VMware (Broadcom)

Cloud & Infrastructure United States Website Reviewed Aug. 6, 2026

VMware virtualization and cloud infrastructure from Broadcom - VCF, vSphere, NSX, VMware Cloud on AWS, Live Recovery and Tanzu.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001 Accredited certification body Broadcom Cloud Services ISMS. VMware services in scope: VMware Cloud on AWS, VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth. On-premises products (VCF, vSphere/ESXi, vCenter, NSX) are NOT in the cloud ISMS scope. Current
ISO/IEC 27017:2015 Accredited certification body Cloud-specific information security guidance. VMware Cloud on AWS ONLY - no other VMware or Tanzu service is in scope. Current
ISO/IEC 27018:2019 Accredited certification body Protection of PII in public cloud as a PII processor. VMware Cloud on AWS ONLY. Current
ISO 9001:2015 Accredited certification body Quality management system. VMware Cloud on AWS is the ONLY VMware service listed in scope. Current
SOC 1 Independent third-party CPA firm VMware Cloud on AWS, VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth. Report download requires the Broadcom Support Portal and an NDA. Current
SOC 2 Independent third-party CPA firm VMware Cloud on AWS, VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth. Report download requires the Broadcom Support Portal and an NDA. Bridge letters are available. Current
SOC 3 Independent third-party CPA firm Tanzu CloudHealth is the ONLY VMware/Tanzu service with a SOC 3 report. VMware Cloud on AWS, Live Cyber Recovery, Avi Load Balancer and vDefend ATP do NOT have SOC 3. Current
PCI DSS Qualified Security Assessor (QSA) VMware Cloud on AWS ONLY. No other VMware service is PCI DSS in scope; PCI 3DS covers only the Arcot payment products, not VMware. Current
HIPAA Business Associate Agreement Contractual commitment (not a certification) Broadcom will enter into a HIPAA BAA for VMware Cloud on AWS and VMware Live Cyber Recovery ONLY. No other VMware service is BAA-eligible. Current
Cyber Essentials UK NCSC-backed scheme via accredited certification body VMware Cloud Foundation ONLY. No other VMware, Tanzu or Symantec service is in the Cyber Essentials scope. Current
Cyber Essentials Plus Accredited third party (annual external vulnerability testing) VMware Cloud Foundation ONLY. Requires an accredited third party to conduct external vulnerability testing annually. Current
TruSight Assessment TruSight Solutions (bank-created third-party assessment utility) Broadcom-wide participation. Completed assessment reports are purchased directly from TruSight ([email protected]), not from Broadcom. Current

Compliance Frameworks

ISO/IEC 27001:2022
Partial
Broadcom Cloud Services ISMS covers only five VMware/Tanzu cloud services (VMware Cloud on AWS, Live Cyber Recovery, Avi Load Balancer, vDefend ATP, Tanzu CloudHealth). On-premises VCF, vSphere, vCenter and NSX are outside the certified scope.
SOC 2 Type 2
Partial
SOC 1 and SOC 2 cover the same five cloud services. SOC 3 exists for Tanzu CloudHealth only. Reports require the Broadcom Support Portal plus an NDA.
ISO 9001:2015
Partial
ISO 9001:2015 quality management certification lists VMware Cloud on AWS as the only VMware service in scope.
PCI DSS v4.0
Partial
PCI DSS scope is VMware Cloud on AWS only. Do not treat any other VMware component as a PCI-certified service.
HIPAA Security
Partial
HIPAA BAA available for VMware Cloud on AWS and VMware Live Cyber Recovery only. This is a contractual commitment rather than an audited HIPAA certification.
Cyber Essentials
Partial
Cyber Essentials and Cyber Essentials Plus are held for VMware Cloud Foundation only, with annual external vulnerability testing by an accredited third party.
GDPR 2016/679
Full
Broadcom Privacy Notice and Policy, a Data Processing and Data Transfers page, and a dated public Third Party List (sub-processors) with an email subscription for change notifications.
ISO 27002
Partial
ISO 27002 control alignment is inherited from the ISO/IEC 27001 cloud ISMS certification and is not separately attested.

