Citrix (Cloud Software Group)
Citrix portfolio from Cloud Software Group - DaaS, NetScaler, Endpoint Management and Secure Private Access.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| SOC 2 Type 2 | Independent third-party CPA firm | 2025 Citrix Cloud Based Services SOC 2 report. Covers Citrix Desktop as a Service (DaaS), Citrix Endpoint Management (CEM) and NetScaler Console / Application Delivery Management (ADM). Report access requires a signed online NDA. | — | — | Current |
| ISO/IEC 27001:2022 | Accredited certification body | Citrix ISO 27001+27701:2022 certificate. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). Separate certificates exist for TIBCO and TIBCO EBX. | — | — | Current |
| ISO/IEC 27701:2022 | Accredited certification body | Privacy Information Management System, issued as a combined ISO 27001+27701:2022 certificate. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). | — | — | Current |
| HIPAA Letter of Assessment | Independent third-party assessor | CSG (Citrix Platform) 2025 HIPAA Letter of Assessment. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). NOT held for any TIBCO or Arctera product. | — | — | Current |
| PCI DSS v4.0 | Qualified Security Assessor (QSA) | 2025 Citrix Cloud Platform PCI DSS attestation. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). NOT held for TIBCO or Arctera products. | — | — | Current |
| IRAP Assessment | ASD-endorsed IRAP assessor | 2025 Citrix Cloud IRAP Security Assessment Report (SAR). Covers Citrix DaaS and NetScaler Console (ADM) ONLY - Citrix Endpoint Management is NOT in the IRAP scope. Report access requires a signed NDA. | — | — | Current |
| FedRAMP Moderate (JAB Authorization) | FedRAMP PMO / Joint Authorization Board | Citrix Desktop as a Service (DaaS) ONLY. Citrix Endpoint Management, NetScaler Console, all TIBCO products and Arctera are NOT FedRAMP authorised. | — | — | Current |
| FIPS 140-2 | NIST/CSE Cryptographic Module Validation Program | Cryptographic module compliance for selected Citrix products; see the FIPS 140-2 compliance page for the per-product list. FIPS 140-2 has been superseded by FIPS 140-3. | — | — | Current |
| Common Criteria (ISO/IEC 15408) | Common Criteria certification scheme | Cloud Software Group describes itself as making "progress in attaining" Common Criteria certification; check the Common Criteria Certification Information page for the exact certified product versions and Evaluation Assurance Levels. | — | — | In Progress |
| Section 508 / WCAG 2.1 (VPAT) | Self-assessment | Accessibility conformance documentation. High-priority usability and accessibility initiatives described rather than a blanket conformance claim. | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| Qualified external assessors plus an internal security testing team perform threat modelling, vulnerability scanning and penetration testing of the cloud services. Each distinct cloud service follows its own individual testing and evaluation schedule, and every cloud service release requires a security assessment by the internal testing team beforehand. Independent parties are contracted where certifications require it. (date = profile capture date) | Qualified external assessors (unnamed) plus the Cloud Software Group internal Engineering Security Team | Aug. 6, 2026 | Ad-hoc | On NDA |
| Customer-run penetration testing against their own Citrix Cloud environment is permitted but must be coordinated in advance so other tenants are not affected. Prior notice is submitted by email to [email protected] and the submitter must confirm authority to accept the Customer Penetration Test Requirements on the customer’s behalf. (date = profile capture date) | Customer or customer-appointed tester, subject to Cloud Software Group Customer Penetration Test Requirements | Aug. 6, 2026 | Ad-hoc | Not Available |
Data Handling
Sub-processors
| Sub-processor | Purpose | Data Location | Trust Portal |
|---|---|---|---|
| Akamai Technologies, Inc. | CDN, connectivity monitoring, logging and analytics | Citrix services: Citrix Workspace app (Receiver), DaaS | United States | View ↗ |
| Amazon Web Services (AWS) | Machine learning service | Citrix services: ShareFile, DaaS, Citrix Gateway Service / Secure Private Access | United States | View ↗ |
| Duo Security (affiliate of Cisco) | Security and authentication services | Citrix services: Intelligent Traffic Management (ITM) | United States | View ↗ |
| Firebase (Google Cloud Platform) | Traffic and event analysis | Citrix services: DaaS, Citrix Gateway Service / Secure Private Access | United States | View ↗ |
