Skip to content

IBMCompliance, certifications and attestations

Certifications held, by family31 held
Status
Public
Founded
1911
Website
ibm.com
Trust center Company profile
31
Certifications held
5
Backed by a registry
41
Pieces of evidence
Sep 24, 2026
Last captured
Across fru.devAcquisitionsEarningsPaydaysConferences

SOC reports

ISO standards

AI governance

US government

Health

Payments

Privacy

Cloud security

Regional

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

Added or renewedUpgradedIn process or ReadyLapsed or removed
  1. AddedFedRAMP ModerateGO.gov
  2. In processFedRAMP ModerateGO.gov
  3. In processFedRAMP HighIBM Platform Services for Government
  4. AddedFedRAMP HighIBM Federal ATOM
  5. ReadyFedRAMP HighIBM Federal ATOM
  6. In processFedRAMP HighIBM Federal ATOM
  7. AddedFedRAMP LowIBM Envizi ESG Reporting
  8. In processFedRAMP LowIBM Envizi ESG Reporting
  9. AddedFedRAMP ModerateIBM Federal HR Cloud
  10. In processFedRAMP ModerateIBM Federal HR Cloud
  11. AddedFedRAMP HighSmartCloud for Government
  12. UpgradedFedRAMP HighIBM Cloud for Government
  13. AddedFedRAMP ModerateIBM Automation Services for Government
  14. In processFedRAMP HighSmartCloud for Government
  15. In processFedRAMP ModerateIBM Automation Services for Government
  16. In processFedRAMP HighIBM Cloud for Government
  17. AddedCSA STARFirst listed in the CSA STAR Registry
  18. AddedData Privacy FrameworkInternational Business Machines Corporation (IBM)
  19. AddedFedRAMP ModerateIBM Platform Services for Government
  20. In processFedRAMP ModerateIBM Platform Services for Government

Evidence

Every source, what it says and when it was read.

SOC 11 source

HeldVendor compliance page
...ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 31000 ISO 9001 SOC 1 SOC 2 SOC 3 Government programs DoD DISA FedRAMP FISMA ITAR Regional programs APRA (Australia) BaFin (Germany)...
Captured Sep 24, 2026Open source

SOC 21 source

HeldVendor compliance page
...20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 31000 ISO 9001 SOC 1 SOC 2 SOC 3 Government programs DoD DISA FedRAMP FISMA ITAR Regional programs APRA (Australia) BaFin (Germany) CCPA...
Captured Sep 24, 2026Open source

SOC 31 source

HeldVendor compliance page
...ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 31000 ISO 9001 SOC 1 SOC 2 SOC 3 Government programs DoD DISA FedRAMP FISMA ITAR Regional programs APRA (Australia) BaFin (Germany) CCPA and CPRA...
Captured Sep 24, 2026Open source

ISO/IEC 270011 source

HeldVendor compliance page
...HITRUST PCI DSS SEC Rule 17a 4(f) Global programs CIS CSA STAR ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 31000 ISO 9001 SOC 1 SOC 2 SOC 3 Government programs DoD DISA FedRAMP FISMA...
Captured Sep 24, 2026Open source

ISO/IEC 270171 source

HeldVendor compliance page
...DSS SEC Rule 17a 4(f) Global programs CIS CSA STAR ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 31000 ISO 9001 SOC 1 SOC 2 SOC 3 Government programs DoD DISA FedRAMP FISMA ITAR Regional...
Captured Sep 24, 2026Open source

ISO/IEC 270181 source

HeldVendor compliance page
...Rule 17a 4(f) Global programs CIS CSA STAR ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 31000 ISO 9001 SOC 1 SOC 2 SOC 3 Government programs DoD DISA FedRAMP FISMA ITAR Regional programs...
Captured Sep 24, 2026Open source

ISO/IEC 277011 source

HeldVendor compliance page
...Global programs CIS CSA STAR ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO 27701 ISO 31000 ISO 9001 SOC 1 SOC 2 SOC 3 Government programs DoD DISA FedRAMP FISMA ITAR Regional programs APRA (Australia)...
Captured Sep 24, 2026Open source

FedRAMP10 sources

Held · HighFedRAMP Marketplace

SmartCloud for Government

FedRAMP Authorized, High impact; authorized 2019-11-14 (JAB); assessor Coalfire Systems, Inc.; 4 agency authorizations
Captured Sep 23, 2026Since Nov 14, 2019Open source
Held · ModerateFedRAMP Marketplace

IBM Platform Services for Government

FedRAMP Authorized, Moderate impact; authorized 2015-07-17 (JAB); assessor Coalfire Systems, Inc.; 9 agency authorizations
Captured Sep 23, 2026Since Jul 17, 2015Open source
Held · HighFedRAMP Marketplace

IBM Cloud for Government

FedRAMP Authorized, High impact; authorized 2019-11-14 (JAB); assessor Fortreum, LLC; 4 agency authorizations
Captured Sep 23, 2026Since Nov 14, 2019Open source
Held · ModerateFedRAMP Marketplace

IBM Automation Services for Government

FedRAMP Authorized, Moderate impact; authorized 2019-03-12 (Agency); assessor Coalfire Systems, Inc.; 11 agency authorizations
Captured Sep 23, 2026Since Mar 12, 2019Open source
Held · ModerateFedRAMP Marketplace