Penetration Testing

Scope Conducted By Date Frequency Report
No VMware or Broadcom penetration test report or testing cadence is published on the trust centre. The only published third-party technical testing is the annual external vulnerability testing required for Cyber Essentials Plus on VMware Cloud Foundation. VMware runs a mature vulnerability response programme (vSRC) and participates in Pwn2Own, where researchers target ESXi, Workstation and vCenter. (date = profile capture date) Not published. Accredited third party performs annual external vulnerability testing for Cyber Essentials Plus (VMware Cloud Foundation only). Aug. 6, 2026 Annual Not Available

Data Handling

Data Residency Regions
Per the Broadcom Third Party List (30 July 2026): VMware Cloud on AWS hosts in US, UK, Germany, Ireland, France, Italy, Sweden, Switzerland, Canada, Brazil, Australia, Japan, South Korea, India, Hong Kong SAR, Bahrain and South Africa. VMware Live Recovery covers a similar set plus Singapore. vDefend Firewall/ATP on Google: US, Germany, South Korea, Australia. Avi Load Balancer on Google: US, Japan, Ireland. Tanzu CloudHealth: US, Germany, UK. Tanzu Mission Control: US, Ireland, Japan, Canada.
Encryption at Rest
Yes — Not documented on the Broadcom trust centre. Encryption is a product-level capability (e.g. vSAN data-at-rest encryption, VM encryption, vSphere Native Key Provider) that the customer configures. Obtain the SOC 2 report and per-service documentation for the managed-service position.
Encryption in Transit
Yes — Not documented on the trust centre. In-transit protection depends on product configuration (NSX, vDefend, VMware Cloud Web Security). Confirm via the SOC 2 report and the service description for your specific subscription.
Backup Frequency
Not published. VMware Live Recovery / Live Cyber Recovery is itself the backup and cyber-recovery offering; RPO and RTO are customer-configured per protected workload rather than a vendor-published figure.
Retention Policy
Data Deletion
No service-specific retention or deletion periods are published. General commitments sit in the Broadcom Privacy Notice and Policy and the Data Processing and Data Transfers page. GAP: obtain written retention, return and deletion terms per VMware service, and confirm what happens to data on termination, before onboarding. This is a material gap given the volume of workload data VMware services hold.

Sub-processors

Sub-processor Purpose Data Location Trust Portal
Amazon Web Services (AWS) Hosting provider and platform services for VMware Cloud on AWS US, UK, Germany, Ireland, France, Italy, Sweden, Switzerland, Canada, Brazil, Australia, Japan, South Korea, India, Hong Kong SAR, Bahrain, South Africa View ↗
Amazon Web Services (AWS) Hosting provider and platform services for VMware Live Recovery US, Ireland, UK, France, Germany, Italy, Sweden, Switzerland, Canada, Brazil, Australia, Singapore, Japan, South Korea, India, Hong Kong SAR, Bahrain, South Africa View ↗
Amazon Web Services (AWS) Hosting provider and platform services for Tanzu Application Catalog, Tanzu CloudHealth, DX OpenExplore and Carbon Black On Prem EDR United States View ↗
Google LLC Hosting provider and platform services for VMware vDefend Firewall and vDefend Firewall with Advanced Threat Prevention United States, Germany, South Korea, Australia View ↗
Google LLC Hosting provider and platform services for VMware Avi Load Balancer United States, Japan, Ireland View ↗
Google LLC Hosting provider and platform services for Tanzu CloudHealth United States, Germany, United Kingdom View ↗
Google LLC Hosting, SSO, authentication, observability pipeline, email delivery monitoring and product feedback for Tanzu Mission Control SaaS United States, Ireland, Japan, Canada View ↗
Google LLC Hosting provider and platform services for VMware Cloud Web Security United States View ↗
Microsoft OpenAI service for VMware Tanzu Insights United States View ↗
Cloudflare, Inc. Infrastructure management for VMware Cloud Web Security United States View ↗
Elasticsearch Inc. Security services, logging and monitoring for VMware Cloud Web Security, VMware NSX, VMware NSX Defender and VMware NSX Detonator United States, Belgium View ↗
Fullstory Inc. Product usage clickstream analytics for VMware Cloud on AWS United States
Aha! Labs Inc. Gather and process product feedback for Tanzu CloudHealth United States
Pendo.io, Inc. Product analytics and usage telemetry for Tanzu CloudHealth (and Symantec Endpoint Security, CBX) United States View ↗
Sensu Observability pipeline and monitoring for Tanzu CloudHealth United States
TeleSign Corporation Optional delivery of SMS one-time passwords - listed against ALL Broadcom products United States
Xyleme Inc. Learning management system and education services - listed against ALL Broadcom products United States

