Symantec (Broadcom)

Cybersecurity United States Website Reviewed Aug. 6, 2026

Symantec Enterprise Cloud security portfolio from Broadcom: endpoint security, DLP, cloud SWG, CASB, email security, web isolation and VIP authentication.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 (certificate also covers ISO/IEC 27017:2015 and ISO/IEC 27018:2019) Accredited third-party certification body Broadcom Cloud Services ISMS. Symantec services in scope: Symantec Endpoint Security Complete, Symantec Secure Access Cloud (SAC), Cloud Secure Web Gateway, CloudSOC CASB, Data Loss Prevention Cloud, Email Security.cloud, Threat Intelligence Service, VIP, Web Isolation Current
SOC 1 and SOC 2 Type II Independent third-party auditor Symantec services in scope: Symantec Endpoint Security Complete, Symantec Secure Access Cloud (SAC), Cloud Secure Web Gateway, CloudSOC CASB, Data Loss Prevention Cloud, Email Security.cloud, Threat Intelligence Service, VIP, Web Isolation, Zero Trust Network Access. SOC 3 is not offered for Symantec services Current
ISO 9001:2015 Accredited third-party certification body Quality management system. In-scope entries relevant to Symantec: Cybersecurity, Enterprise Software, Email Security.cloud, VIP Current
IRAP assessment (ACSC Information Security Manual) IRAP-registered assessor Cloud Secure Web Gateway, CloudSOC CASB, Data Loss Prevention Cloud, Symantec Endpoint Security Complete, Symantec Secure Access Cloud (SAC), Web Isolation Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
Broadcom Cloud Services ISMS certified to ISO/IEC 27001:2022, with the same certificate covering ISO/IEC 27017:2015 and ISO/IEC 27018:2019. Per-service certificates downloadable from the Broadcom Trust Center.
SOC 2 Type 2
Full
SOC 1 and SOC 2 Type II reports available for the Symantec cloud services listed above; download via the Broadcom Support Portal under NDA. No SOC 3 for Symantec services.
ISO 9001:2015
Partial
ISO 9001:2015 certificates issued at entity/service level - Cybersecurity, Enterprise Software, Email Security.cloud and VIP are in scope rather than the full Symantec portfolio.
GDPR 2016/679
Full
Broadcom provides pre-executed data processing terms and standard contractual clauses, publishes a Third Party (sub-processor) List with change notification, and issues per-product Transparency Notices.
ACSC Essential Eight
Partial
IRAP assessment completed against the ACSC Information Security Manual for six Symantec cloud services. Essential Eight is a separate control subset and is not itself certified.

Penetration Testing

Scope Conducted By Date Frequency Report
Broadcom Cloud Services covering the Symantec portfolio - independent testing performed as part of the ISO 27001, SOC 2 and IRAP programmes. Broadcom does not publish standalone penetration test summaries (date shown is the profile capture date) Independent third-party assessors engaged by Broadcom Aug. 6, 2026 Annual On NDA

Data Handling

Data Residency Regions
Varies by Symantec service and hosting provider. Per the Broadcom Third Party List: United States, Germany, Belgium, Netherlands, Ireland, United Kingdom, Finland, Sweden, India, Brazil, Singapore, Japan, Australia. Content Analysis is hosted on Azure in China. Confirm the region for the specific service at contract stage.
Encryption at Rest
Yes — Asserted for Broadcom Cloud Services in the per-product Transparency Notices and covered by the ISO 27001/27017/27018 and SOC 2 control sets. Algorithm and key management detail are not published - obtain the SOC 2 report and Transparency Notice for the specific Symantec service.
Encryption in Transit
Yes — TLS for service, console and API traffic. Email Security.cloud additionally offers customer-facing email encryption via Echoworx and Zix. Confirm minimum TLS version per service in the SOC 2 report.
Backup Frequency
Not published. Backup and recovery objectives are service-specific and documented in the SOC 2 report and product documentation available under NDA.
Retention Policy
Data Deletion
Governed by the Broadcom pre-executed data processing terms and the per-product Transparency Notice for each service, which set out retention periods and deletion or return of personal data on termination. Service-specific retention should be confirmed in the applicable Transparency Notice.

Sub-processors

Sub-processor Purpose Data Location Trust Portal
Google LLC Hosting provider and platform services / infrastructure management for the majority of Symantec cloud services (Symantec Endpoint Security Complete and Enterprise, Cloud Secure Web Gateway, Web Isolation, Zero Trust Network Access, Secure Access Cloud, CloudSOC CASB, Data Loss Prevention, Email Security.cloud, VIP, Threat Intelligence Service, WebPulse, Cloud Sandboxing/Cynic) United States, Germany, Belgium, Netherlands, India, Brazil, Singapore, Japan, Australia, United Kingdom, Finland
Amazon Web Services (AWS) Hosting provider and platform services for Email Security.cloud; hosting and one-time password delivery for Cloud Workload Protection for Storage and Industrial Control Systems Protection United States, Sweden, Ireland, United Kingdom, Europe View ↗
Microsoft Hosting provider and platform services for Cloud Secure Web Gateway; Azure cloud hosting for Content Analysis United States, China View ↗
Echoworx Corporation Email encryption service for Email Security.cloud United States, United Kingdom
Zix Corporation Email encryption service for Email Security.cloud United States
Pendo.io, Inc. Product analytics and usage telemetry for Symantec Endpoint Security Complete and Symantec Endpoint Security Enterprise United States
SendGrid, Inc. Email delivery service for Symantec Endpoint Security Enterprise United States
TeleSign Corporation Optional delivery of SMS one-time passwords (applies to all products) United States
Payfone, Inc. DBA Prove One-time password delivery by voice message for Validation & ID Protection (VIP) Service United States
AC PM, LLC (ActiveCampaign) dba Postmark Email delivery for Endpoint Protection Mobile United States
Xyleme Inc. Learning management system and education services (applies to all products) United States

