Skip to content
Updated 2h ago

Which vendors hold which certification

64 cloud, data and AI vendors · 63 certifications · 771 held, each with its source · refreshed every Wednesday

ISO 22301

12 of 64 vendors show evidence for ISO 22301

Vendor
MicrosoftCloud · 50 held
OracleCloud · 43 held
AWSCloud · 41 held
Google CloudCloud · 31 held
IBMCloud · 31 held
Alibaba CloudCloud · 28 held
SAPBusiness apps · 25 held
ServiceNowBusiness apps · 24 held
SnowflakeData platforms · 22 held
DatabricksData platforms · 19 held
DropboxBusiness apps · 19 held
DigitalOceanCloud · 10 held

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

Latest changes

All changes
DateChange
Removed FedRAMP Google Cloud

Google Cloud VMware Engine (GCVE)

Upgraded FedRAMP High Cloudflare

Cloudflare for Government - High

Added FedRAMP Moderate Asana

Asana

Added FedRAMP Moderate IBM

GO.gov

Removed FedRAMP Splunk

Splunk Observability Cloud for FedRAMP Moderate

Added Data Privacy Framework Stripe

Covered entity of Stripe, LLC

Questions

What is Attested?

Attested answers which certifications and attestations cloud, data, AI and developer-tool vendors hold: SOC 1, 2 and 3, ISO 27001 and its family, ISO 42001, FedRAMP, GovRAMP, DoD Impact Levels, FIPS 140, CMMC, HIPAA, HITRUST, GxP, 21 CFR Part 11, PCI DSS, DORA, the Data Privacy Framework, CSA STAR, C5, IRAP, ISMAP and more. Pick up to three and get the vendors that hold all of them, each linked to its evidence and the date it was captured.

Where does the data come from?

From public registries where they exist (the FedRAMP Marketplace data, the CSA STAR Registry, the Data Privacy Framework List, the NIST CMVP list of validated FIPS 140 modules and the GovRAMP product list) and otherwise from each vendor's own compliance or trust-center page. Registry entries are authoritative; vendor-page entries record the sentence the vendor published, and matches nobody has confirmed show Unverified.

How often is it updated?

A run every Wednesday at 10:00 UTC re-reads every registry and a rotating set of vendor pages. What changed goes into the change log with its date.

Which vendors support GxP and 21 CFR Part 11?

Pick GxP and 21 CFR Part 11 on the home page. There is no GxP certificate: the list shows vendors whose compliance pages publish GxP qualification guidance or Part 11 and Annex 11 mappings, such as AWS, Microsoft and Google Cloud, each with the page that says so.

Which AI vendors are FedRAMP authorized?

Filter the grid by FedRAMP: OpenAI (ChatGPT Enterprise and API Platform, FedRAMP 20x Moderate), Perplexity (20x Low), Scale AI and Palantir (High), and Google's Gemini for Government (20x Low) are listed in the FedRAMP Marketplace. Claude reaches federal agencies through AWS GovCloud and Google Cloud authorizations.

Which companies are ISO 42001 certified?

Open the ISO/IEC 42001 page: it lists every tracked vendor that names the AI management system certification on its compliance page or in the CSA STAR Registry, including Microsoft, AWS, Google Cloud, Anthropic, OpenAI, Snowflake and Workday.

Is HIPAA a certification?

No. There is no HIPAA certificate. The HIPAA column records whether a vendor says it supports HIPAA-regulated data and signs a Business Associate Agreement, and for which products; confirm the BAA scope with the vendor.

Does a SOC 2 listing mean I can see the report?

No. SOC 1 and SOC 2 reports are shared under NDA through the vendor's trust center. SOC 3 is the public summary. Attested records that the vendor states it has the report, with a link to where to request it.

Weekly: vendors that gained or lost a certification, Wednesdays.