Incident & Breach History

Date Summary Impact Resolution Report
July 29, 2026 VMSA-2026-0006.1 (Broadcom notification VCDSA38017): five privately reported vulnerabilities in VMware ESX, vCenter, Workstation and Fusion, CVSSv3 range 2.7-9.8. Includes a vCenter VMware Directory Service authentication bypass (CVE-2026-59309, 9.8) and a vCenter Syslog directory traversal allowing arbitrary code execution (CVE-2026-59310, 9.8). Reported by Atredis Partners and by STARLabs SG via Pwn2Own/ZDI. Affects VMware ESX, vCenter, Workstation, Fusion, VMware Cloud Foundation, vSphere Foundation, Telco Cloud Platform and Telco Cloud Infrastructure. An attacker with network access to vCenter could bypass authentication or execute code; a local VM administrator could escape to the host via a VMXNET3 out-of-bounds write (CVE-2026-47876, 9.3). No workarounds available for any of the five issues. Cumulative patches: vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k and 8.0 U2f; ESXi 9.1.0.0200-25557999 and 9.0.2.0100-25595025. Telco Cloud per KB449886; VCF 5.x async patching per KB88287. Supplemental FAQ at brcm.tech/vmsa-2026-0006. Advisory status still OPEN, last updated 03 August 2026. Report ↗
March 4, 2025 VMSA-2025-0004 (VCDSA25390): three vulnerabilities in VMware ESXi, Workstation and Fusion, CVSSv3 range 7.1-9.3. Broadcom stated it had information to suggest that exploitation of all three issues had occurred in the wild. All three were reported by the Microsoft Threat Intelligence Center. CVE-2025-22224 (9.3) is a VMCI TOCTOU out-of-bounds write letting a VM administrator run code as the host VMX process. CVE-2025-22225 (8.2) allows an arbitrary kernel write and sandbox escape. CVE-2025-22226 (7.1) leaks VMX process memory via an HGFS out-of-bounds read. Affected VMware ESXi, Workstation Pro/Player, Fusion, VMware Cloud Foundation and Telco Cloud Platform. Chained, these permit guest-to-host escape. Patches published the same day as the advisory, including ESXi80U3d-24585383 and ESXi80U2d-24585300. No workarounds were available, so patching was the only remediation. With confirmed in-the-wild exploitation this was an emergency-patch event for hypervisor estates. Advisory status OPEN, last updated 04 March 2025. Report ↗
Oct. 23, 2023 VMSA-2023-0023 (VCDSA23677): an out-of-bounds write in the vCenter Server DCERPC implementation (CVE-2023-34048, CVSS 9.8) and a partial information disclosure (CVE-2023-34056, CVSS 4.3). VMware subsequently confirmed that exploitation of CVE-2023-34048 had occurred in the wild. Reported via Trend Micro Zero Day Initiative and Deiteriy Lab. An actor with only network access to vCenter Server could trigger the out-of-bounds write and potentially achieve remote code execution, compromising the management plane of the whole virtual estate. CVE-2023-34056 let a non-administrative vCenter user reach unauthorised data. Affected VMware vCenter Server and VMware Cloud Foundation. In-product workarounds were investigated and found not viable. Given the severity, VMware issued patches even for end-of-life releases (vCenter 6.7U3, 6.5U3, VCF 3.x) plus extra patches for 8.0U1, and async patches for VCF 5.x and 4.x per KB88287. Advisory is CLOSED, last updated 15 January 2024. Report ↗

Security Policies

Policy Availability Link
VMware External Vulnerability Response and Remediation Policy Public View ↗
Broadcom Privacy Policy Public View ↗
Cookie Policy Public View ↗
Data Processing and Data Transfers Statement Public View ↗
Third Party List (sub-processors) Public View ↗
Enterprise Software Products & Services Transparency Notices Public View ↗
VMware Usage Data Programs Notice Public View ↗
Data Processing Addendum (Global Customers) Public View ↗
EU Data Act Addendum Public View ↗
Supplier Responsibility Standards Public View ↗
Compliance artifact library (SOC 1/2/3, ISO certificates, HIPAA and PCI documentation) On Request View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Trust centre:** Broadcom Trust Center at broadcom.com/support/trust-center, with the certification index at broadcom.com/support/trust-center/compliance. Certifications are listed per service and per region, and the filters make clear that most VMware attestations cover only a small subset of the portfolio.

**Audit evidence access:** there is no self-service trust portal. Compliance artifacts (SOC reports, ISO certificates, HIPAA and PCI documentation) sit behind the Broadcom Support Portal in the Product Legal Documentation module and require an Enterprise User Profile, which is a two-step upgrade from a Basic account. Download instructions are published as notification 37107 (first published 25 February 2026, last updated 09 March 2026).

