IBM

Cloud & Infrastructure United States Website Reviewed Sept. 2, 2026

IBM Cloud, watsonx AI, and IBM managed infrastructure and consulting services.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited third-party certification body IBM Cloud services and supporting ISMS Current
ISO/IEC 27017:2015 and ISO/IEC 27018:2019 Accredited third-party certification body Cloud security controls and protection of PII in public cloud for IBM Cloud Current
ISO/IEC 27701:2019 Accredited third-party certification body Privacy information management system covering in-scope IBM services Current
SOC 1 Type II and SOC 2 Type II Independent third-party auditor In-scope IBM Cloud services; reports available to customers under NDA Current
PCI DSS Qualified Security Assessor In-scope IBM Cloud services Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
Certification scope varies by IBM Cloud service - check the service description
SOC 2 Type 2
Full
GDPR 2016/679
Full
IBM acts as processor under its Data Processing Addendum; SCCs and UK IDTA available
PCI DSS v4.0
Partial
Applies to in-scope IBM Cloud services only
NIST Cybersecurity Framework
Partial
IBM maps its controls to NIST CSF

Assess IBM in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.