Certifications
63 certifications and attestations in 10 families · 60 held by at least one of the 64 vendors
63 of 63 certifications
| Certification | ||
|---|---|---|
| SOC reports 3 | ||
| SOC 1 An auditor's report on controls relevant to customers' financial reporting. 21 of 64 vendors · vendor pages | 21 | Vendor pages |
| SOC 2 An auditor's report on security, availability, confidentiality, processing integrity and privacy controls. 52 of 64 vendors · vendor pages | 52 | Vendor pages |
| SOC 3 A public summary of a SOC 2 examination, readable without an NDA. 19 of 64 vendors · vendor pages | 19 | Vendor pages |
| ISO standards 8 | ||
| ISO/IEC 27001 A certified information security management system. 48 of 64 vendors · vendor pages | 48 | Vendor pages |
| ISO/IEC 27017 Cloud-specific security controls on top of ISO 27001. 27 of 64 vendors · vendor pages | 27 | Vendor pages |
| ISO/IEC 27018 Protection of personal data in public clouds acting as processors. 26 of 64 vendors · vendor pages | 26 | Vendor pages |
| ISO/IEC 27701 A certified privacy information management system extending ISO 27001. 20 of 64 vendors · vendor pages | 20 | Vendor pages |
| ISO 9001 A certified quality management system. 13 of 64 vendors · vendor pages | 13 | Vendor pages |
| ISO 22301 A certified business continuity management system. 12 of 64 vendors · vendor pages | 12 | Vendor pages |
| ISO/IEC 20000-1 A certified IT service management system. 7 of 64 vendors · vendor pages | 7 | Vendor pages |
| ISO 27799 Information security controls for personal health information. 1 of 64 vendors · vendor pages | 1 | Vendor pages |
| AI governance 2 | ||
| ISO/IEC 42001 A certified AI management system: how a company governs the AI it builds or uses. 19 of 64 vendors · CSA STAR Registry | 19 | CSA STAR Registry and vendor pages |
| CSA STAR for AI A listing in the CSA STAR for AI program. 4 of 64 vendors · CSA STAR Registry | 4 | CSA STAR Registry and vendor pages |
| US government 12 | ||
| FedRAMP Authorization to sell a cloud service to US federal agencies. 38 of 64 vendors · FedRAMP Marketplace | 38 | FedRAMP Marketplace and vendor pages |
| DoD Impact Level A provisional authorization for Department of Defense data at an impact level. 10 of 64 vendors · vendor pages | 10 | Vendor pages |
| GovRAMP (StateRAMP) A security verification for US state and local government cloud buyers. 17 of 64 vendors · GovRAMP list | 17 | GovRAMP list and vendor pages |
| TX-RAMP Texas state certification for cloud services sold to state agencies. 5 of 64 vendors · vendor pages | 5 | Vendor pages |
| CMMC 2.0 Cybersecurity Maturity Model Certification for the defense supply chain. 4 of 64 vendors · vendor pages | 4 | Vendor pages |
| NIST SP 800-171 Controls for protecting controlled unclassified information in non-federal systems. 7 of 64 vendors · vendor pages | 7 | Vendor pages |
| NIST SP 800-53 The federal security and privacy control catalog (the basis of FedRAMP). 5 of 64 vendors · vendor pages | 5 | Vendor pages |
| FIPS 140 validated Cryptographic modules validated under FIPS 140-2 or 140-3. 12 of 64 vendors · NIST CMVP | 12 | NIST CMVP and vendor pages |
| ITAR Support for export-controlled defense data under ITAR. 6 of 64 vendors · vendor pages | 6 | Vendor pages |
| CJIS Support for the FBI CJIS Security Policy for criminal justice data. 5 of 64 vendors · vendor pages | 5 | Vendor pages |
| IRS Publication 1075 Safeguards for federal tax information held by agencies and their vendors. 4 of 64 vendors · vendor pages | 4 | Vendor pages |
| Section 508 / VPAT Accessibility conformance reports (VPAT) for US federal buyers. 11 of 64 vendors · vendor pages | 11 | Vendor pages |
| Finance 12 | ||
| PCI DSS Validated compliance with the card industry data security standard. 32 of 64 vendors · vendor pages | 32 | Vendor pages |
| PCI 3DS Compliance with the PCI standard for 3-D Secure card authentication. 3 of 64 vendors · vendor pages | 3 | Vendor pages |
| SWIFT CSP Attestation against the SWIFT Customer Security Programme controls. 0 of 64 vendors · vendor pages | 0 | Vendor pages |
| SEC 17a-4 / FINRA 4511 WORM record retention assessed against SEC Rule 17a-4(f) and FINRA 4511. 4 of 64 vendors · vendor pages | 4 | Vendor pages |
| GLBA Support for the Gramm-Leach-Bliley Act safeguards on financial data. 2 of 64 vendors · vendor pages | 2 | Vendor pages |
| SOX support Controls documented to support customers' Sarbanes-Oxley reporting. 2 of 64 vendors · vendor pages | 2 | Vendor pages |