| Functional Software, Inc. (dba Sentry) | Monitor logs and events | Citrix services: DaaS, ShareFile, Citrix Gateway Service / Secure Private Access | United States | View ↗ |
| Google Analytics | Traffic and event analysis | Citrix services: DaaS | United States | View ↗ |
| Google Chronicle | Security monitoring, logging and analytics | Citrix services: Cloud Operations | United States | View ↗ |
| Google Cloud Platform | Traffic logging and analysis | Citrix services: ShareFile, ITM, DaaS, Citrix Gateway Service / Secure Private Access | United States | View ↗ |
| Google Maps Platform | Geographic map rendering of usage locations | Citrix services: NetScaler Console / ADM | United States | View ↗ |
| Grafana Cloud (Raintank Inc. d/b/a Grafana Labs) | Monitoring and logging | Citrix services: Cloud Operations | United States | View ↗ |
| NetActuate, Inc. (formerly Host Virtual, Inc.) | Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) | United States, Poland | View ↗ |
| Microsoft | Storage and diagnostics | Citrix services: ITM, DaaS, CEM, Citrix Gateway Service / SPA, Cloud Operations, NetScaler Console (ADM) | United States | View ↗ |
| Neustar | Application security | Citrix services: ITM, Citrix Analytics Service (CAS) | United States | — |
| New Relic, Inc. | Connectivity monitoring, logging and analytics | Citrix services: Cloud Operations, ITM | United States | View ↗ |
| Pendo.io | In-app communications and analytics | Citrix services: DaaS | United States (offices Israel, Japan, United Kingdom) | View ↗ |
| SendGrid (Twilio Inc.) | Email service provider | Citrix services: ShareFile, DaaS, CEM | United States, Ireland | View ↗ |
| Splunk Inc. | Security monitoring, logging and analytics | Citrix services: Cloud Operations | United States | View ↗ |
| Zenlayer, Inc. (formerly C3Networks Inc.) | Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) | United States | View ↗ |
| Equinix Services, Inc. | Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) | United States | View ↗ |
| Datadog, Inc. | Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) | United States | View ↗ |
| Catchpoint Systems, Inc. | Connectivity monitoring and analytics | Citrix services: Intelligent Traffic Management (ITM) | United States | View ↗ |
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| Oct. 10, 2023 | "CitrixBleed" - CVE-2023-4966 (sensitive information disclosure) and CVE-2023-4967 (denial of service) in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway. CVE-2023-4966 allowed an unauthenticated attacker to leak session tokens from appliance memory and hijack authenticated sessions, bypassing multi-factor authentication. | Exploited in the wild before and after disclosure and used for ransomware and espionage intrusions across many organisations globally. Affects customer-managed NetScaler appliances rather than the Citrix Cloud control plane, so remediation depended on customers patching. Session hijacking meant patching alone was insufficient. | Fixed builds released 10 October 2023 under Security Bulletin CTX579459. Because valid session tokens could survive patching, Citrix additionally instructed customers to terminate all active and persistent sessions after upgrading. Affected versions and required builds are listed in the bulletin. | Report ↗ |
| June 17, 2025 | "CitrixBleed 2" - CVE-2025-5777 (out-of-bounds memory read allowing session token disclosure) and CVE-2025-5349 (improper access control on the NetScaler management interface, CVSS 8.7) in NetScaler ADC and NetScaler Gateway. A further critical issue, CVE-2025-6543, was disclosed on 25 June 2025. | Affects customer-managed NetScaler ADC and Gateway appliances. National cyber security centres in New Zealand, Canada, the UK (NHS England) and elsewhere issued alerts, and CVE-2025-5777 was subsequently reported as exploited. Not a compromise of Cloud Software Group corporate or Citrix Cloud systems. | Security Bulletin CTX693420 published 17 June 2025 with fixed builds; a further advisory followed on 25 June 2025 for CVE-2025-6543. Customers must upgrade affected appliances and, as with CitrixBleed, terminate existing sessions. Remediation guidance is also published in the NetScaler Console instance advisory. | Report ↗ |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| Information Security Policy | On Request | View ↗ |
| Acceptable Use Policy (AUP) | On Request | View ↗ |
| Access Management Policy | On Request | View ↗ |
| Password Policy | On Request | View ↗ |
| Asset Management Policy | On Request | View ↗ |