Incident & Breach History

Date Summary Impact Resolution Report
Jan. 17, 2012 Source code for several Symantec products, including Norton Antivirus and pcAnywhere, was published by a third party. Symantec confirmed the code had been taken in a 2006 network intrusion rather than a new breach. Symantec advised customers to disable pcAnywhere until updates were issued, because exposure of the source code raised the risk of exploit development against that product. Predates Broadcom ownership. Hotfixes and updated releases were issued and customers were guided through remediation. Symantec subsequently retired pcAnywhere as a product.
Sept. 11, 2017 Following investigations into certificate mis-issuance, browser vendors announced a phased plan to distrust TLS certificates issued by Symantec’s certificate authority. Symantec agreed to divest the CA business, which was acquired by DigiCert (completed October 2017). Customers holding Symantec-issued TLS certificates (including Thawte, GeoTrust and RapidSSL brands) had to replace them to avoid browser trust errors. Reputational impact on Symantec’s assurance practices. Predates Broadcom ownership. The certificate authority business was transferred to DigiCert, which re-issued affected certificates from its own trusted roots. Symantec exited the public CA market.

Security Policies

Policy Availability Link
Broadcom Global Privacy Notice and Policy Public View ↗
Data Processing and Data Transfers (pre-executed DPA terms and SCCs) Public View ↗
Third Party List (sub-processors) with change notification subscription Public View ↗
Privacy and Data Protection hub, including per-product Transparency Notices Public View ↗
Symantec Vulnerability Response Guidelines Public View ↗
Broadcom Product Security Center Public View ↗
Broadcom Terms of Use Public View ↗
Certification and audit reports (SOC 1/2, ISO 27001/9001, IRAP) via Broadcom Support Portal On Request View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Trust portal:** [Broadcom Trust Center](https://www.broadcom.com/support/trust-center) with the compliance index at [/support/trust-center/compliance](https://www.broadcom.com/support/trust-center/compliance). Certificates and scope tables are public and filterable by region and service; SOC 1/SOC 2 reports and bridge letters are downloaded from the Broadcom Support Portal and require an account and NDA.

**Important scoping caveat:** Broadcom certifications are granted per service, not per company. Several standards listed on the Trust Center do **not** cover Symantec services - PCI DSS and PCI 3DS cover the Arcot payment products and VMware Cloud on AWS, HIPAA BAA covers VMware Cloud on AWS and VMware Live Cyber Recovery, Cyber Essentials covers VMware Cloud Foundation, and TISAX covers Broadcom chip manufacturing. Always confirm the specific Symantec service appears in the scope table.

**Sub-processors:** [Third Party List](https://www.broadcom.com/company/legal/privacy/third-party-list) - public, dated (last updated 30 July 2026), with an email subscription for change notifications. This is unusually transparent for an enterprise security vendor and is the best evidence source for onward data flows.

**Transparency Notices:** per-product privacy documentation via [/company/legal/privacy](https://www.broadcom.com/company/legal/privacy).

**TruSight:** Broadcom participates in the TruSight shared assessment programme; reports are obtained directly from TruSight rather than Broadcom.

Risk Assessment Notes

**Corporate structure - check what you are actually buying**

Symantec is not a standalone company. Broadcom acquired the Symantec enterprise security business in November 2019; the consumer business (Norton, LifeLock) was retained separately and is now Gen Digital. This profile covers the Broadcom enterprise portfolio only. Contracts, DPAs and assurance artefacts are all issued by Broadcom entities.

**Inherent risk drivers**

- Endpoint agents and network inspection points (Cloud SWG, Web Isolation, CASB, DLP) sit inline and can affect availability and confidentiality of traffic across the estate.
- TLS interception in Cloud SWG creates a high-value decryption point that needs its own control review.
- DLP and CASB modules by design ingest content, materially raising data classification sensitivity.

**Mitigating factors**

- Per-service ISO 27001/27017/27018 certificates and SOC 1/SOC 2 Type II reports for the main Symantec cloud services.
- IRAP assessment against the ACSC ISM for six Symantec cloud services.
- Public, dated sub-processor list with subscription-based change notification.

**Concerns to track**

- Certification scope is narrower than the marketing surface: no PCI DSS, HIPAA BAA or Cyber Essentials coverage for Symantec services. Do not inherit assurance from other Broadcom or VMware product lines.
- Post-acquisition Broadcom has repositioned toward its largest accounts; assess support model, roadmap and licensing continuity risk, and document an exit plan.
- Encryption and backup specifics are not published - these must be evidenced from the SOC 2 report rather than assumed.
- Heavy reliance on Google Cloud as the underlying hosting provider for most Symantec services creates a fourth-party concentration to record.
- No public bug bounty programme; vulnerability handling is PSIRT-only, which gives less external assurance than peers.

**Suggested review cadence:** annual, with evidence refresh when each SOC 2 report is reissued and re-check of the Third Party List at every review.

Assess Symantec (Broadcom) in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.