IBM Federal HR Cloud

FedRAMP Authorized, Moderate impact; authorized 2023-06-08 (Agency); assessor Coalfire Systems, Inc.; 5 agency authorizations
Captured Sep 23, 2026Since Jun 8, 2023Open source
Held · LowFedRAMP Marketplace

IBM Envizi ESG Reporting

FedRAMP Authorized, LI-SaaS impact; authorized 2024-09-13 (Agency); assessor Coalfire Systems, Inc.; 1 agency authorization
Captured Sep 23, 2026Since Sep 13, 2024Open source
Held · HighFedRAMP Marketplace

IBM Federal ATOM

FedRAMP Authorized, High impact; authorized 2025-11-13 (Agency); assessor Coalfire Systems, Inc.; 2 agency authorizations
Captured Sep 23, 2026Since Nov 13, 2025Open source
Held · ModerateFedRAMP Marketplace

IBM Data Services for Government

FedRAMP Authorized, Moderate impact; authorized 2026-02-10 (Agency); assessor Fortreum, LLC; 1 agency authorization
Captured Sep 23, 2026Since Feb 10, 2026Open source
Held · ModerateFedRAMP Marketplace

GO.gov

FedRAMP Authorized, Moderate impact; authorized 2026-06-04 (Agency); assessor Coalfire Systems, Inc.; 21 agency authorizations
Captured Sep 23, 2026Since Jun 4, 2026Open source
In process · HighFedRAMP Marketplace

IBM Platform Services for Government

Agency In Process, High impact; assessor Coalfire Systems, Inc.
Captured Sep 23, 2026Open source

HIPAA (BAA)1 source

HeldVendor compliance page
...Compliance Navigator Industry programs IBM Cloud for Financial Services EBA (EU) FISC (Japan) GxP HIPAA HITRUST PCI DSS SEC Rule 17a 4(f) Global programs CIS CSA STAR ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017...
Captured Sep 24, 2026Open source

HITRUST1 source

HeldVendor compliance page
...Navigator Industry programs IBM Cloud for Financial Services EBA (EU) FISC (Japan) GxP HIPAA HITRUST PCI DSS SEC Rule 17a 4(f) Global programs CIS CSA STAR ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018...
Captured Sep 24, 2026Open source

PCI DSS1 source

HeldVendor compliance page
...Industry programs IBM Cloud for Financial Services EBA (EU) FISC (Japan) GxP HIPAA HITRUST PCI DSS SEC Rule 17a 4(f) Global programs CIS CSA STAR ISO 20000 ISO 20243 ISO 22301 ISO 27001 ISO 27017 ISO 27018 ISO...
Captured Sep 24, 2026Open source

Data Privacy Framework1 source

HeldData Privacy Framework List

EU-US, UK extension, Swiss-US; non-HR data. International Business Machines Corporation (IBM)

EU-US status: Active; certified since 2016-12-02; recertification due 2026-11-11; verification: Self-Assessment
Captured Sep 23, 2026Since Dec 2, 2016Renewal due Nov 11, 2026Open source

EU Cloud Code of Conduct2 sources

HeldCSA STAR Registry

Partner entry in the STAR Registry

Listed as IBM Cloud since 2017-10-16; EU Cloud Code of Conduct entry
Captured Sep 23, 2026Since Oct 16, 2017Open source
HeldVendor compliance page
...(Germany) CCPA and CPRA C5 (Germany) Digital Operational Resilience Act (DORA) EU ENS (Spain) EU Cloud Code of Conduct EU Digital Services Act EU Model Clauses EU-US Privacy Shield G-Cloud (UK) GDPR (EU) HCF (Australia) HDS 2.0 (France)...
Captured Sep 24, 2026Open source

CSA STAR1 source

Held · Level 2CSA STAR Registry

CAIQ, certification

Listed as IBM Cloud since 2017-10-16; Level 2 (third-party audit)
Captured Sep 23, 2026Since Oct 16, 2017Open source

IRAP1 source

HeldVendor compliance page
...Model Clauses EU-US Privacy Shield G-Cloud (UK) GDPR (EU) HCF (Australia) HDS 2.0 (France) IRAP (Australia) ISMAP (Japan) IT-Grundschutz (Germany) LGPD (Brazil) MeitY (India) MTCS (Singapore) NIS Directive...
Captured Sep 24, 2026Open source

BSI C51 source

HeldVendor compliance page
...DISA FedRAMP FISMA ITAR Regional programs APRA (Australia) BaFin (Germany) CCPA and CPRA C5 (Germany) Digital Operational Resilience Act (DORA) EU ENS (Spain) EU Cloud Code of Conduct EU Digital Services Act EU Model...
Captured Sep 24, 2026Open source

ISMAP1 source

HeldVendor compliance page
...EU-US Privacy Shield G-Cloud (UK) GDPR (EU) HCF (Australia) HDS 2.0 (France) IRAP (Australia) ISMAP (Japan) IT-Grundschutz (Germany) LGPD (Brazil) MeitY (India) MTCS (Singapore) NIS Directive (EU) PASF (UK) PINAKES...
Captured Sep 24, 2026Open source

TISAX1 source

HeldVendor compliance page
...PASF (UK) PINAKES PIPEDA (Canada) POPIA (South Africa) Protected B (Canada) SCEC (Australia) TISAX (Germany) Disclaimer: The client is responsible for ensuring compliance with all applicable laws and regulations....
Captured Sep 24, 2026Open source

Compare with

Weekly: vendors that gained or lost a certification, Wednesdays.