| Information Classification and Handling Policy (with control matrix) | On Request | View ↗ |
| Cybersecurity Risk Management Standard | On Request | View ↗ |
| Physical Security and Control of Entry Policy | On Request | View ↗ |
| Business Continuity and Disaster Recovery Programme (incl. Business Impact Analysis) | On Request | View ↗ |
| Incident Response Plan and Incident Response Standard | On Request | View ↗ |
| Third-Party Management Policy and Supplier Security Standards | On Request | View ↗ |
| Software Development Lifecycle (SDLC) Policy | On Request | View ↗ |
| Vulnerability and Patch Management Policy | On Request | View ↗ |
| Services Security Exhibit (April 2026 edition) | Public | View ↗ |
| Code of Business Conduct | Public | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- Terms of Service View ↗
- GDPR Representative Cloud Software Group, Inc. maintains a Chief Privacy Officer and a dedicated Privacy team. Contact details and any Art. 27 representative are set out in the Privacy Statement at https://www.cloud.com/privacy - confirm during assessment.
- Lawful Basis Cloud Software Group acts as processor for Customer Content under its Data Processing Addendum, supported by the Services Security Exhibit (April 2026) defining the technical and organisational measures. A separate Partner DPA covers channel partners. Sub-processors and affiliates with access to Customer Content are published with an RSS change-notification feed. An External AI Transparency Notice and per-product privacy/AI data sheets are published.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform HackerOne - Cloud Software Group Bug Bounty Program at https://hackerone.com/csg-public. PSIRT reports to [email protected] with a public PGP key. Vulnerability response follows ISO/IEC 29147:2018 with acknowledgement by end of the next working day.
Trust Portal & Audit Evidence
**Important:** Citrix is a business unit of **Cloud Software Group**, alongside TIBCO, Spotfire, NetScaler and Arctera. The old https://www.citrix.com/trust-center/ URL now 404s; the live trust centre is at **https://www.cloud.com/trust-center**, reachable via https://www.citrix.com/about/trust-center.html. Certifications are held **per product**, not per company, and the Citrix, TIBCO and Arctera product sets have materially different coverage.
**Per-product certification matrix as published (August 2026)**
*Citrix products*
- Citrix DaaS: SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0, IRAP, FedRAMP Moderate JAB - the only fully covered product
- Citrix Endpoint Management (CEM): SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0. **No IRAP, no FedRAMP**
- NetScaler Console / Application Delivery Management (ADM): SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0, IRAP. **No FedRAMP**
*TIBCO products (for context - not covered by this profile)*
- TIBCO Platform: SOC 2 Type 2, ISO 27001, ISO 27701 only
- TIBCO Scribe: SOC 2 Type 2 only
- TIBCO EBX: ISO 27001 only
*Arctera*
- Arctera Insights Platform: SOC 2 Type 2 only
**Publicly available without NDA**
- Certification matrix: https://www.cloud.com/trust-center/certifications
- Downloadable certificates: Citrix ISO 27001+27701:2022, TIBCO ISO 27001+27701:2022, TIBCO EBX ISO 27001+27701:2022, CSG (Citrix Platform) 2025 HIPAA Letter of Assessment, 2025 Citrix Cloud Platform PCI DSS, 2025 Citrix Cloud IRAP SAR
- Top 20 security FAQs (unusually detailed control descriptions): https://www.cloud.com/trust-center/faqs
- Security assurance and customer penetration testing rules: https://www.cloud.com/trust-center/security-assurance
- Vulnerability response process (ISO/IEC 29147:2018) and bug bounty: https://www.cloud.com/trust-center/product-security/vulnerability-response
- Services Security Exhibit (April 2026), End User Agreement, DPA, Partner DPA, Service Descriptions, SLAs, Code of Business Conduct: https://www.cloud.com/trust-center/agreements
- Sub-processor and affiliate list with an RSS change feed: https://www.cloud.com/trust-center/sub-processor-list-rss
- External AI Transparency Notice and product privacy / AI governance data sheets for TIBCO Platform, Spotfire and Citrix DaaS
- Status dashboards: https://status.cloud.com and https://status.cloud.tibco.com
**Gated behind a signed online NDA**
- SOC 2 Type 2 reports (all products) and the IRAP audit report
- Due Diligence Package, including the Shared Assessments **SIG self-attestation questionnaire** and supporting evidence
- Penetration test results
Note: NDAs are signed online through My Account and take 4-6 hours to propagate to back-office systems before documents become visible.
