Skip to content

DatabricksCompliance, certifications and attestations

Certifications held, by family19 held
Status
Private
Founded
2013
Trust center Company profile
19
Certifications held
2
Backed by a registry
21
Pieces of evidence
Sep 24, 2026
Last captured
Across fru.devAcquisitionsFundingPaydaysReleasesConferences

SOC reports

ISO standards

AI governance

US government

Health

Payments

Privacy

Cloud security

Regional

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

Added or renewedUpgradedIn process or ReadyLapsed or removed
  1. AddedFedRAMP HighDatabricks on Azure Commercial
  2. In processFedRAMP HighDatabricks on Azure Commercial
  3. UpgradedFedRAMP HighDatabricks on AWS GovCloud
  4. In processFedRAMP HighDatabricks on AWS GovCloud
  5. AddedFedRAMP ModerateDatabricks on AWS US East/West
  6. In processFedRAMP ModerateDatabricks on AWS US East/West
  7. AddedData Privacy FrameworkDatabricks, Inc.

Evidence

Every source, what it says and when it was read.

SOC 11 source

HeldVendor compliance page
...entities, spanning baseline controls (ECC), cloud computing (CCC) and data cybersecurity (DCC). SOC 1 , SOC 2 , SOC 3 Standard for describing security controls of cloud service providers TISAX (Trusted Information...
Captured Sep 24, 2026Open source

SOC 21 source

Held · Type IIVendor compliance page
...reach out to your Databricks account team for copies of our Enterprise Security Guide and SOC 2 Type II report. Download Certifications and standards C5 The C5 Criteria Catalogue is a test standard that specifies...
Captured Sep 24, 2026Open source

SOC 31 source

HeldVendor compliance page
...baseline controls (ECC), cloud computing (CCC) and data cybersecurity (DCC). SOC 1 , SOC 2 , SOC 3 Standard for describing security controls of cloud service providers TISAX (Trusted Information Security Assessment...
Captured Sep 24, 2026Open source

ISO/IEC 270011 source

HeldVendor compliance page
...International standard for information security in Business Continuity Management System (BCMS) ISO 27001 International standard for information security management systems ISO 27017 International standard for securely...
Captured Sep 24, 2026Open source

ISO/IEC 270171 source

HeldVendor compliance page
...System (BCMS) ISO 27001 International standard for information security management systems ISO 27017 International standard for securely utilizing or providing cloud services ISO 27018 International standard for...
Captured Sep 24, 2026Open source

ISO/IEC 270181 source

HeldVendor compliance page
...systems ISO 27017 International standard for securely utilizing or providing cloud services ISO 27018 International standard for handling of PII in the public cloud ISO 27036 International standard for information...
Captured Sep 24, 2026Open source

ISO/IEC 277011 source

HeldVendor compliance page
...cloud ISO 27036 International standard for information security in supplier relationships ISO 27701 International standard for privacy management K-FSI The Korean Financial Security Institute (K-FSI) plays a crucial...
Captured Sep 24, 2026Open source

FedRAMP3 sources

Held · ModerateFedRAMP Marketplace

Databricks on AWS US East/West

FedRAMP Authorized, Moderate impact; authorized 2022-09-29 (Agency); assessor Fortreum, LLC; 5 agency authorizations
Captured Sep 23, 2026Since Sep 29, 2022Open source
Held · HighFedRAMP Marketplace

Databricks on AWS GovCloud

FedRAMP Authorized, High impact; authorized 2025-02-26 (Agency); assessor Fortreum, LLC; 7 agency authorizations
Captured Sep 23, 2026Since Feb 26, 2025Open source
Held · HighFedRAMP Marketplace

Databricks on Azure Commercial

FedRAMP Authorized, High impact; authorized 2026-01-16 (Agency); assessor Fortreum, LLC; 1 agency authorization
Captured Sep 23, 2026Since Jan 16, 2026Open source

DoD Impact Level1 source

Held · IL5Vendor compliance page
...validated third-party risk assessment, enhancing supplier due diligence and cybersecurity DoD IL5 Certification to standardize U.S. Department of Defense security authorizations FedRAMP Certification to standardize...
Captured Sep 24, 2026Open source

HIPAA (BAA)1 source

HeldVendor compliance page
...provides guidelines, standards and regulations that ensure safe practices, such as manufacturing HIPAA U.S. privacy regulation for protected health information HITRUST A set of controls designed to address regulations...
Captured Sep 24, 2026Open source

HITRUST1 source

HeldVendor compliance page
...practices, such as manufacturing HIPAA U.S. privacy regulation for protected health information HITRUST A set of controls designed to address regulations such as HIPAA IRAP A framework for assessing security controls...
Captured Sep 24, 2026Open source

PCI DSS1 source

HeldVendor compliance page
...evaluating the security of cloud service providers (CSPs) used by financial institutions in Korea. PCI-DSS Requirements for processing, storing, transmitting or accessing credit card information NCA ECC/CCC/DCC The Kingdom...
Captured Sep 24, 2026Open source

Data Privacy Framework1 source

HeldData Privacy Framework List

EU-US, UK extension, Swiss-US; non-HR data. Databricks, Inc.

EU-US status: Active; certified since 2018-09-04; recertification due 2027-08-10; verification: Self-Assessment
Captured Sep 23, 2026Since Sep 4, 2018Renewal due Aug 10, 2027Open source

IRAP1 source

HeldVendor compliance page
...health information HITRUST A set of controls designed to address regulations such as HIPAA IRAP A framework for assessing security controls to meet the Australian government's security requirements ISMAP Japan’s...
Captured Sep 24, 2026Open source

ISMAP1 source

HeldVendor compliance page
...for assessing security controls to meet the Australian government's security requirements ISMAP Japan’s government cloud security registration program that ensures cloud services meet rigorous security and...
Captured Sep 24, 2026Open source

TISAX1 source

HeldVendor compliance page
...SOC 1 , SOC 2 , SOC 3 Standard for describing security controls of cloud service providers TISAX (Trusted Information Security Assessment Exchange) An automotive industry standard developed to ensure consistent...
Captured Sep 24, 2026Open source

Compare with

Weekly: vendors that gained or lost a certification, Wednesdays.