Skip to main content
Certifications and Frameworks
Certifications๐ (you get audited, get a formal certificate, can show customers)
- SOC 2 Type II โ US SaaS trust standard, very common in procurement.
- ISO/IEC 27001 โ International information security management certification.
- ISO/IEC 27701 โ Privacy management (pairs with ISO 27001).
- FedRAMP Moderate โ Required if selling to US federal agencies (government cloud).
- CMMC Level 2 โ Required for Department of Defense-related contracts.
- PCI DSS SAQ โ Payment card security compliance (usually handled by payment processor, but you still attest).
- CSA STAR Certification โ Cloud security certification recognized globally.
Frameworks & Compliance Standards ๐ (best practices, often referenced in RFPs; you align to them)
- NIST Cybersecurity Framework (CSF) โ US governmentโfavored baseline for managing cybersecurity risk.
- NIST SP 800-53 โ More detailed control set for government contracts.
- State Privacy Laws Compliance โ CCPA/CPRA (California)
- GDPR โ EU privacy regulation (important if expanding internationally).
- CJIS Security Policy โ If handling law-enforcement-related data for municipal utilities.