Secure Access Certification

Cisco Secure Access

Compliance and certifications

Cisco Secure Access is supported by global certifications, regional compliance coverage, and alignment to frameworks including NIST, CISA Zero Trust, and TIC 3.0.

Overview Resources Demos and webinars

Global and regional certifications

Cisco Secure Access meets or exceeds global and regional standards, listed below, for data security and privacy. This webpage is solely for informational purposes. Go to the Trust Portal for specific certifications. 

Global Certifications

CertificationDescriptionStatus

CSA Star

 A multi-tiered provider assurance program that documents the specific security and privacy controls implemented by cloud service providers.Read more

Certified

ISO 27001

An international standard for information security management systems (ISMS) to manage sensitive company and client information. Read more

 

Certified

 

ISO 27017

A specialized code of practice that provides enhanced information security controls tailored for the provision and use of cloud services. Read more

Certified

ISO 27018

An international standard for protecting personally identifiable information (PII) in public cloud environments. Read more

Certified

ISO 27701

An extension to ISO 27001 for Privacy Information Management System (PIMS) and protection of personal data. Read more

In Process

PCI-DSS

A global standard defining technical and operational requirements to protect payment card data and reduce fraud. Read more

Available upon request

SOC 2
Type 2

An AICPA audit framework assessing security, availability, and confidentiality controls over a defined period. Read more

Certified

U.S. government certifications

CertificationsDescriptionStatus

CJIS

A security framework established by the FBI to ensure the protection and integrity of sensitive criminal justice information within the United States. Read more

In process

FedRAMP

A U.S. government program providing standardized assessment, authorization, and continuous monitoring for cloud products. Read more

Certified

GovRAMP

A standardized security authorization program specifically designed to meet the unique compliance needs of select U.S. state governments. Read more

Authorized
HIPAAA Department of Health and Human Services (HHS) regulation establishing administrative, physical, and technical safeguards for health information. Read moreAligned to support customer's compliance 
IL5 (DoD)A U.S. Department of Defense cloud security level required to host high-sensitivity Controlled Unclassified Information (CUI) and National Security Systems. Read moreIn process
TX-RAMPA mandatory certification program for cloud services used by Texas state agencies and public institutions of higher education. Read moreCertified

Regional certifications

CertificationsDescriptionStatus

C5 (Germany)

The Cloud Computing Compliance Criteria Catalogue (C5) defines the minimum requirements for secure cloud computing. Read more

Certified

Cyber Essentials Plus (UK)

A U.K. government-backed certification assessing cybersecurity defenses against common internet-based threats. Read moreIn process

ENS High (Spain)

The National Security Scheme (Esquema Nacional de Seguridad), a framework establishing security requirements for digital services in public administration. Read moreCertified
ISMAP (Japan)The Information System Security Management and Assessment Program evaluates cloud services against security requirements for government procurement. Read moreCertified
IRAP (Australia)An Australian Signals Directorate program providing independent security assessments to ensure compliance with the Information Security Manual (ISM). Read moreCertified

Accelerate compliance with key framework mappings

Framework Mapping: Secure Access for Government + NIST CSF 2.0

Maps capabilities to NIST Cybersecurity Framework functions and categories.

Read more

Framework Mapping: Secure Access + CISA Zero Trust

Maps capabilities to CISA Zero Trust pillars and technical elements.

Read more

Cisco TIC 3.0 Architecture Guide

Aligns capabilities to TIC 3.0 architecture and federal security requirements.

Read more

Cisco Secure Access e-book

Our new e-book provides insight into top business challenges and how Cisco Secure Access addresses them.