Cloudflare

Cloud & Infrastructure United States Website Reviewed Sept. 2, 2026

CDN, DNS, WAF, DDoS protection and Zero Trust access services sitting in front of customer web applications.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited third-party certification body Cloudflare global network and supporting ISMS Current
ISO/IEC 27018:2019 and ISO/IEC 27701:2019 Accredited third-party certification body Protection of PII in public cloud and privacy information management for Cloudflare services Current
SOC 2 Type II Independent third-party auditor Cloudflare services; report available to customers under NDA Current
PCI DSS Level 1 Service Provider Qualified Security Assessor Cloudflare CDN and WAF as a service provider in customer cardholder data environments Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
PCI DSS v4.0
Full
PCI DSS Level 1 service provider
GDPR 2016/679
Full
Cloudflare acts as processor under its DPA; SCCs, UK IDTA and EU data localisation options available
NIS2 Directive
Partial
Relevant where Cloudflare supports NIS2 in-scope customer services

Assess Cloudflare in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.