Microsoft

Cloud & Infrastructure United States Website Reviewed Aug. 6, 2026

Global software and cloud provider (Azure, Microsoft 365, Dynamics 365, Power Platform, Intune, Defender) serving enterprise and public sector customers.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 BSI (accredited certification body) Azure, Microsoft 365, Dynamics 365, Power Platform, Intune and other in-scope online services Current
ISO/IEC 27017:2015 BSI Cloud-specific information security controls for in-scope online services Current
ISO/IEC 27018:2019 BSI Protection of PII in public cloud for in-scope online services Current
ISO/IEC 27701:2019 BSI Privacy information management system for in-scope online services Current
ISO 22301:2019 BSI Business continuity management system Current
ISO 9001:2015 BSI Quality management system Current
ISO/IEC 20000-1 BSI IT service management system Current
ISO/IEC 42001:2023 Independent certification body AI management system for in-scope AI services Current
SOC 1 / SOC 2 / SOC 3 Independent third-party auditor In-scope online services; SOC 2 Type II covering security, availability, confidentiality and privacy Current
PCI DSS (Level 1 Service Provider) Qualified Security Assessor Azure and in-scope services supporting cardholder data environments Current
FedRAMP High / DoD SRG IL2-IL5 3PAO, JAB and agency authorisations Azure Government, Azure Commercial and Microsoft 365 Government Current
HITRUST CSF HITRUST authorised external assessor Azure and in-scope healthcare workloads Current
CSA STAR Certification and Attestation Cloud Security Alliance / third-party auditor Cloud Controls Matrix; STAR Level 2 certification and attestation Current
BSI C5 (Germany) Independent German auditor Cloud Computing Compliance Criteria Catalogue for in-scope services Current
Cyber Essentials Plus (UK) UK NCSC-accredited certification body UK-relevant in-scope Microsoft services Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
ISO/IEC 27001 certified; certificates and scope statements published on the Service Trust Portal.
SOC 2 Type 2
Full
SOC 2 Type II reports issued on a rolling basis; available via the Service Trust Portal.
PCI DSS v4.0
Full
PCI DSS Level 1 Service Provider AoC for Azure; customer remains responsible for in-scope workload configuration.
ISO 22301:2019
Full
ISO 22301 certified business continuity management system.
ISO 9001:2015
Full
ISO 9001 quality management certification.
BSI C5
Full
BSI C5 attestation covering in-scope online services in Germany.
GDPR 2016/679
Full
Microsoft acts as processor under the Products and Services DPA; SCCs, EU-US DPF and EU Data Boundary support transfers.
HIPAA Security
Full
HIPAA/HITECH covered by the Microsoft HIPAA Business Associate Agreement for in-scope services.
NIST Cybersecurity Framework
Full
NIST CSF alignment and mapping published by Microsoft; not a certification in itself.
Cyber Essentials
Full
Cyber Essentials Plus certification held for UK-relevant services.
CIS V8
Partial
CIS Benchmarks published for Azure and Microsoft 365; implementation is a customer responsibility.

Penetration Testing

Scope Conducted By Date Frequency Report
Microsoft online services and supporting infrastructure - continuous internal red team exercises plus independent assessment under the SOC 2, ISO 27001 and FedRAMP programmes (date shown is the profile capture date) Microsoft red teams and independent third-party assessors Aug. 6, 2026 Annual On NDA
Customer security testing of its own Microsoft online assets, permitted under the Microsoft Security Testing Rules of Engagement (date shown is the profile capture date) Customer or customer-appointed testing provider Aug. 6, 2026 Ad-hoc Not Available

Data Handling

Data Residency Regions
US, Canada, Brazil, Mexico, Chile, UK, Ireland, Netherlands, Germany, France, Switzerland, Norway, Sweden, Denmark, Finland, Poland, Italy, Spain, Austria, Greece, Israel, UAE, Qatar, Saudi Arabia, South Africa, India, Japan, South Korea, Taiwan, Australia, New Zealand, Singapore, Indonesia, Malaysia; EU Data Boundary for EU/EFTA customer data; China operated separately by 21Vianet
Encryption at Rest
Yes — AES-256 by default. BitLocker and Distributed Key Manager for Microsoft 365, Storage Service Encryption for Azure, TDE for SQL. Customer-managed keys via Azure Key Vault and Managed HSM (FIPS 140-2 Level 3); Customer Key and Double Key Encryption available for Microsoft 365.
Encryption in Transit
Yes — TLS 1.2 minimum with TLS 1.3 supported. MACsec (IEEE 802.1AE) encryption on Microsoft WAN links between datacentres. Private connectivity via Azure Private Link and ExpressRoute.
Backup Frequency
Service-dependent and customer-configurable via Azure Backup and Azure Site Recovery. Microsoft 365 maintains multiple redundant, geo-replicated copies; retention governed by customer-configured retention policies.
Retention Policy
Data Deletion
On termination or expiry of a subscription, customer data is held in a limited-function account for a 90-day retention period. Microsoft then disables the account and deletes customer data including cached and backup copies, within a further 90 days for in-scope services. Decommissioned storage media are purged or destroyed in line with NIST 800-88.

