CrowdStrike

Cybersecurity United States Website Reviewed Aug. 6, 2026

Cloud-native cybersecurity platform (Falcon) covering endpoint and cloud detection and response, identity protection, next-gen SIEM and threat intelligence.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 (including ISO/IEC 27017:2015) Accredited third-party certification body CrowdStrike information security management system and the Falcon platform Current
ISO 22301:2019 Accredited third-party certification body Business continuity management system Current
ISO/IEC 42001:2023 Accredited third-party certification body AI management system (CrowdStrike reports being among the first cybersecurity vendors certified) Current
SOC 2 Type II - Falcon Platform Independent third-party auditor Security and availability trust services criteria; 2026 report issued July 2026 Current
SOC 2 Type II - Corporate Operations Independent third-party auditor Security and availability trust services criteria for corporate operations Current
SOC 2 Type I - Forensic Lab Independent third-party auditor CrowdStrike Forensic Lab Current
PCI DSS v4.0.1 Qualified Security Assessor Falcon platform in-scope services Current
CSA STAR Level 2 Cloud Security Alliance / third-party auditor Cloud Controls Matrix certification Current
BSI C5 (Germany) Independent German auditor Cloud Computing Compliance Criteria Catalogue Current
FedRAMP High 3PAO / agency authorisation CrowdStrike Falcon Platform for Government (authorised March 2025) Current
GovRAMP GovRAMP programme review US state and local government offering Current
Cyber Essentials (UK) UK NCSC-accredited certification body UK operations Current
TISAX ENX Association assessment Automotive industry information security assessment exchange Current
ENS (Spain - Esquema Nacional de Seguridad) Spanish accredited certification body Spanish public sector security framework Current
EU-US Data Privacy Framework (incl. UK Extension and Swiss-US DPF) US Department of Commerce self-certification Personal data transfers from the EEA, UK and Switzerland to the US Current
APEC CBPR and PRP / Global CBPR and PRP APEC-recognised accountability agent Cross-border privacy rules and privacy recognition for processors Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
ISO/IEC 27001:2022 certified ISMS, updated in 2025 to include ISO/IEC 27017:2015.
SOC 2 Type 2
Full
Separate SOC 2 Type II reports for the Falcon platform and corporate operations; latest issued July 2026.
PCI DSS v4.0
Full
PCI DSS v4.0.1 listed on the CrowdStrike Trust Center.
ISO 22301:2019
Full
ISO 22301:2019 certified business continuity management system, first issued 2025.
BSI C5
Full
BSI C5 attestation listed on the CrowdStrike Trust Center.
Cyber Essentials
Full
Cyber Essentials certification listed on the CrowdStrike Trust Center.
DORA
Full
DORA assessment completed with external auditor Schellman (December 2024); executive summary available in the Trust Center. Relevant where CrowdStrike is treated as a critical ICT third-party provider.
GDPR 2016/679
Full
CrowdStrike acts as processor under its Global Data Protection Agreement; transfers covered by SCCs and the EU-US DPF.
ACSC Essential Eight
Partial
CrowdStrike publishes a Falcon Platform for ACSC Essential Eight mapping whitepaper - product enablement rather than a certification of CrowdStrike itself.

Penetration Testing

Scope Conducted By Date Frequency Report
Falcon platform application penetration testing, plus code analysis and vulnerability management as documented under App Security in the CrowdStrike Trust Center (date shown is the profile capture date) Independent third-party security testing firms Aug. 6, 2026 Annual On NDA

Data Handling

Data Residency Regions
US-1 and US-2 (United States), EU-1 (Germany), AU-1 (Australia), IN-1 (India), US-GOV-1 and US-GOV-2 (US Government). Falcon cloud region is selected at tenant provisioning and hosted on Amazon Web Services.
Encryption at Rest
Yes — AES-256 encryption at rest for customer data in the Falcon platform; disk encryption and key management controls documented under Data Security and Endpoint Security in the Trust Center.
Encryption in Transit
Yes — TLS 1.2 or higher for sensor-to-cloud, API and console traffic. Trust Center reports a Qualys SSL Labs grade of A+ for the Falcon platform.
Backup Frequency
Documented under Data Security > Data Backups in the CrowdStrike Trust Center; detail is available under NDA rather than published.
Retention Policy
Data Deletion
Data erasure controls are documented in the Trust Center. Deletion or return of customer data on termination is governed by the CrowdStrike Global Data Protection Agreement; retention periods for telemetry vary by module and subscription (for example Falcon Next-Gen SIEM retention tiers).

