Citrix (Cloud Software Group)

Cloud & Infrastructure United States Website Reviewed Aug. 6, 2026

Citrix portfolio from Cloud Software Group - DaaS, NetScaler, Endpoint Management and Secure Private Access.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
SOC 2 Type 2 Independent third-party CPA firm 2025 Citrix Cloud Based Services SOC 2 report. Covers Citrix Desktop as a Service (DaaS), Citrix Endpoint Management (CEM) and NetScaler Console / Application Delivery Management (ADM). Report access requires a signed online NDA. Current
ISO/IEC 27001:2022 Accredited certification body Citrix ISO 27001+27701:2022 certificate. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). Separate certificates exist for TIBCO and TIBCO EBX. Current
ISO/IEC 27701:2022 Accredited certification body Privacy Information Management System, issued as a combined ISO 27001+27701:2022 certificate. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). Current
HIPAA Letter of Assessment Independent third-party assessor CSG (Citrix Platform) 2025 HIPAA Letter of Assessment. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). NOT held for any TIBCO or Arctera product. Current
PCI DSS v4.0 Qualified Security Assessor (QSA) 2025 Citrix Cloud Platform PCI DSS attestation. Covers Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). NOT held for TIBCO or Arctera products. Current
IRAP Assessment ASD-endorsed IRAP assessor 2025 Citrix Cloud IRAP Security Assessment Report (SAR). Covers Citrix DaaS and NetScaler Console (ADM) ONLY - Citrix Endpoint Management is NOT in the IRAP scope. Report access requires a signed NDA. Current
FedRAMP Moderate (JAB Authorization) FedRAMP PMO / Joint Authorization Board Citrix Desktop as a Service (DaaS) ONLY. Citrix Endpoint Management, NetScaler Console, all TIBCO products and Arctera are NOT FedRAMP authorised. Current
FIPS 140-2 NIST/CSE Cryptographic Module Validation Program Cryptographic module compliance for selected Citrix products; see the FIPS 140-2 compliance page for the per-product list. FIPS 140-2 has been superseded by FIPS 140-3. Current
Common Criteria (ISO/IEC 15408) Common Criteria certification scheme Cloud Software Group describes itself as making "progress in attaining" Common Criteria certification; check the Common Criteria Certification Information page for the exact certified product versions and Evaluation Assurance Levels. In Progress
Section 508 / WCAG 2.1 (VPAT) Self-assessment Accessibility conformance documentation. High-priority usability and accessibility initiatives described rather than a blanket conformance claim. Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
Citrix ISO 27001+27701:2022 certificate covering Citrix DaaS, Citrix Endpoint Management and NetScaler Console (ADM). The corporate security framework is explicitly built on ISO 27001/27002.
ISO 27002
Partial
ISO 27002 controls are named as part of the security and compliance framework alongside ISO 27001, but there is no separate ISO 27002 attestation.
SOC 2 Type 2
Full
2025 Citrix Cloud Based Services SOC 2 Type 2 report covering DaaS, CEM and NetScaler Console. NDA required. Separate SOC 2 reports exist for TIBCO Platform, TIBCO Scribe and Arctera Insights.
PCI DSS v4.0
Full
2025 Citrix Cloud Platform PCI DSS v4.0 attestation covering DaaS, CEM and NetScaler Console. Does not extend to TIBCO or Arctera products.
HIPAA Security
Full
2025 CSG (Citrix Platform) HIPAA Letter of Assessment covering DaaS, CEM and NetScaler Console. Confirm a BAA is executed before placing PHI in scope.
NIST Cybersecurity Framework
Partial
NIST SP 800-53 controls are named as part of the corporate security framework and FedRAMP Moderate JAB authorisation is held for Citrix DaaS. No standalone NIST CSF attestation is published.
CIS V8
Partial
CIS standards are explicitly named as one of the three control suites underpinning the security and compliance framework, but no CIS benchmark attestation is published.

