Skip to content

Certifications

63 certifications and attestations in 10 families · 60 held by at least one of the 64 vendors

63 of 63 certifications

Certification
SOC reports 3
SOC 1

An auditor's report on controls relevant to customers' financial reporting.

21 of 64 vendors · vendor pages

SOC 2

An auditor's report on security, availability, confidentiality, processing integrity and privacy controls.

52 of 64 vendors · vendor pages

SOC 3

A public summary of a SOC 2 examination, readable without an NDA.

19 of 64 vendors · vendor pages

ISO standards 8
ISO/IEC 27001

A certified information security management system.

48 of 64 vendors · vendor pages

ISO/IEC 27017

Cloud-specific security controls on top of ISO 27001.

27 of 64 vendors · vendor pages

ISO/IEC 27018

Protection of personal data in public clouds acting as processors.

26 of 64 vendors · vendor pages

ISO/IEC 27701

A certified privacy information management system extending ISO 27001.

20 of 64 vendors · vendor pages

ISO 9001

A certified quality management system.

13 of 64 vendors · vendor pages

ISO 22301

A certified business continuity management system.

12 of 64 vendors · vendor pages

ISO/IEC 20000-1

A certified IT service management system.

7 of 64 vendors · vendor pages

ISO 27799

Information security controls for personal health information.

1 of 64 vendors · vendor pages

AI governance 2
ISO/IEC 42001

A certified AI management system: how a company governs the AI it builds or uses.

19 of 64 vendors · CSA STAR Registry

CSA STAR for AI

A listing in the CSA STAR for AI program.

4 of 64 vendors · CSA STAR Registry

US government 12
FedRAMP

Authorization to sell a cloud service to US federal agencies.

38 of 64 vendors · FedRAMP Marketplace

DoD Impact Level

A provisional authorization for Department of Defense data at an impact level.

10 of 64 vendors · vendor pages

GovRAMP (StateRAMP)

A security verification for US state and local government cloud buyers.

17 of 64 vendors · GovRAMP list

TX-RAMP

Texas state certification for cloud services sold to state agencies.

5 of 64 vendors · vendor pages

CMMC 2.0

Cybersecurity Maturity Model Certification for the defense supply chain.

4 of 64 vendors · vendor pages

NIST SP 800-171

Controls for protecting controlled unclassified information in non-federal systems.

7 of 64 vendors · vendor pages

NIST SP 800-53

The federal security and privacy control catalog (the basis of FedRAMP).

5 of 64 vendors · vendor pages

FIPS 140 validated

Cryptographic modules validated under FIPS 140-2 or 140-3.

12 of 64 vendors · NIST CMVP

ITAR

Support for export-controlled defense data under ITAR.

6 of 64 vendors · vendor pages

CJIS

Support for the FBI CJIS Security Policy for criminal justice data.

5 of 64 vendors · vendor pages

IRS Publication 1075

Safeguards for federal tax information held by agencies and their vendors.

4 of 64 vendors · vendor pages

Section 508 / VPAT

Accessibility conformance reports (VPAT) for US federal buyers.

11 of 64 vendors · vendor pages

Finance 12
PCI DSS

Validated compliance with the card industry data security standard.

32 of 64 vendors · vendor pages

PCI 3DS

Compliance with the PCI standard for 3-D Secure card authentication.

3 of 64 vendors · vendor pages

SWIFT CSP

Attestation against the SWIFT Customer Security Programme controls.

0 of 64 vendors · vendor pages

SEC 17a-4 / FINRA 4511

WORM record retention assessed against SEC Rule 17a-4(f) and FINRA 4511.

4 of 64 vendors · vendor pages

GLBA

Support for the Gramm-Leach-Bliley Act safeguards on financial data.

2 of 64 vendors · vendor pages

SOX support

Controls documented to support customers' Sarbanes-Oxley reporting.

2 of 64 vendors · vendor pages

FFIEC

Mapping to the FFIEC IT examination guidance for US banks.

3 of 64 vendors · vendor pages

MAS TRM (Singapore)

Alignment with MAS technology risk management and outsourcing guidelines.