**Sub-processor list structure**
The published list is dated **26 March 2025** and is segmented into: Citrix Cloud sub-processors (recorded in this profile); Citrix sub-processors used for support services; Citrix Cloud **Government** sub-processors; Citrix Cloud Government support services sub-processors; TIBCO Platform sub-processors; TIBCO support services sub-processors; Cloud Software Group affiliates by country; and Citrix DaaS sub-processors. Only the Citrix Cloud list is captured here - review the support-services and Government lists separately if they apply to you.
**Documented corporate controls of note**
Full-time CISO with a Security and Trust Organisation, and a Chief Privacy Officer heading the Privacy team. Framework built on ISO 27001/27002, NIST SP 800-53 and CIS, reviewed at least annually. Least-privilege access provisioning with management approval and quarterly access reviews. MFA for remote network access and cloud consoles; production machine access needs a VPN config file plus separate VPN and production credentials. Risk-rated asset inventory with owners, labels and sunset dates. Business Impact Analysis driving RTO/RPO, quarterly technology drills, annual business function exercises, quarterly IT DR testing at a DR data centre, annual table-top exercises. CSIRT led by Security with Legal managing incident communications; customer notification within the period required by applicable law. Third-Party Risk Management programme with periodic supplier reassessment and Supplier Security Standards. Secure-by-design SDLC with threat modelling, design and code reviews, exploit development, cloud hardening tests, fuzzing, assisted source review, and CWE Top 25 / OWASP Top 10 assessment. SIEM ingestion from public-cloud hosted components with alerting and correlation.
**Gaps noted at review**
- Sub-processor list is dated 26 March 2025, roughly 16 months before this review.
- No published encryption algorithms, key management detail, backup frequency, RTO/RPO figures or data retention periods.
- Penetration testing has no fixed cadence: "each distinct cloud service currently adheres to its own individual testing and evaluation schedule."
- Common Criteria is described as progress toward certification rather than a completed certification.
Risk Assessment Notes
**Inherent risk drivers**
- Citrix products sit on the access path to the whole desktop and application estate. DaaS brokers virtual desktops and published apps; NetScaler Gateway is the internet-facing front door for remote access; Endpoint Management holds mobile device and app management authority. Compromise gives an attacker a foothold with legitimate user context. Treat inherent risk as **high to critical** depending on which products are in use.
- **NetScaler has an exceptional adverse vulnerability record.** CVE-2019-19781, CVE-2023-4966 ("CitrixBleed") and CVE-2025-5777 ("CitrixBleed 2") were all mass-exploited session-hijack or RCE issues in internet-facing appliances, and CVE-2025-5349 and CVE-2025-6543 followed within days of CitrixBleed 2. This is a repeating pattern, not isolated bad luck.
- Session-token disclosure vulnerabilities specifically **bypass multi-factor authentication** and survive patching unless sessions are explicitly terminated. Standard patch-management assurance is not sufficient for this vendor.