Penetration Testing

Scope Conducted By Date Frequency Report
Qualified external assessors plus an internal security testing team perform threat modelling, vulnerability scanning and penetration testing of the cloud services. Each distinct cloud service follows its own individual testing and evaluation schedule, and every cloud service release requires a security assessment by the internal testing team beforehand. Independent parties are contracted where certifications require it. (date = profile capture date) Qualified external assessors (unnamed) plus the Cloud Software Group internal Engineering Security Team Aug. 6, 2026 Ad-hoc On NDA
Customer-run penetration testing against their own Citrix Cloud environment is permitted but must be coordinated in advance so other tenants are not affected. Prior notice is submitted by email to [email protected] and the submitter must confirm authority to accept the Customer Penetration Test Requirements on the customer’s behalf. (date = profile capture date) Customer or customer-appointed tester, subject to Cloud Software Group Customer Penetration Test Requirements Aug. 6, 2026 Ad-hoc Not Available

Data Handling

Data Residency Regions
Citrix Cloud control planes and services run on Microsoft Azure and AWS with region selection varying by service. Named sub-processor hosting is predominantly United States, with NetActuate in the US and Poland and Pendo offices in Israel, Japan and the UK. Citrix Cloud Government is a separate US-only offering with its own sub-processor list. Confirm exact region and residency options for your service in the Citrix product documentation and Service Description.
Encryption at Rest
Yes — Encryption controls are set out in the Cloud Software Group Services Security Exhibit (current edition April 2026) and the Information Classification and Handling policy, whose control matrix defines required controls for data both in motion and at rest. Specific algorithms and key management are not published on the trust centre - request the Exhibit and the Due Diligence Package.
Encryption in Transit
Yes — Covered by the Services Security Exhibit and the data-in-motion controls of the Information Classification and Handling matrix. Remote network access requires TOTP multi-factor authentication; production machine access requires a VPN configuration file plus separate VPN and production credentials.
Backup Frequency
Not published as a fixed figure. RTO and RPO are calculated per asset from the Business Impact Analysis. The IT Disaster Recovery Plan is tested quarterly with restoration of critical production processing at the DR data centre; BC plans tested annually.
Retention Policy
Data Deletion
No public retention or deletion periods. Commitments sit in the Cloud Software Group Data Processing Addendum and the Services Security Exhibit, with per-product detail in the Service Descriptions and product privacy data sheets (TIBCO Platform, Spotfire, Citrix DaaS). Asset end-of-life is governed by an assigned sunset date under the Asset Management Policy. GAP: obtain written retention and deletion periods for your service during assessment.

Sub-processors

Sub-processor Purpose Data Location Trust Portal
Akamai Technologies, Inc. CDN, connectivity monitoring, logging and analytics | Citrix services: Citrix Workspace app (Receiver), DaaS United States View ↗
Amazon Web Services (AWS) Machine learning service | Citrix services: ShareFile, DaaS, Citrix Gateway Service / Secure Private Access United States View ↗
Duo Security (affiliate of Cisco) Security and authentication services | Citrix services: Intelligent Traffic Management (ITM) United States View ↗
Firebase (Google Cloud Platform) Traffic and event analysis | Citrix services: DaaS, Citrix Gateway Service / Secure Private Access United States View ↗
Functional Software, Inc. (dba Sentry) Monitor logs and events | Citrix services: DaaS, ShareFile, Citrix Gateway Service / Secure Private Access United States View ↗
Google Analytics Traffic and event analysis | Citrix services: DaaS United States View ↗
Google Chronicle Security monitoring, logging and analytics | Citrix services: Cloud Operations United States View ↗
Google Cloud Platform Traffic logging and analysis | Citrix services: ShareFile, ITM, DaaS, Citrix Gateway Service / Secure Private Access United States View ↗
Google Maps Platform Geographic map rendering of usage locations | Citrix services: NetScaler Console / ADM United States View ↗
Grafana Cloud (Raintank Inc. d/b/a Grafana Labs) Monitoring and logging | Citrix services: Cloud Operations United States View ↗
NetActuate, Inc. (formerly Host Virtual, Inc.) Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) United States, Poland View ↗
Microsoft Storage and diagnostics | Citrix services: ITM, DaaS, CEM, Citrix Gateway Service / SPA, Cloud Operations, NetScaler Console (ADM) United States View ↗
Neustar Application security | Citrix services: ITM, Citrix Analytics Service (CAS) United States
New Relic, Inc. Connectivity monitoring, logging and analytics | Citrix services: Cloud Operations, ITM United States View ↗
Pendo.io In-app communications and analytics | Citrix services: DaaS United States (offices Israel, Japan, United Kingdom) View ↗
SendGrid (Twilio Inc.) Email service provider | Citrix services: ShareFile, DaaS, CEM United States, Ireland View ↗
Splunk Inc. Security monitoring, logging and analytics | Citrix services: Cloud Operations United States View ↗
Zenlayer, Inc. (formerly C3Networks Inc.) Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) United States View ↗
Equinix Services, Inc. Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) United States View ↗
Datadog, Inc. Connectivity monitoring, logging and analytics | Citrix services: Intelligent Traffic Management (ITM) United States View ↗
Catchpoint Systems, Inc. Connectivity monitoring and analytics | Citrix services: Intelligent Traffic Management (ITM) United States View ↗

