Palo Alto Networks

Cybersecurity United States Website Reviewed Sept. 2, 2026

Network and cloud security: NGFW, Prisma Access SASE, Prisma Cloud and Cortex XDR/XSIAM.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited third-party certification body Palo Alto Networks cloud-delivered security services and supporting ISMS Current
ISO/IEC 27017:2015 and ISO/IEC 27018:2019 Accredited third-party certification body Cloud security controls and protection of PII in public cloud for in-scope services Current
SOC 2 Type II Independent third-party auditor Prisma Access, Prisma Cloud and Cortex services; report available under NDA Current
FedRAMP US federal authorising body Prisma Access for Government and in-scope US federal offerings Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
GDPR 2016/679
Full
Processor under its DPA; EU and UK data residency options for Prisma Access
NIST Cybersecurity Framework
Partial
Products commonly mapped to NIST CSF controls
HIPAA Security
Partial
HIPAA support available for eligible services

Assess Palo Alto Networks in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.