Method
Where each entry comes from, how it is read, and what it cannot tell you
| Source | What it gives | Last read |
|---|---|---|
| FedRAMP Marketplace dataPublic registry Every offering, its impact level, authorization date and status history. Authoritative for FedRAMP. | Every offering, its impact level, authorization date and status history. Authoritative for FedRAMP. | Sep 23, 2026 |
| CSA STAR RegistryPublic registry STAR Level 1 and 2, STAR for AI, and partner entries for ISO/IEC 42001 and the EU Cloud Code of Conduct, with the date first listed. | STAR Level 1 and 2, STAR for AI, and partner entries for ISO/IEC 42001 and the EU Cloud Code of Conduct, with the date first listed. | Sep 23, 2026 |
| Data Privacy Framework ListPublic registry EU-US, UK and Swiss certification status, the date certified and when recertification is due. | EU-US, UK and Swiss certification status, the date certified and when recertification is due. | Sep 23, 2026 |
| NIST CMVP validated modulesPublic registry Active FIPS 140-3 and 140-2 certificates listed under the vendor's name, with the module names. | Active FIPS 140-3 and 140-2 certificates listed under the vendor's name, with the module names. | Sep 24, 2026 |
| GovRAMP product listPublic registry Offerings authorized, ready or in process for US state and local government, with the impact level. | Offerings authorized, ready or in process for US state and local government, with the impact level. | Sep 24, 2026 |
| Vendor compliance pagesVendor statement Everything else: the vendor's own trust center or compliance page, read as text, with the sentence that names the certification. | Everything else: the vendor's own trust center or compliance page, read as text, with the sentence that names the certification. | 55 pages |
What "held" means
Held means a public registry lists the vendor as authorized, certified or validated (FedRAMP Marketplace, CSA STAR, the DPF List, NIST CMVP, GovRAMP), or the vendor's own compliance page names the certification as one it holds. Levels are shown where the source states one (FedRAMP High, SOC 2 Type II, FIPS 140-3, DoD IL5). No evidence means not shown.
In process is FedRAMP or GovRAMP In Process, Pending or Ready. Lapsed is a withdrawn or expired registry entry, or a vendor page that says it no longer holds it.
A vendor page is matched by the certification's name and kept with the sentence it appeared in. Pages that only name a standard as something customers are responsible for are set aside by hand. Unverified marks a match nobody has confirmed: added by the weekly run, or read by hand and found to name the standard without showing the vendor holding it (support for a customer's own CMMC or FERPA duties, for example).
Several entries are not certificates at all: HIPAA, GxP, 21 CFR Part 11, DORA, FERPA and similar rules have no certification. For those, the entry records that the vendor says it supports customers under the rule, and links the page that says so.
Most trust centers render their lists with JavaScript. Those are read in a browser when the site is refreshed by hand; plain pages are re-read by the weekly run, Wednesday 10:00 UTC, along with every registry.
Scope matters. A certification usually covers named products, regions or a government cloud, not everything a company sells. From public trust centers and registries on the date shown. Confirm scope with the vendor.
Questions
What is Compliance (compliance.fru.dev)?
It answers which certifications and attestations cloud, data, AI and developer-tool vendors hold: SOC 1, 2 and 3, ISO 27001 and its family, ISO 42001, FedRAMP, GovRAMP, DoD Impact Levels, FIPS 140, CMMC, HIPAA, HITRUST, GxP, 21 CFR Part 11, PCI DSS, DORA, the Data Privacy Framework, CSA STAR, C5, IRAP, ISMAP and more. Pick up to three and get the vendors that hold all of them, each linked to its evidence and the date it was captured.
Is this about certifications people earn?
No. This site tracks the certifications companies hold (SOC 2, ISO 27001, FedRAMP and the rest). For exams and certifications people take, see Certifications (certifications.fru.dev).
Where does the data come from?
From public registries where they exist (the FedRAMP Marketplace data, the CSA STAR Registry, the Data Privacy Framework List, the NIST CMVP list of validated FIPS 140 modules and the GovRAMP product list) and otherwise from each vendor's own compliance or trust-center page. Registry entries are authoritative; vendor-page entries record the sentence the vendor published, and matches nobody has confirmed show Unverified.
How often is it updated?
A run every Wednesday at 10:00 UTC re-reads every registry and a rotating set of vendor pages. What changed goes into the change log with its date.
Which vendors support GxP and 21 CFR Part 11?
Pick GxP and 21 CFR Part 11 on the home page. There is no GxP certificate: the list shows vendors whose compliance pages publish GxP qualification guidance or Part 11 and Annex 11 mappings, such as AWS, Microsoft and Google Cloud, each with the page that says so.
Which AI vendors are FedRAMP authorized?
Filter the grid by FedRAMP: OpenAI (ChatGPT Enterprise and API Platform, FedRAMP 20x Moderate), Perplexity (20x Low), Scale AI and Palantir (High), and Google's Gemini for Government (20x Low) are listed in the FedRAMP Marketplace. Claude reaches federal agencies through AWS GovCloud and Google Cloud authorizations.
Which companies are ISO 42001 certified?
Open the ISO/IEC 42001 page: it lists every tracked vendor that names the AI management system certification on its compliance page or in the CSA STAR Registry, including Microsoft, AWS, Google Cloud, Anthropic, OpenAI, Snowflake and Workday.
Is HIPAA a certification?
No. There is no HIPAA certificate. The HIPAA column records whether a vendor says it supports HIPAA-regulated data and signs a Business Associate Agreement, and for which products; confirm the BAA scope with the vendor.
Does a SOC 2 listing mean I can see the report?
No. SOC 1 and SOC 2 reports are shared under NDA through the vendor's trust center. SOC 3 is the public summary. Compliance records that the vendor states it has the report, with a link to where to request it.