Incident & Breach History

Date Summary Impact Resolution Report
Oct. 10, 2023 "CitrixBleed" - CVE-2023-4966 (sensitive information disclosure) and CVE-2023-4967 (denial of service) in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway. CVE-2023-4966 allowed an unauthenticated attacker to leak session tokens from appliance memory and hijack authenticated sessions, bypassing multi-factor authentication. Exploited in the wild before and after disclosure and used for ransomware and espionage intrusions across many organisations globally. Affects customer-managed NetScaler appliances rather than the Citrix Cloud control plane, so remediation depended on customers patching. Session hijacking meant patching alone was insufficient. Fixed builds released 10 October 2023 under Security Bulletin CTX579459. Because valid session tokens could survive patching, Citrix additionally instructed customers to terminate all active and persistent sessions after upgrading. Affected versions and required builds are listed in the bulletin. Report ↗
June 17, 2025 "CitrixBleed 2" - CVE-2025-5777 (out-of-bounds memory read allowing session token disclosure) and CVE-2025-5349 (improper access control on the NetScaler management interface, CVSS 8.7) in NetScaler ADC and NetScaler Gateway. A further critical issue, CVE-2025-6543, was disclosed on 25 June 2025. Affects customer-managed NetScaler ADC and Gateway appliances. National cyber security centres in New Zealand, Canada, the UK (NHS England) and elsewhere issued alerts, and CVE-2025-5777 was subsequently reported as exploited. Not a compromise of Cloud Software Group corporate or Citrix Cloud systems. Security Bulletin CTX693420 published 17 June 2025 with fixed builds; a further advisory followed on 25 June 2025 for CVE-2025-6543. Customers must upgrade affected appliances and, as with CitrixBleed, terminate existing sessions. Remediation guidance is also published in the NetScaler Console instance advisory. Report ↗

Security Policies

Policy Availability Link
Information Security Policy On Request View ↗
Acceptable Use Policy (AUP) On Request View ↗
Access Management Policy On Request View ↗
Password Policy On Request View ↗
Asset Management Policy On Request View ↗
Information Classification and Handling Policy (with control matrix) On Request View ↗
Cybersecurity Risk Management Standard On Request View ↗
Physical Security and Control of Entry Policy On Request View ↗
Business Continuity and Disaster Recovery Programme (incl. Business Impact Analysis) On Request View ↗
Incident Response Plan and Incident Response Standard On Request View ↗
Third-Party Management Policy and Supplier Security Standards On Request View ↗
Software Development Lifecycle (SDLC) Policy On Request View ↗
Vulnerability and Patch Management Policy On Request View ↗
Services Security Exhibit (April 2026 edition) Public View ↗
Code of Business Conduct Public View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Important:** Citrix is a business unit of **Cloud Software Group**, alongside TIBCO, Spotfire, NetScaler and Arctera. The old https://www.citrix.com/trust-center/ URL now 404s; the live trust centre is at **https://www.cloud.com/trust-center**, reachable via https://www.citrix.com/about/trust-center.html. Certifications are held **per product**, not per company, and the Citrix, TIBCO and Arctera product sets have materially different coverage.

**Per-product certification matrix as published (August 2026)**

*Citrix products*
- Citrix DaaS: SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0, IRAP, FedRAMP Moderate JAB - the only fully covered product
- Citrix Endpoint Management (CEM): SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0. **No IRAP, no FedRAMP**
- NetScaler Console / Application Delivery Management (ADM): SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0, IRAP. **No FedRAMP**

*TIBCO products (for context - not covered by this profile)*
- TIBCO Platform: SOC 2 Type 2, ISO 27001, ISO 27701 only
- TIBCO Scribe: SOC 2 Type 2 only
- TIBCO EBX: ISO 27001 only

