Cisco

Cybersecurity United States Website Reviewed Sept. 2, 2026

Networking, collaboration (Webex), and security products including Duo, Umbrella, Secure Endpoint and Meraki.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited third-party certification body In-scope Cisco cloud offers including Webex, Duo, Umbrella and Meraki Current
ISO/IEC 27017:2015 and ISO/IEC 27018:2019 Accredited third-party certification body Cloud security controls and protection of PII in public cloud for in-scope Cisco offers Current
ISO/IEC 27701:2019 Accredited third-party certification body Privacy information management system covering in-scope Cisco offers Current
SOC 2 Type II Independent third-party auditor In-scope Cisco cloud offers; reports available to customers under NDA Current
FedRAMP US federal authorising body Webex for Government and other authorised Cisco offers Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
Scope differs per Cisco cloud offer - check the relevant Cisco Trust Portal entry
SOC 2 Type 2
Full
GDPR 2016/679
Full
Cisco publishes per-product privacy data sheets; SCCs and UK IDTA available
HIPAA Security
Partial
HIPAA BAA available for eligible offers such as Webex
NIST Cybersecurity Framework
Partial
Cisco maps offers to NIST CSF

Assess Cisco in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.