Salesforce

SaaS / Software United States Website Reviewed Sept. 2, 2026

CRM and customer platform - Sales Cloud, Service Cloud, Marketing Cloud, Platform and Agentforce - plus Tableau and MuleSoft.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited third-party certification body Salesforce Services covered by the Salesforce ISMS Current
ISO/IEC 27017:2015 and ISO/IEC 27018:2019 Accredited third-party certification body Cloud security controls and protection of PII in public cloud for Salesforce Services Current
ISO/IEC 27701:2019 Accredited third-party certification body Privacy information management system extension to the Salesforce ISMS Current
SOC 1, SOC 2 and SOC 3 Type II Independent third-party auditor Salesforce Services. SOC 3 published publicly; SOC 1 and SOC 2 available to customers under NDA Current
PCI DSS Level 1 Service Provider Qualified Security Assessor In-scope Salesforce Services handling cardholder data Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
GDPR 2016/679
Full
Salesforce acts as processor under its DPA; SCCs and UK IDTA available
PCI DSS v4.0
Partial
PCI DSS applies to specific in-scope Salesforce Services only
HIPAA Security
Partial
HIPAA BAA available for eligible Salesforce Services

Assess Salesforce in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.