2 of 64 vendors · vendor pages

APRA CPS 234

Support for APRA prudential standards on information security.

5 of 64 vendors · vendor pages

OSFI B-13

Alignment with Canadian OSFI technology and cyber risk guidelines.

2 of 64 vendors · vendor pages

FISC (Japan)

Alignment with Japan's FISC security guidelines for financial institutions.

5 of 64 vendors · vendor pages

DORA

Readiness for the EU Digital Operational Resilience Act for financial entities.

10 of 64 vendors · vendor pages

Health 5
HIPAA (BAA)

The vendor supports HIPAA-regulated health data and signs a Business Associate Agreement.

39 of 64 vendors · vendor pages

HITRUST

A certified assessment against the HITRUST CSF.

11 of 64 vendors · vendor pages

HDS (France)

Certification to host personal health data in France (Hébergeur de Données de Santé).

6 of 64 vendors · vendor pages

NHS DSPT (UK)

The NHS Data Security and Protection Toolkit self-assessment for suppliers.

4 of 64 vendors · vendor pages

PHIPA (Ontario)

Support for Ontario's Personal Health Information Protection Act.

0 of 64 vendors · vendor pages

Life sciences (GxP) 4
GxP qualification

Support for regulated life-sciences workloads under GMP, GCP and GLP.

12 of 64 vendors · vendor pages

FDA 21 CFR Part 11

Support for electronic records and signatures under 21 CFR Part 11.

4 of 64 vendors · vendor pages

EU GMP Annex 11

Support for computerised systems under EU GMP Annex 11.

2 of 64 vendors · vendor pages

CSV / CSA validation

Computer system validation or computer software assurance packages for customers.

2 of 64 vendors · vendor pages

Privacy and cloud 4
Data Privacy Framework

Self-certification under the EU-US Data Privacy Framework, with UK and Swiss extensions where noted.

48 of 64 vendors · DPF List

APEC CBPR / PRP

Certification under the Cross-Border Privacy Rules or Privacy Recognition for Processors.

8 of 64 vendors · vendor pages

EU Cloud Code of Conduct

Adherence to the GDPR code of conduct for cloud processors.

13 of 64 vendors · CSA STAR Registry

CSA STAR

A listing in the Cloud Security Alliance STAR Registry.

41 of 64 vendors · CSA STAR Registry

Regional programs 10
Cyber Essentials (UK)

The UK government-backed baseline security certification.

15 of 64 vendors · vendor pages

UK G-Cloud

Listing on the UK government's cloud procurement framework.

6 of 64 vendors · vendor pages

BSI C5 (Germany)

An attestation against Germany's Cloud Computing Compliance Criteria Catalogue.

11 of 64 vendors · vendor pages

ENS (Spain)

Certification under Spain's Esquema Nacional de Seguridad.

13 of 64 vendors · vendor pages

SecNumCloud (France)

ANSSI qualification for trusted cloud services in France.

0 of 64 vendors · vendor pages

IRAP (Australia)

An assessment by an ASD-endorsed assessor for Australian government data.

17 of 64 vendors · vendor pages

ISMAP (Japan)

Registration on Japan's government cloud security list.

13 of 64 vendors · vendor pages

MTCS (Singapore)

Certification under Singapore's Multi-Tier Cloud Security standard.

7 of 64 vendors · vendor pages

K-ISMS (Korea)

Korea's information security management system certification.

3 of 64 vendors · vendor pages

TISAX

An assessment shared through the German automotive industry's exchange.

21 of 64 vendors · vendor pages

Education 3
FERPA

Support for student education records under FERPA.

7 of 64 vendors · vendor pages

HECVAT

A published Higher Education Community Vendor Assessment Toolkit.

3 of 64 vendors · vendor pages

COPPA

Support for the Children's Online Privacy Protection Act, where stated.

2 of 64 vendors · vendor pages

Certification changes by email

Wednesdays: vendors that gained or lost a certification, only in weeks with a change.

Double opt-in. Unsubscribe any time.