**TruSight:** Broadcom participates in TruSight, but reports are purchased directly from TruSight ([email protected]) rather than obtained from Broadcom.

**Security advisories:** the public VMware Security Advisories index is at broadcom.com/support/vmware-security-advisories. It has no per-advisory deep links; the searchable advisory table lives on the Support Portal at support.broadcom.com/web/ecx/security-advisory, segmented as VC (VMware Cloud Foundation), VT (Tanzu) and VA (Application Networking and Security). At the review date the VMware Cloud Foundation segment held 340 advisories.

**Vulnerability policy:** VMware External Vulnerability Response and Remediation Policy at broadcom.com/support/vmware-services/security-response. PSIRT contact [email protected]; PGP key at knowledge.broadcom.com/external/article?legacyId=1055.

**Sub-processors:** Broadcom Third Party List at broadcom.com/company/legal/privacy/third-party-list, last updated 30 July 2026.

**Scope warning:** VMware End User Computing (Horizon, Workspace ONE) was divested to Omnissa and is out of scope for Broadcom trust documentation. Omnissa must be assessed separately at omnissa.com.

Risk Assessment Notes

**Inherent risk drivers**

- Hypervisor and management-plane concentration: vCenter and ESX sit beneath large parts of the estate, so a single critical vulnerability has estate-wide blast radius.
- Repeated confirmed in-the-wild exploitation of critical, network-reachable vCenter and ESXi flaws (CVE-2023-34048 in 2023; CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226 in 2025).
- Workarounds are frequently unavailable, so patching is often the only remediation and the patch window becomes the entire control.
- Predominantly on-premises software: the customer, not Broadcom, owns patching, hardening, segmentation, backup and monitoring.

**Certification scope is narrow - always check per service**

- ISO/IEC 27001: only VMware Cloud on AWS (which also holds 27017 and 27018), VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth.
- SOC 1 and SOC 2: VMware Cloud on AWS, Live Cyber Recovery, Avi Load Balancer and vDefend ATP. Tanzu CloudHealth is the only service with a SOC 3.
- PCI DSS and ISO 9001: VMware Cloud on AWS only. HIPAA BAA: VMware Cloud on AWS and VMware Live Cyber Recovery only.
- Cyber Essentials and Cyber Essentials Plus: VMware Cloud Foundation only.
- IRAP: no VMware service is in scope, all IRAP entries are Symantec. PCI 3DS: Arcot only. TISAX: the semiconductor business only.
- Practical consequence: on-premises VMware Cloud Foundation, vSphere, NSX and Tanzu deployments sit largely outside the audited service perimeter, so an attestation should not be assumed to cover the SKU you are buying.

**Mitigating factors**

- Mature, well-documented PSIRT: VMware is an approved CVE Numbering Authority and publishes structured VMSAs with CVSS scores, known attack vectors, response matrices and explicit notes when exploitation is happening in the wild.
- Advisories are prompt and usually coordinated with patch availability, with supplemental FAQs for critical events.
- Broadcom has patched end-of-life versions where severity warranted it, for example vCenter 6.7U3, 6.5U3 and VCF 3.x under VMSA-2023-0023.
- Published Data Processing Addendum, EU Data Act Addendum, transparency notices and a dated third-party list.
- Explicit safe-harbour commitment for good-faith security researchers.

**Residual responsibilities for the customer**

- Subscribe to Broadcom security alerts and maintain an emergency patch path for Critical VMSAs; treat vCenter and ESX as tier-0 assets.
- Restrict management-plane network reachability and never expose vCenter to untrusted networks.
- Confirm the specific service or SKU being purchased is inside a certified scope before relying on any attestation.
- Assess Omnissa separately for Horizon and Workspace ONE.
- Own backup, replication and DR design for on-premises deployments.

**Evidence gaps at review date**

- No self-service trust portal; audit evidence requires an Enterprise Support Portal profile, which adds friction to annual due diligence.
- No public bug bounty and no published penetration-test summary for on-premises products; visible external assurance comes mainly through Pwn2Own and Zero Day Initiative submissions.
- No published RTO, RPO or uptime SLA on the public trust centre for VMware services.
- No named Article 27 EU representative or Data Protection Officer.

**Suggested review cadence:** annual, with continuous monitoring of VMSAs and an out-of-cycle review triggered by any Critical advisory affecting a deployed product.

Assess VMware (Broadcom) in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.