CrowdStrike
Cloud-native cybersecurity platform (Falcon) covering endpoint and cloud detection and response, identity protection, next-gen SIEM and threat intelligence.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 (including ISO/IEC 27017:2015) | Accredited third-party certification body | CrowdStrike information security management system and the Falcon platform | — | — | Current |
| ISO 22301:2019 | Accredited third-party certification body | Business continuity management system | — | — | Current |
| ISO/IEC 42001:2023 | Accredited third-party certification body | AI management system (CrowdStrike reports being among the first cybersecurity vendors certified) | — | — | Current |
| SOC 2 Type II - Falcon Platform | Independent third-party auditor | Security and availability trust services criteria; 2026 report issued July 2026 | — | — | Current |
| SOC 2 Type II - Corporate Operations | Independent third-party auditor | Security and availability trust services criteria for corporate operations | — | — | Current |
| SOC 2 Type I - Forensic Lab | Independent third-party auditor | CrowdStrike Forensic Lab | — | — | Current |
| PCI DSS v4.0.1 | Qualified Security Assessor | Falcon platform in-scope services | — | — | Current |
| CSA STAR Level 2 | Cloud Security Alliance / third-party auditor | Cloud Controls Matrix certification | — | — | Current |
| BSI C5 (Germany) | Independent German auditor | Cloud Computing Compliance Criteria Catalogue | — | — | Current |
| FedRAMP High | 3PAO / agency authorisation | CrowdStrike Falcon Platform for Government (authorised March 2025) | — | — | Current |
| GovRAMP | GovRAMP programme review | US state and local government offering | — | — | Current |
| Cyber Essentials (UK) | UK NCSC-accredited certification body | UK operations | — | — | Current |
| TISAX | ENX Association assessment | Automotive industry information security assessment exchange | — | — | Current |
| ENS (Spain - Esquema Nacional de Seguridad) | Spanish accredited certification body | Spanish public sector security framework | — | — | Current |
| EU-US Data Privacy Framework (incl. UK Extension and Swiss-US DPF) | US Department of Commerce self-certification | Personal data transfers from the EEA, UK and Switzerland to the US | — | — | Current |
| APEC CBPR and PRP / Global CBPR and PRP | APEC-recognised accountability agent | Cross-border privacy rules and privacy recognition for processors | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| Falcon platform application penetration testing, plus code analysis and vulnerability management as documented under App Security in the CrowdStrike Trust Center (date shown is the profile capture date) | Independent third-party security testing firms | Aug. 6, 2026 | Annual | On NDA |
Data Handling
Sub-processors
| Sub-processor | Purpose | Data Location | Trust Portal |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure hosting for the Falcon platform (listed under Infrastructure in the CrowdStrike Trust Center) | Per selected Falcon cloud region: United States, Germany, Australia, India | View ↗ |
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| July 19, 2024 | A faulty Falcon sensor Rapid Response Content update (Channel File 291) contained an out-of-bounds memory read that caused the Windows sensor to crash the operating system. A bug in the Content Validator allowed the problematic content to pass validation and it was pushed globally rather than progressively. | Approximately 8.5 million Windows hosts entered a blue-screen/boot loop, requiring manual or scripted remediation. Widespread global operational disruption to airlines, healthcare, financial services, broadcasters and retail. Not a security breach and no customer data was compromised. | Content reverted within roughly 78 minutes and remediation guidance, recovery tooling and a full Root Cause Analysis were published. Remediations included additional Content Validator test coverage, staged/canary rollout of Rapid Response Content, customer-controlled content update rings and inspection windows, enhanced error handling in the Content Interpreter, and independent third-party code and quality reviews. | Report ↗ |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| CrowdStrike Privacy Notice | Public | View ↗ |
| CrowdStrike Global Data Protection Agreement | Public | View ↗ |
| CrowdStrike Terms and Conditions | Public | View ↗ |
| Subprocessor change notification subscription | Public | View ↗ |
| Falcon Content Update Remediation and Guidance Hub (19 July 2024 RCA) | Public | View ↗ |
| Audit reports and certificates (SOC 2, ISO 27001/22301/42001, PCI DSS, C5) via Trust Center | On Request | View ↗ |
| Information security, business continuity and incident response policies via Trust Center | On Request | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- Terms of Service View ↗
- GDPR Representative EU/UK representative details are published in the CrowdStrike Privacy Notice; privacy enquiries via [email protected]. Self-certified to the EU-US DPF, UK Extension and Swiss-US DPF. Confirm contracting entity at contract stage.
- Lawful Basis Processor acting on documented customer instructions under the CrowdStrike Global Data Protection Agreement (Art. 28 GDPR). Legitimate interests relied on for security telemetry, threat detection and threat intelligence research necessary to deliver the service. International transfers rely on Standard Contractual Clauses and the EU-US Data Privacy Framework.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform HackerOne (hackerone.com/crowdstrike); [email protected] for open-source repositories
Trust Portal & Audit Evidence
**Trust portal:** [trust.crowdstrike.com](https://trust.crowdstrike.com) - SafeBase-hosted. A small number of documents are public (GDPR overview, data sovereignty whitepaper, SIG Core, CAIQ, HECVAT); SOC 2 reports, ISO certificates, PCI DSS AoC, C5, penetration test summaries and policy documents require an access request and NDA acceptance. Bulk download and update subscriptions are available.
**Self-assessments available:** CSA CAIQ, HECVAT, SIG Core (Falcon Platform).
**Sub-processors:** CrowdStrike maintains its sub-processor list in the Falcon support portal (customer sign-in required) and offers an email notification subscription for changes at [crowdstrike.com/en-us/legal/subprocessor-notification](https://www.crowdstrike.com/en-us/legal/subprocessor-notification/). Only the infrastructure provider (AWS) is recorded below; request the full list during onboarding.
**Recent trust centre updates:** SOC 2 reports refreshed July 2026; ISO/IEC 42001 certification announced January 2026; FedRAMP High authorisation March 2025; DORA assessment (Schellman) December 2024.
Risk Assessment Notes
**Inherent risk drivers**
- Kernel-level agent deployed across the endpoint estate, with the ability to affect availability of every host it protects - the 19 July 2024 event is the reference case.
- Highly privileged telemetry: process, file, network, identity and, depending on modules, log data from across the estate.
- Vendor-pushed content updates historically bypassed customer change control, creating an availability dependency outside the customer change window.
**Mitigating factors**
- Strong and unusually broad assurance for a security vendor: ISO 27001/27017/22301/42001, three separate SOC 2 reports, PCI DSS v4.0.1, C5, CSA STAR L2, FedRAMP High, TISAX, ENS, Cyber Essentials.
- Post-2024 remediations give customers control over sensor and content update rings, plus staged rollout and inspection windows.
- Documented DORA assessment, which matters where CrowdStrike is a critical ICT third-party provider in the EU.
**Controls to verify during assessment**
- Confirm sensor update policy uses N-1 or N-2 rings with staggered deployment across host groups, and that a documented rollback and manual recovery runbook exists (including BitLocker key availability).
- Confirm the Falcon cloud region matches data residency requirements, and check module-level telemetry retention against the retention policy.
- Obtain the current sub-processor list and the latest SOC 2 Type II report, and check the bridge letter covers the period since the report date.
- Where CrowdStrike is business-critical, capture it in the DORA/operational resilience register and test the exit plan.
**Suggested review cadence:** annual, with an interim review after any major sensor architecture change.
Copyright © 2026 SnapGRC