- Corporate ownership churn: Citrix was taken private and merged into Cloud Software Group with TIBCO in 2022, and Arctera has since been folded in. Trust-centre URLs have moved, documentation is split across cloud.com, citrix.com, docs.citrix.com, netscaler.com and tibco.com, and certification scope is now defined at Cloud Software Group level across a much wider portfolio.
- Heavy reliance on a long list of US-based monitoring, analytics and CDN sub-processors, particularly for Intelligent Traffic Management.
**Mitigating factors**
- Genuinely detailed and specific public control documentation - the top 20 security FAQs and the Services Security Exhibit describe named policies, testing methods and governance roles rather than marketing generalities.
- Certification matrix is published **per product** with clear gaps shown, which makes honest scoping possible. Many vendors obscure this.
- Citrix DaaS carries the full set: SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0, IRAP and FedRAMP Moderate JAB authorisation.
- Vulnerability response is aligned to ISO/IEC 29147:2018 with a committed acknowledgement by end of the next working day, variant analysis to catch whole classes of issue, and coordinated disclosure for third-party findings.
- Active public bug bounty on HackerOne plus a PSIRT with a published PGP key.
- Customer-run penetration testing is explicitly permitted with a defined notification route.
- Due Diligence Package includes a Shared Assessments SIG self-attestation with supporting evidence - directly reusable in a TPRM workflow.
- Sub-processor changes are notifiable via RSS feed.
- Mature resilience programme: BIA-driven RTO/RPO, quarterly IT DR testing at a DR data centre, annual BC testing, dedicated full-time BC/IR team, follow-the-sun rerouting for support.
**Concerns to track**
- Confirm exactly which products you are buying and map them against the certification matrix. **Citrix Endpoint Management has no IRAP and no FedRAMP; only DaaS is FedRAMP Moderate; NetScaler Console has IRAP but no FedRAMP.** TIBCO and Arctera products carry far less.
- Anything hosted or self-managed by you (NetScaler appliances, on-premises Virtual Apps and Desktops) is outside the cloud certifications entirely. The SOC 2 and ISO scope is the cloud services.
- Sub-processor list has not been re-dated since 26 March 2025. Ask whether it is current.
- No published encryption specifics, backup frequency, RTO/RPO or retention periods - all must be obtained under NDA.
- Penetration testing cadence is per-service and undisclosed, and no third-party pen test report is available even under NDA on the public pages.
- Common Criteria status is aspirational rather than certified.
- Beta, lab and tech-preview services (including Cloud Labs) are **explicitly out of scope** of the Services Security Exhibit. Do not use them for regulated data.
- Neustar (application security for ITM and Citrix Analytics) publishes its sub-processor list only as a PDF and has itself changed ownership - worth a look if ITM is in scope.
**Residual customer responsibilities**
- Patch NetScaler ADC and Gateway on an emergency footing, and **terminate all active and persistent sessions after upgrading** whenever a session-token disclosure issue is fixed. This is the single most important control for this vendor.
- Subscribe to Citrix security bulletin alerts at https://support.citrix.com/user/alerts and to the sub-processor RSS feed.
- Restrict access to the NetScaler management interface (NSIP/cluster IP) to a management network - CVE-2025-5349 depended on management interface exposure.
- Sign the online NDA early: the Due Diligence Package, SOC 2 and IRAP reports all sit behind it and take 4-6 hours to become visible.
- Execute the DPA, and a BAA where PHI is involved, and confirm which Service Description and SLA apply.
- Do not place regulated data in beta or Cloud Labs environments.
- Coordinate any customer penetration testing through [email protected] in advance.
- Configure and monitor your own logging - ship Citrix Cloud and NetScaler logs to your SIEM rather than relying on vendor-side detection.
**Suggested review cadence:** semi-annual reassessment, with continuous monitoring of Citrix and NetScaler security bulletins. Any critical NetScaler Gateway or ADC advisory should trigger immediate out-of-cycle emergency patching and session termination regardless of where the review cycle sits.
Copyright © 2026 SnapGRC