Skip to content

Zscaler compliance, certifications and attestations

Security and infra · 5 certifications held · 5 from public registries · read Sep 24, 2026

CertificationEvidence
US government
FedRAMP
High

Zscaler Private Access - Government (Zero Trust Networking - VPN Replacement); Zscaler Internet Access - Government (Secure Web Gateway - vTIC)

FedRAMP Marketplace

Sep 23, 2026
GovRAMP (StateRAMP)
Moderate

Zscaler Private Access (Authorized, Moderate); Zscaler Internet Access - Government (ZIA Gov) (Authorized, Moderate)

GovRAMP product list

Sep 24, 2026
FIPS 140 validated
FIPS 140-3

1 active FIPS 140-3 module: #5080 Zscaler Java Crypto Module

NIST CMVP

Sep 24, 2026
Privacy and cloud
Data Privacy Framework
Held

EU-US, UK extension, Swiss-US; non-HR data and HR data. Zscaler

Data Privacy Framework List

Sep 23, 2026
CSA STAR
Level 2

CAIQ, certification

CSA STAR Registry

Sep 23, 2026

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

DateChange
Added FedRAMP Moderate

Zscaler Private Access - Government (Zero Trust Exchange - VPN Replacement)

Added FedRAMP High

Zscaler Internet Access - Government (Secure Web Gateway - vTIC) - High

In process FedRAMP Moderate

Zscaler Private Access - Government (Zero Trust Exchange - VPN Replacement)

Ready FedRAMP High

Zscaler Internet Access - Government (Secure Web Gateway - vTIC) - High

Upgraded FedRAMP High

Zscaler Private Access - Government (Zero Trust Networking - VPN Replacement)

Ready FedRAMP High

Zscaler Private Access - Government (Zero Trust Networking - VPN Replacement)

Added CSA STAR

First listed in the CSA STAR Registry

Added FedRAMP Moderate

Zscaler Internet Access - Government (Secure Web Gateway - vTIC)

In process FedRAMP Moderate

Zscaler Internet Access - Government (Secure Web Gateway - vTIC)

Added Data Privacy Framework

Zscaler

About Zscaler

Zero trust exchange for internet and private access.

Status
Public
Founded
2008

No public evidence found for

SOC reports
SOC 1, SOC 2, SOC 3
ISO standards
ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 9001, ISO 22301, ISO 20000, ISO 27799
AI governance
ISO 42001, STAR AI
US government
DoD IL, TX-RAMP, CMMC, 800-171, 800-53, ITAR, CJIS, IRS 1075, 508/VPAT
Finance
PCI DSS, PCI 3DS, SWIFT, 17a-4, GLBA, SOX, FFIEC, MAS TRM, APRA, OSFI, FISC, DORA
Health
HIPAA, HITRUST, HDS, NHS DSPT, PHIPA
Life sciences (GxP)
GxP, Part 11, Annex 11, CSV
Privacy and cloud
CBPR, EU CoC
Regional programs
Cyber Ess., G-Cloud, C5, ENS, SecNum, IRAP, ISMAP, MTCS, K-ISMS, TISAX
Education
FERPA, HECVAT, COPPA

Compare with CrowdStrike, Wiz, Twilio, PagerDuty, Okta

Company profile
Across fru.devAcquisitionsawardsEarningsleadersPaydaysConferences

Certification changes by email

Wednesdays: vendors that gained or lost a certification, only in weeks with a change.

Double opt-in. Unsubscribe any time.