Certifications
The certifications and compliance programs tracked vendors' trust centers list, and which vendors list each.
| Framework | Vendors | Kind |
|---|---|---|
| SOC 2 Type II | 241 | certificate or audit report |
| GDPR | 220 | compliance claim |
| ISO/IEC 27001 | 211 | certificate or audit report |
| CCPA/CPRA | 140 | compliance claim |
| HIPAA | 105 | compliance claim |
| SOC 2 | 86 | certificate or audit report |
| PCI DSS | 78 | certificate or audit report |
| Data Privacy Framework | 64 | compliance claim |
| SOC 3 | 51 | certificate or audit report |
| CSA STAR | 50 | certificate or audit report |
| ISO/IEC 27701 | 49 | certificate or audit report |
| ISO/IEC 27017 | 48 | certificate or audit report |
| ISO/IEC 27018 | 44 | certificate or audit report |
| ISO/IEC 42001 | 40 | certificate or audit report |
| FedRAMP | 30 | certificate or audit report |
| SOC 2 Type I | 29 | certificate or audit report |
| TX-RAMP | 29 | certificate or audit report |
| SOC 1 Type II | 22 | certificate or audit report |
| ISO 9001 | 20 | certificate or audit report |
| DORA | 19 | compliance claim |
| Cyber Essentials | 17 | certificate or audit report |
| Cyber Essentials Plus | 12 | certificate or audit report |
| TISAX | 12 | certificate or audit report |
| ISO 22301 | 11 | certificate or audit report |
| StateRAMP | 10 | certificate or audit report |
| IRAP | 8 | certificate or audit report |
| PIPEDA | 8 | compliance claim |
| APEC CBPR | 7 | certificate or audit report |
| BSI C5 | 7 | certificate or audit report |
| NIST CSF | 7 | compliance claim |
| SOC 1 | 7 | certificate or audit report |
| ENS (Spain) | 6 | certificate or audit report |
| HITRUST CSF | 5 | certificate or audit report |
| CASA | 4 | certificate or audit report |
| COPPA | 3 | compliance claim |
| FERPA | 2 | compliance claim |
| HDS (France) | 2 | certificate or audit report |
| ISMAP | 2 | certificate or audit report |
| EU Cloud Code of Conduct | 1 | certificate or audit report |
| SOC 1 Type I | 1 | certificate or audit report |
From trust centers on Vanta, SafeBase and Conveyor, as each vendor lists them. A listing is the vendor's statement; the reports themselves are usually shared on request.