*Arctera*
- Arctera Insights Platform: SOC 2 Type 2 only

**Publicly available without NDA**
- Certification matrix: https://www.cloud.com/trust-center/certifications
- Downloadable certificates: Citrix ISO 27001+27701:2022, TIBCO ISO 27001+27701:2022, TIBCO EBX ISO 27001+27701:2022, CSG (Citrix Platform) 2025 HIPAA Letter of Assessment, 2025 Citrix Cloud Platform PCI DSS, 2025 Citrix Cloud IRAP SAR
- Top 20 security FAQs (unusually detailed control descriptions): https://www.cloud.com/trust-center/faqs
- Security assurance and customer penetration testing rules: https://www.cloud.com/trust-center/security-assurance
- Vulnerability response process (ISO/IEC 29147:2018) and bug bounty: https://www.cloud.com/trust-center/product-security/vulnerability-response
- Services Security Exhibit (April 2026), End User Agreement, DPA, Partner DPA, Service Descriptions, SLAs, Code of Business Conduct: https://www.cloud.com/trust-center/agreements
- Sub-processor and affiliate list with an RSS change feed: https://www.cloud.com/trust-center/sub-processor-list-rss
- External AI Transparency Notice and product privacy / AI governance data sheets for TIBCO Platform, Spotfire and Citrix DaaS
- Status dashboards: https://status.cloud.com and https://status.cloud.tibco.com

**Gated behind a signed online NDA**
- SOC 2 Type 2 reports (all products) and the IRAP audit report
- Due Diligence Package, including the Shared Assessments **SIG self-attestation questionnaire** and supporting evidence
- Penetration test results
Note: NDAs are signed online through My Account and take 4-6 hours to propagate to back-office systems before documents become visible.

**Sub-processor list structure**
The published list is dated **26 March 2025** and is segmented into: Citrix Cloud sub-processors (recorded in this profile); Citrix sub-processors used for support services; Citrix Cloud **Government** sub-processors; Citrix Cloud Government support services sub-processors; TIBCO Platform sub-processors; TIBCO support services sub-processors; Cloud Software Group affiliates by country; and Citrix DaaS sub-processors. Only the Citrix Cloud list is captured here - review the support-services and Government lists separately if they apply to you.

**Documented corporate controls of note**
Full-time CISO with a Security and Trust Organisation, and a Chief Privacy Officer heading the Privacy team. Framework built on ISO 27001/27002, NIST SP 800-53 and CIS, reviewed at least annually. Least-privilege access provisioning with management approval and quarterly access reviews. MFA for remote network access and cloud consoles; production machine access needs a VPN config file plus separate VPN and production credentials. Risk-rated asset inventory with owners, labels and sunset dates. Business Impact Analysis driving RTO/RPO, quarterly technology drills, annual business function exercises, quarterly IT DR testing at a DR data centre, annual table-top exercises. CSIRT led by Security with Legal managing incident communications; customer notification within the period required by applicable law. Third-Party Risk Management programme with periodic supplier reassessment and Supplier Security Standards. Secure-by-design SDLC with threat modelling, design and code reviews, exploit development, cloud hardening tests, fuzzing, assisted source review, and CWE Top 25 / OWASP Top 10 assessment. SIEM ingestion from public-cloud hosted components with alerting and correlation.

**Gaps noted at review**
- Sub-processor list is dated 26 March 2025, roughly 16 months before this review.
- No published encryption algorithms, key management detail, backup frequency, RTO/RPO figures or data retention periods.
- Penetration testing has no fixed cadence: "each distinct cloud service currently adheres to its own individual testing and evaluation schedule."
- Common Criteria is described as progress toward certification rather than a completed certification.