Sub-processors

Sub-processor Purpose Data Location Trust Portal
Amazon Web Services (AWS) Cloud infrastructure hosting for the Falcon platform (listed under Infrastructure in the CrowdStrike Trust Center) Per selected Falcon cloud region: United States, Germany, Australia, India View ↗

Incident & Breach History

Date Summary Impact Resolution Report
July 19, 2024 A faulty Falcon sensor Rapid Response Content update (Channel File 291) contained an out-of-bounds memory read that caused the Windows sensor to crash the operating system. A bug in the Content Validator allowed the problematic content to pass validation and it was pushed globally rather than progressively. Approximately 8.5 million Windows hosts entered a blue-screen/boot loop, requiring manual or scripted remediation. Widespread global operational disruption to airlines, healthcare, financial services, broadcasters and retail. Not a security breach and no customer data was compromised. Content reverted within roughly 78 minutes and remediation guidance, recovery tooling and a full Root Cause Analysis were published. Remediations included additional Content Validator test coverage, staged/canary rollout of Rapid Response Content, customer-controlled content update rings and inspection windows, enhanced error handling in the Content Interpreter, and independent third-party code and quality reviews. Report ↗

Security Policies

Policy Availability Link
CrowdStrike Privacy Notice Public View ↗
CrowdStrike Global Data Protection Agreement Public View ↗
CrowdStrike Terms and Conditions Public View ↗
Subprocessor change notification subscription Public View ↗
Falcon Content Update Remediation and Guidance Hub (19 July 2024 RCA) Public View ↗
Audit reports and certificates (SOC 2, ISO 27001/22301/42001, PCI DSS, C5) via Trust Center On Request View ↗
Information security, business continuity and incident response policies via Trust Center On Request View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Trust portal:** [trust.crowdstrike.com](https://trust.crowdstrike.com) - SafeBase-hosted. A small number of documents are public (GDPR overview, data sovereignty whitepaper, SIG Core, CAIQ, HECVAT); SOC 2 reports, ISO certificates, PCI DSS AoC, C5, penetration test summaries and policy documents require an access request and NDA acceptance. Bulk download and update subscriptions are available.

**Self-assessments available:** CSA CAIQ, HECVAT, SIG Core (Falcon Platform).

**Sub-processors:** CrowdStrike maintains its sub-processor list in the Falcon support portal (customer sign-in required) and offers an email notification subscription for changes at [crowdstrike.com/en-us/legal/subprocessor-notification](https://www.crowdstrike.com/en-us/legal/subprocessor-notification/). Only the infrastructure provider (AWS) is recorded below; request the full list during onboarding.

**Recent trust centre updates:** SOC 2 reports refreshed July 2026; ISO/IEC 42001 certification announced January 2026; FedRAMP High authorisation March 2025; DORA assessment (Schellman) December 2024.

Risk Assessment Notes

**Inherent risk drivers**

- Kernel-level agent deployed across the endpoint estate, with the ability to affect availability of every host it protects - the 19 July 2024 event is the reference case.
- Highly privileged telemetry: process, file, network, identity and, depending on modules, log data from across the estate.
- Vendor-pushed content updates historically bypassed customer change control, creating an availability dependency outside the customer change window.

**Mitigating factors**

- Strong and unusually broad assurance for a security vendor: ISO 27001/27017/22301/42001, three separate SOC 2 reports, PCI DSS v4.0.1, C5, CSA STAR L2, FedRAMP High, TISAX, ENS, Cyber Essentials.
- Post-2024 remediations give customers control over sensor and content update rings, plus staged rollout and inspection windows.
- Documented DORA assessment, which matters where CrowdStrike is a critical ICT third-party provider in the EU.

**Controls to verify during assessment**

- Confirm sensor update policy uses N-1 or N-2 rings with staggered deployment across host groups, and that a documented rollback and manual recovery runbook exists (including BitLocker key availability).
- Confirm the Falcon cloud region matches data residency requirements, and check module-level telemetry retention against the retention policy.
- Obtain the current sub-processor list and the latest SOC 2 Type II report, and check the bridge letter covers the period since the report date.
- Where CrowdStrike is business-critical, capture it in the DORA/operational resilience register and test the exit plan.

**Suggested review cadence:** annual, with an interim review after any major sensor architecture change.

Assess CrowdStrike in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.