CyberArk
Privileged access management, secrets management and identity security for human and machine identities.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001 | Accredited third-party certification body | CyberArk Identity Security Platform and supporting ISMS | — | — | Current |
| ISO 27017 and ISO 27018 | Accredited third-party certification body | Cloud security controls and protection of PII in public cloud | — | — | Current |
| SOC 2 Type II | Independent third-party auditor | CyberArk SaaS services; report available to customers under NDA | — | — | Current |
| FedRAMP | US federal authorising body | CyberArk offerings authorised for US federal use | — | — | Current |
Compliance Frameworks
ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
GDPR 2016/679
Full
EU and UK data regions available; processor under its DPA
CIS V8
Partial
Supports CIS Control 5 and 6 privileged account management
NIST Cybersecurity Framework
Partial
Commonly mapped to NIST CSF protect function
Copyright © 2026 SnapGRC