Risk Assessment Notes

**Inherent risk drivers**
- Citrix products sit on the access path to the whole desktop and application estate. DaaS brokers virtual desktops and published apps; NetScaler Gateway is the internet-facing front door for remote access; Endpoint Management holds mobile device and app management authority. Compromise gives an attacker a foothold with legitimate user context. Treat inherent risk as **high to critical** depending on which products are in use.
- **NetScaler has an exceptional adverse vulnerability record.** CVE-2019-19781, CVE-2023-4966 ("CitrixBleed") and CVE-2025-5777 ("CitrixBleed 2") were all mass-exploited session-hijack or RCE issues in internet-facing appliances, and CVE-2025-5349 and CVE-2025-6543 followed within days of CitrixBleed 2. This is a repeating pattern, not isolated bad luck.
- Session-token disclosure vulnerabilities specifically **bypass multi-factor authentication** and survive patching unless sessions are explicitly terminated. Standard patch-management assurance is not sufficient for this vendor.
- Corporate ownership churn: Citrix was taken private and merged into Cloud Software Group with TIBCO in 2022, and Arctera has since been folded in. Trust-centre URLs have moved, documentation is split across cloud.com, citrix.com, docs.citrix.com, netscaler.com and tibco.com, and certification scope is now defined at Cloud Software Group level across a much wider portfolio.
- Heavy reliance on a long list of US-based monitoring, analytics and CDN sub-processors, particularly for Intelligent Traffic Management.

**Mitigating factors**
- Genuinely detailed and specific public control documentation - the top 20 security FAQs and the Services Security Exhibit describe named policies, testing methods and governance roles rather than marketing generalities.
- Certification matrix is published **per product** with clear gaps shown, which makes honest scoping possible. Many vendors obscure this.
- Citrix DaaS carries the full set: SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA, PCI DSS v4.0, IRAP and FedRAMP Moderate JAB authorisation.
- Vulnerability response is aligned to ISO/IEC 29147:2018 with a committed acknowledgement by end of the next working day, variant analysis to catch whole classes of issue, and coordinated disclosure for third-party findings.
- Active public bug bounty on HackerOne plus a PSIRT with a published PGP key.
- Customer-run penetration testing is explicitly permitted with a defined notification route.
- Due Diligence Package includes a Shared Assessments SIG self-attestation with supporting evidence - directly reusable in a TPRM workflow.
- Sub-processor changes are notifiable via RSS feed.
- Mature resilience programme: BIA-driven RTO/RPO, quarterly IT DR testing at a DR data centre, annual BC testing, dedicated full-time BC/IR team, follow-the-sun rerouting for support.

**Concerns to track**
- Confirm exactly which products you are buying and map them against the certification matrix. **Citrix Endpoint Management has no IRAP and no FedRAMP; only DaaS is FedRAMP Moderate; NetScaler Console has IRAP but no FedRAMP.** TIBCO and Arctera products carry far less.
- Anything hosted or self-managed by you (NetScaler appliances, on-premises Virtual Apps and Desktops) is outside the cloud certifications entirely. The SOC 2 and ISO scope is the cloud services.
- Sub-processor list has not been re-dated since 26 March 2025. Ask whether it is current.
- No published encryption specifics, backup frequency, RTO/RPO or retention periods - all must be obtained under NDA.
- Penetration testing cadence is per-service and undisclosed, and no third-party pen test report is available even under NDA on the public pages.
- Common Criteria status is aspirational rather than certified.
- Beta, lab and tech-preview services (including Cloud Labs) are **explicitly out of scope** of the Services Security Exhibit. Do not use them for regulated data.
- Neustar (application security for ITM and Citrix Analytics) publishes its sub-processor list only as a PDF and has itself changed ownership - worth a look if ITM is in scope.

**Residual customer responsibilities**
- Patch NetScaler ADC and Gateway on an emergency footing, and **terminate all active and persistent sessions after upgrading** whenever a session-token disclosure issue is fixed. This is the single most important control for this vendor.
- Subscribe to Citrix security bulletin alerts at https://support.citrix.com/user/alerts and to the sub-processor RSS feed.
- Restrict access to the NetScaler management interface (NSIP/cluster IP) to a management network - CVE-2025-5349 depended on management interface exposure.
- Sign the online NDA early: the Due Diligence Package, SOC 2 and IRAP reports all sit behind it and take 4-6 hours to become visible.
- Execute the DPA, and a BAA where PHI is involved, and confirm which Service Description and SLA apply.
- Do not place regulated data in beta or Cloud Labs environments.
- Coordinate any customer penetration testing through [email protected] in advance.
- Configure and monitor your own logging - ship Citrix Cloud and NetScaler logs to your SIEM rather than relying on vendor-side detection.

**Suggested review cadence:** semi-annual reassessment, with continuous monitoring of Citrix and NetScaler security bulletins. Any critical NetScaler Gateway or ADC advisory should trigger immediate out-of-cycle emergency patching and session termination regardless of where the review cycle sits.

Assess Citrix (Cloud Software Group) in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.