Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 | Accredited third-party certification body | IBM Cloud services and supporting ISMS | — | — | Current |
| ISO/IEC 27017:2015 and ISO/IEC 27018:2019 | Accredited third-party certification body | Cloud security controls and protection of PII in public cloud for IBM Cloud | — | — | Current |
| ISO/IEC 27701:2019 | Accredited third-party certification body | Privacy information management system covering in-scope IBM services | — | — | Current |
| SOC 1 Type II and SOC 2 Type II | Independent third-party auditor | In-scope IBM Cloud services; reports available to customers under NDA | — | — | Current |
| PCI DSS | Qualified Security Assessor | In-scope IBM Cloud services | — | — | Current |
Compliance Frameworks
ISO/IEC 27001:2022
Full
Certification scope varies by IBM Cloud service - check the service description
SOC 2 Type 2
Full
GDPR 2016/679
Full
IBM acts as processor under its Data Processing Addendum; SCCs and UK IDTA available
PCI DSS v4.0
Partial
Applies to in-scope IBM Cloud services only
NIST Cybersecurity Framework
Partial
IBM maps its controls to NIST CSF
Copyright © 2026 SnapGRC