Tenable

Cybersecurity United States Website Reviewed Sept. 2, 2026

Exposure management and vulnerability scanning: Tenable Nessus, Tenable Vulnerability Management and Tenable Cloud Security.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001 Accredited third-party certification body Tenable cloud platform and supporting ISMS Current
SOC 2 Type II Independent third-party auditor Tenable Vulnerability Management and in-scope cloud services; report available under NDA Current
FedRAMP Moderate US federal authorising body Tenable.io for Government Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
GDPR 2016/679
Full
Processor under its DPA; EU and UK cloud regions available
CIS V8
Full
Certified CIS Benchmark content and configuration auditing
NIST Cybersecurity Framework
Partial
Commonly mapped to NIST CSF identify and protect functions

Assess Tenable in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.