| FFIEC Mapping to the FFIEC IT examination guidance for US banks. 3 of 64 vendors · vendor pages | 3 | Vendor pages |
| MAS TRM (Singapore) Alignment with MAS technology risk management and outsourcing guidelines. 2 of 64 vendors · vendor pages | 2 | Vendor pages |
| APRA CPS 234 Support for APRA prudential standards on information security. 5 of 64 vendors · vendor pages | 5 | Vendor pages |
| OSFI B-13 Alignment with Canadian OSFI technology and cyber risk guidelines. 2 of 64 vendors · vendor pages | 2 | Vendor pages |
| FISC (Japan) Alignment with Japan's FISC security guidelines for financial institutions. 5 of 64 vendors · vendor pages | 5 | Vendor pages |
| DORA Readiness for the EU Digital Operational Resilience Act for financial entities. 10 of 64 vendors · vendor pages | 10 | Vendor pages |
| Health 5 | ||
| HIPAA (BAA) The vendor supports HIPAA-regulated health data and signs a Business Associate Agreement. 39 of 64 vendors · vendor pages | 39 | Vendor pages |
| HITRUST A certified assessment against the HITRUST CSF. 11 of 64 vendors · vendor pages | 11 | Vendor pages |
| HDS (France) Certification to host personal health data in France (Hébergeur de Données de Santé). 6 of 64 vendors · vendor pages | 6 | Vendor pages |
| NHS DSPT (UK) The NHS Data Security and Protection Toolkit self-assessment for suppliers. 4 of 64 vendors · vendor pages | 4 | Vendor pages |
| PHIPA (Ontario) Support for Ontario's Personal Health Information Protection Act. 0 of 64 vendors · vendor pages | 0 | Vendor pages |
| Life sciences (GxP) 4 | ||
| GxP qualification Support for regulated life-sciences workloads under GMP, GCP and GLP. 12 of 64 vendors · vendor pages | 12 | Vendor pages |
| FDA 21 CFR Part 11 Support for electronic records and signatures under 21 CFR Part 11. 4 of 64 vendors · vendor pages | 4 | Vendor pages |
| EU GMP Annex 11 Support for computerised systems under EU GMP Annex 11. 2 of 64 vendors · vendor pages | 2 | Vendor pages |
| CSV / CSA validation Computer system validation or computer software assurance packages for customers. 2 of 64 vendors · vendor pages | 2 | Vendor pages |
| Privacy and cloud 4 | ||
| Data Privacy Framework Self-certification under the EU-US Data Privacy Framework, with UK and Swiss extensions where noted. 48 of 64 vendors · DPF List | 48 | DPF List and vendor pages |
| APEC CBPR / PRP Certification under the Cross-Border Privacy Rules or Privacy Recognition for Processors. 8 of 64 vendors · vendor pages | 8 | Vendor pages |
| EU Cloud Code of Conduct Adherence to the GDPR code of conduct for cloud processors. 13 of 64 vendors · CSA STAR Registry | 13 | CSA STAR Registry and vendor pages |
| CSA STAR A listing in the Cloud Security Alliance STAR Registry. 41 of 64 vendors · CSA STAR Registry | 41 | CSA STAR Registry and vendor pages |
| Regional programs 10 | ||
| Cyber Essentials (UK) The UK government-backed baseline security certification. 15 of 64 vendors · vendor pages | 15 | Vendor pages |
| UK G-Cloud Listing on the UK government's cloud procurement framework. 6 of 64 vendors · vendor pages | 6 | Vendor pages |
| BSI C5 (Germany) An attestation against Germany's Cloud Computing Compliance Criteria Catalogue. 11 of 64 vendors · vendor pages | 11 | Vendor pages |
| ENS (Spain) Certification under Spain's Esquema Nacional de Seguridad. 13 of 64 vendors · vendor pages | 13 | Vendor pages |
| SecNumCloud (France) ANSSI qualification for trusted cloud services in France. 0 of 64 vendors · vendor pages | 0 | Vendor pages |
| IRAP (Australia) An assessment by an ASD-endorsed assessor for Australian government data. 17 of 64 vendors · vendor pages | 17 | Vendor pages |
| ISMAP (Japan) Registration on Japan's government cloud security list. 13 of 64 vendors · vendor pages | 13 | Vendor pages |
| MTCS (Singapore) Certification under Singapore's Multi-Tier Cloud Security standard. 7 of 64 vendors · vendor pages | 7 | Vendor pages |
| K-ISMS (Korea) Korea's information security management system certification. 3 of 64 vendors · vendor pages | 3 | Vendor pages |
| TISAX An assessment shared through the German automotive industry's exchange. 21 of 64 vendors · vendor pages | 21 | Vendor pages |
| Education 3 | ||
| FERPA Support for student education records under FERPA. 7 of 64 vendors · vendor pages | 7 | Vendor pages |
| HECVAT A published Higher Education Community Vendor Assessment Toolkit. 3 of 64 vendors · vendor pages | 3 | Vendor pages |
| COPPA Support for the Children's Online Privacy Protection Act, where stated. 2 of 64 vendors · vendor pages | 2 | Vendor pages |