of CDPA requirements with no ISO 27001 control coverage — specifically: universal opt-out technical enforcement, GPC signal implementation, data protection assessments for specific processing activities, and consumer rights fulfillment infrastructure. These gaps require implementation, not documentation.

  2. 2Development team with compliance lead

    Audit technical enforcement of consumer opt-out preferences. Do not ask the consent platform whether opt-outs are recorded — verify technically that opted-out users are not tracked. Load a test user session, record an opt-out, then inspect outbound network traffic from the browser to confirm that tracking pixels, advertising tags, and analytics calls are suppressed. Repeat this test after every significant front-end deployment. Document results. If the test fails, the CDPA compliance claim fails regardless of what the consent platform dashboard shows.

    Expected outcome

    Confirmed technical enforcement of opt-out preferences, not just documented preference recording. A test protocol that can be run after deployments to catch regression. Evidence that technical enforcement was verified, not assumed.

  3. 3Security team with application owners

    Implement record-level access logging for all systems storing Virginia consumer personal data. The logging must capture which records were accessed, by which user or system, at what timestamp, and what operation was performed. This is not the same as system access logging or authentication logging. It requires application-layer instrumentation, not infrastructure-layer log collection. Confirm that the logs are being ingested by the SIEM and that a query exists to reconstruct 'which Virginia consumer records were accessed between date X and date Y.' Test the query. If the query cannot be run, the breach notification requirement cannot be met.

    Expected outcome

    Confirmed ability to reconstruct record-level access for Virginia consumer data within the 60-day CDPA breach notification window. Evidence that logging coverage was technically verified, not assumed from SIEM deployment.

  4. 4Vendor management with security team

    Add a technical assessment requirement to third-party assessments for vendors processing Virginia consumer data. Questionnaire-based assessments remain in place for lower-risk vendors. For vendors with access to personal data, add one of: an annual penetration test report provided by the vendor, a SOC 2 Type II report with security criteria, or a technical questionnaire that asks specifically about software versions, patching SLAs, and infrastructure configuration. Require contract language that allows Vulnox or another assessor to conduct a technical assessment of the vendor if a questionnaire response cannot be verified.

    Expected outcome

    Third-party risk assessments that identify infrastructure vulnerabilities, not just documented process maturity. Contractual rights to verify vendor security claims technically. Evidence that third-party risk management goes beyond questionnaire documentation.

  5. 5Compliance lead with IR team

    Produce a CDPA-specific incident response addendum to the ISO 27001 incident management procedure. The addendum must specify: how the organization determines which Virginia consumer records were affected (the log query from step 3), the 60-day notification clock and when it starts running, the content requirements for AG notification versus consumer notification, and the internal evidence package the AG will request — incident timeline in detail, affected data inventory, security measures in place at the time, and remediation steps. Run a tabletop exercise using the Virginia AG's published enforcement guidance as the scenario.

    Expected outcome

    An IR team that knows CDPA notification requirements before an incident, not during one. A documented timeline for AG notification that is achievable given actual log coverage. Evidence that the organization prepared for CDPA-specific notification requirements independently of the generic ISO 27001 incident management process.

Where CDPA enforcement is heading and what ISO 27001-certified organizations should watch

  1. By Q2 2027, the Virginia AG's office will have brought at least one enforcement action against an ISO 27001-certified organization in which the certification status is cited as evidence of organizational capability — using the ISMS documentation to establish what controls the organization claimed to have in place and demonstrating that those controls failed. Certification will appear in the enforcement order as context, not as mitigation.

    The enforcement pattern is already visible in FTC actions against organizations with documented security programs. The Virginia AG's office has indicated interest in enforcement against organizations that have formalized compliance programs but demonstrably failed to protect consumer data. ISO 27001-certified organizations have produced detailed documentation of their intended controls. That documentation is discoverable and useful to enforcement agencies demonstrating a gap between claimed and actual protection. The first case where this happens will change how organizations communicate their ISO 27001 status to regulators.

    Confidence: highIf by June 2027 no Virginia AG enforcement action or consent order references ISO 27001 certification status in the factual background of the action, the prediction is wrong. Monitor the Virginia AG's Consumer Protection Section enforcement releases.
  2. Within 18 months, at least one major ISO 27001 certification body will introduce a CDPA-specific surveillance audit module requiring technical verification of consumer rights implementation — driven by liability concerns after certification is cited in regulatory enforcement. The module will require a technical test of opt-out enforcement and record-level logging coverage, not just documentation review.

    Certification bodies face reputational and potentially legal exposure when their certifications are invoked in regulatory proceedings and the certified controls demonstrably failed. The documentation-only audit model is sustainable until enforcement actions make the gap public. When a certified organization pays $340,000 in CDPA penalties with a current certification on the wall, the certification body has a product credibility problem. The response historically has been scope expansion — adding technical verification requirements to close the documented-control-versus-effective-control gap. This is the same pressure that drove SOC 2 Type II to require operational effectiveness testing, not just control design.

    Confidence: mediumIf by October 2027 no major accredited ISO 27001 certification body operating in the US has introduced a privacy-regulation-specific audit module with technical verification requirements, the timeline prediction is wrong. Monitor UKAS, ANAB, and A2LA program updates.

