Rapid7

Cybersecurity United States Website Reviewed Sept. 2, 2026

Vulnerability management (InsightVM), SIEM (InsightIDR), application security and managed detection and response.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001 Accredited third-party certification body Rapid7 Insight platform and supporting ISMS Current
SOC 2 Type II Independent third-party auditor Rapid7 Insight platform services; report available to customers under NDA Current
Cyber Essentials Plus IASME on behalf of the NCSC Rapid7 UK operations - verify the current certificate Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
GDPR 2016/679
Full
Processor under its DPA; EU and UK Insight platform regions available
NIST Cybersecurity Framework
Partial
Vulnerability management commonly mapped to NIST CSF identify and protect
CIS V8
Partial
Supports CIS Controls v8 vulnerability management and benchmark scanning

Assess Rapid7 in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.