Incident & Breach History

Date Summary Impact Resolution Report
March 2, 2021 On-premises Microsoft Exchange Server zero-day vulnerabilities (later known as ProxyLogon) were exploited in the wild by a state-sponsored actor Microsoft tracks as Hafnium, and subsequently by other groups. Widespread compromise of internet-facing on-premises Exchange servers globally; Exchange Online was not affected. Out-of-band security updates released, mitigation tooling and one-click remediation scripts published, and detection guidance issued with government agencies.
July 11, 2023 A China-based actor Microsoft tracks as Storm-0558 used an acquired Microsoft account consumer signing key to forge authentication tokens and access Outlook Web Access and Exchange Online mailboxes. Unauthorised access to email belonging to approximately 25 organisations, including government agencies, over roughly a month before detection. The signing key was revoked and key management, token issuance and validation hardened. Detailed cloud audit logging was subsequently made available to all customers at no additional cost. The incident was reviewed by the US Cyber Safety Review Board.
Jan. 12, 2024 A nation-state actor Microsoft tracks as Midnight Blizzard (Nobelium/APT29) used a password spray attack against a legacy non-production test tenant account without MFA, then pivoted to a small percentage of Microsoft corporate email accounts. Exfiltration of some Microsoft corporate email and attachments, including correspondence with a number of customers; some source code repositories and internal systems were also accessed. Legacy tenants and accounts remediated, MFA and detection controls strengthened, and the Secure Future Initiative accelerated. Affected customers were notified directly.

Security Policies

Policy Availability Link
Microsoft Privacy Statement Public View ↗
Microsoft Product Terms (including Data Protection Terms) Public View ↗
Microsoft Products and Services Data Protection Addendum (DPA) Public View ↗
Microsoft Security Response Center - Coordinated Vulnerability Disclosure Public View ↗
Microsoft Security Testing Rules of Engagement Public View ↗
Shared responsibility in the cloud Public View ↗
Audit reports (SOC, ISO, PCI DSS, C5) via Service Trust Portal On Request View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Trust portal:** [Microsoft Service Trust Portal](https://servicetrust.microsoft.com/) - hosts SOC 1/2/3 reports, ISO certificates, PCI DSS AoC, C5, FedRAMP and penetration test summaries. Access to most audit reports requires sign-in with a work account tied to an eligible subscription and acceptance of an NDA.

**Public compliance index:** [Microsoft compliance offerings](https://learn.microsoft.com/en-us/compliance/regulatory/offering-home)

**Trust Center:** [microsoft.com/trust-center](https://www.microsoft.com/en-us/trust-center)

**Sub-processors:** Microsoft publishes an Online Services Subcontractor List through the Service Trust Portal (sign-in required), which is why the sub-processor table below is not populated. Microsoft commits under the DPA to notify customers before new sub-processors are authorised.

**Data location:** [microsoft.com/trust-center/privacy/data-location](https://www.microsoft.com/en-us/trust-center/privacy/data-location)

**Status:** [Azure Status](https://azure.status.microsoft/) and the Microsoft 365 admin centre service health dashboard.

Risk Assessment Notes

**Inherent risk drivers**

- Tier 1 / critical dependency covering identity (Entra ID), productivity, email, endpoint management and often hosting - a single vendor concentration across multiple control domains.
- Identity is the highest-impact dependency: compromise of the identity plane affects every connected system.
- Broad data categories likely, including personal and special category data, depending on tenant configuration.

**Mitigating factors**

- Very broad independent assurance: ISO 27001/27017/27018/27701/22301/9001/20000-1/42001, SOC 1-3, PCI DSS, FedRAMP High, HITRUST, C5, Cyber Essentials Plus.
- Mature DPA with SCCs, sub-processor notification commitments and the EU Data Boundary for European data residency.
- Extensive customer-side tooling: Conditional Access, Defender suite, Purview, Sentinel, unified audit logging.

**Concerns to track**

- Repeat nation-state targeting of Microsoft corporate and identity infrastructure (Storm-0558 in 2023, Midnight Blizzard in 2024) with findings critical of security culture in the 2024 US Cyber Safety Review Board report. Confirm progress under the Secure Future Initiative at each review.
- Licensing tier materially affects available security and logging controls - verify that the tenant licence level supports the controls assumed in this assessment.

**Residual customer responsibilities**

- Tenant hardening, Conditional Access and MFA/phishing-resistant authentication, privileged access management.
- Backup and retention beyond native capabilities, data classification and DLP configuration.
- Log retention, monitoring and integration into the customer SIEM.

**Suggested review cadence:** annual, or on notification of a material Microsoft security incident.

Assess Microsoft in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.