Further Reading

Frequently Asked Questions

Does ISO 27001 certification satisfy Virginia CDPA compliance requirements?

No. ISO 27001 certification validates that an ISMS is documented and that management review processes function. The Virginia CDPA requires specific technical controls: universal opt-out mechanism implementation including GPC signal support, data protection assessments for high-risk processing activities, 45-day consumer rights response infrastructure, and breach notification capability. None of these map automatically to ISO 27001 controls. An organization must explicitly map CDPA requirements to ISO 27001 controls and document the gaps where no control applies. In assessed environments, 42% of CDPA-relevant vulnerabilities were undetected by standard ISO 27001 audit tooling. (Vulnox assessment data, 2024)

What does a gap analysis between ISO 27001 and Virginia CDPA actually look for?

Four categories consistently produce findings. First: opt-out technical enforcement — consent platforms record preferences; gap analysis verifies whether opted-out users are technically not tracked across all data flows. Second: data protection assessments for specific processing activities — ISO 27001 risk assessments are organizational; CDPA DPAs must address specific processing activities and data subject harms. Third: record-level access logging — ISO 27001 A.8.15 requires logging policies; CDPA breach reconstruction requires application-layer query logs identifying which consumer records were accessed. Fourth: third-party technical assessment — ISO 27001 allows questionnaire-based vendor assessment; CDPA reasonable security extends to processors and requires technical verification.

What will the Virginia AG ask for after a data breach involving consumer data?

A complete incident timeline with timestamps, user actions, and affected data elements. Specifically: which Virginia consumer records were accessed or exfiltrated, what security measures were in place at the time of the breach, what the organization knew and when, and what remediation steps were taken. ISO 27001 audit reports are not what the AG requests. The questions require record-level access logs, forensic timeline reconstruction, and a data inventory that maps consumer records to the breach window. Organizations that cannot answer these questions from their log infrastructure face both notification violations and evidentiary problems.

What are the Virginia CDPA penalties for a breach involving ISO 27001-certified organizations?

Up to $7,500 per violation with no statutory cap per enforcement action. The AG's office has discretion in counting violations — an exposure involving inadequate security, failure to honor opt-out, and a missing data protection assessment for the processing activity involves multiple violation categories. Virginia CDPA provides a 30-day cure period before the AG may bring an action, but cure requires demonstrating that the violation has been corrected, not just that a plan exists. (Virginia CDPA, Va. Code Ann. § 59.1-578)

How does the Virginia CDPA universal opt-out requirement work technically?

The CDPA references the Global Privacy Control signal — a browser-level Sec-GPC HTTP request header that communicates consumer opt-out to websites. Honoring it requires server-side code that reads this header and suppresses data collection and sharing for those requests. This is an application development requirement. A consent management platform records opt-out preferences but does not enforce the GPC signal unless the application is configured to read the header and suppress data flows accordingly. In assessed environments, organizations using consent platforms frequently had documented opt-out preferences that were not technically enforced because the server-side implementation was never completed.

Can ISO 27001 third-party risk assessments satisfy Virginia CDPA requirements for processor oversight?

Only if the assessment includes technical verification, not just questionnaire documentation. ISO 27001 A.8.1.1 requires a third-party risk assessment process — questionnaire-based assessment satisfies this control. The CDPA's reasonable security standard for processors requires that Virginia consumer data is actually protected, not just that the vendor answered questions confirming they have policies. For vendors processing Virginia consumer data, assessments should include: annual penetration test reports from the vendor, SOC 2 Type II with security criteria, or direct technical questionnaires about software versions and patching SLAs. Contract language requiring the right to conduct technical verification closes the gap that questionnaire-only assessment leaves open.

What logging infrastructure is required for Virginia CDPA breach notification compliance?

Record-level access logging for all systems storing Virginia consumer personal data. The logs must capture which records were accessed, by which user or system, at what timestamp, and what operation was performed. This is application-layer instrumentation — not infrastructure authentication logs or firewall logs. The test: can the organization run a query that returns 'which Virginia consumer records were accessed between date X and date Y'? If not, the 60-day breach notification requirement cannot be met with the specificity the AG will ask for. ISO 27001 A.8.15 logging compliance does not guarantee this capability — it requires explicit application instrumentation configured against the CDPA reconstruction requirement.

Related Articles

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard

GovRAMP Moderate is the first tier where you need a government sponsor, annual 3PAO reassessment, and a Significant Change Request process that can pause normal product releases for months. Most providers who stall post-authorization were not prepared for what maintaining Moderate status actually costs operationally.

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong

GovRAMP Low+ is where providers handling limited Controlled Unclassified Information land — or discover they should not be there. The defining failure is not a missing control. It is a CUI boundary that was drawn before anyone asked what data the government actually sends through the system.

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard

GovRAMP High is where cloud providers discover that having strong encryption is not the same as having FIPS 140-2 validated encryption — and that distinction alone has derailed authorizations from vendors who passed every other control family. The architectural constraints at High are qualitatively different from every lower tier.

Ready to Secure Your Digital Assets?

Get a comprehensive vulnerability assessment for your website today.