Third Party Index

Certifications

The certifications and compliance programs tracked vendors' trust centers list, and which vendors list each.

FrameworkVendorsKind
SOC 2 Type II241certificate or audit report
GDPR220compliance claim
ISO/IEC 27001211certificate or audit report
CCPA/CPRA140compliance claim
HIPAA105compliance claim
SOC 286certificate or audit report
PCI DSS78certificate or audit report
Data Privacy Framework64compliance claim
SOC 351certificate or audit report
CSA STAR50certificate or audit report
ISO/IEC 2770149certificate or audit report
ISO/IEC 2701748certificate or audit report
ISO/IEC 2701844certificate or audit report
ISO/IEC 4200140certificate or audit report
FedRAMP30certificate or audit report
SOC 2 Type I29certificate or audit report
TX-RAMP29certificate or audit report
SOC 1 Type II22certificate or audit report
ISO 900120certificate or audit report
DORA19compliance claim
Cyber Essentials17certificate or audit report
Cyber Essentials Plus12certificate or audit report
TISAX12certificate or audit report
ISO 2230111certificate or audit report
StateRAMP10certificate or audit report
IRAP8certificate or audit report
PIPEDA8compliance claim
APEC CBPR7certificate or audit report
BSI C57certificate or audit report
NIST CSF7compliance claim
SOC 17certificate or audit report
ENS (Spain)6certificate or audit report
HITRUST CSF5certificate or audit report
CASA4certificate or audit report
COPPA3compliance claim
FERPA2compliance claim
HDS (France)2certificate or audit report
ISMAP2certificate or audit report
EU Cloud Code of Conduct1certificate or audit report
SOC 1 Type I1certificate or audit report

From trust centers on Vanta, SafeBase and Conveyor, as each vendor lists them. A listing is the vendor's statement; the reports themselves are usually shared on request.