Skip to content

MicrosoftCompliance, certifications and attestations

Certifications held, by family46 held
Status
Public
Founded
1975
Trust center Company profile
46
Certifications held
7
Backed by a registry
52
Pieces of evidence
Sep 24, 2026
Last captured
Across fru.devAcquisitionsEarningsPaydaysReleasesConferences

SOC reports

ISO standards

AI governance

US government

Health

Payments

Privacy

Cloud security

Regional

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

Added or renewedUpgradedIn process or ReadyLapsed or removed
  1. AddedFedRAMP HighMicrosoft 365 Government Community Cloud-High
  2. In processFedRAMP HighMicrosoft 365 Government Community Cloud-High
  3. AddedFedRAMP HighAzure Government (includes Dynamics 365)
  4. UpgradedFedRAMP HighAzure Commercial Cloud
  5. In processFedRAMP HighAzure Government (includes Dynamics 365)
  6. In processFedRAMP HighAzure Commercial Cloud
  7. AddedData Privacy FrameworkMicrosoft Corporation
  8. AddedCSA STARFirst listed in the CSA STAR Registry
  9. AddedFedRAMP ModerateMicrosoft 365 Government Community Cloud & Supporting Services
  10. In processFedRAMP ModerateMicrosoft 365 Government Community Cloud & Supporting Services

Evidence

Every source, what it says and when it was read.

SOC 11 source

HeldVendor compliance page
...20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10 CFR Part 810 EAR (US Export Adm. Reg.)...
Captured Sep 24, 2026Open source

SOC 21 source

HeldVendor compliance page
...20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10 CFR Part 810 EAR (US Export Adm. Reg.) US...
Captured Sep 24, 2026Open source

SOC 31 source

HeldVendor compliance page
...20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10 CFR Part 810 EAR (US Export Adm. Reg.) US Government...
Captured Sep 24, 2026Open source

ISO/IEC 270011 source

HeldVendor compliance page
...attestation CSA-STAR certification CSA-STAR self-assessment CyberGRX ISO 20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS...
Captured Sep 24, 2026Open source

ISO/IEC 270171 source

HeldVendor compliance page
...certification CSA-STAR self-assessment CyberGRX ISO 20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD...
Captured Sep 24, 2026Open source

ISO/IEC 270181 source

HeldVendor compliance page
...certification CSA-STAR self-assessment CyberGRX ISO 20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10...
Captured Sep 24, 2026Open source

ISO/IEC 277011 source

HeldVendor compliance page
...self-assessment CyberGRX ISO 20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10 CFR Part...
Captured Sep 24, 2026Open source

ISO/IEC 420012 sources

HeldCSA STAR Registry

Partner entry in the STAR Registry

Listed as Microsoft since 2016-04-05; ISO/IEC 42001 entry
Captured Sep 23, 2026Since Apr 5, 2016Open source
HeldVendor compliance page
...self-assessment CyberGRX ISO 20000-1:2011 ISO 22301 ISO 27001 Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10 CFR Part 810 EAR (US...
Captured Sep 24, 2026Open source

CSA STAR for AI1 source

Held ยท Level 2CSA STAR Registry

AI-CAIQ, validated

Listed as Microsoft since 2016-04-05; STAR for AI Level 2
Captured Sep 23, 2026Since Apr 5, 2016Open source

FedRAMP5 sources

Held ยท HighFedRAMP Marketplace

Azure Commercial Cloud

FedRAMP Authorized, High impact; authorized 2019-05-03 (JAB); assessor Kratos; 78 agency authorizations
Captured Sep 23, 2026Since May 3, 2019Open source
Held ยท HighFedRAMP Marketplace

Azure Government (includes Dynamics 365)

FedRAMP Authorized, High impact; authorized 2020-04-29 (JAB); assessor Kratos; 60 agency authorizations
Captured Sep 23, 2026Since Apr 29, 2020Open source
Held ยท HighFedRAMP Marketplace

Microsoft 365 Government Community Cloud-High

FedRAMP Authorized, High impact; authorized 2024-12-26 (Agency); assessor Kratos; 5 agency authorizations
Captured Sep 23, 2026Since Dec 26, 2024Open source
Held ยท ModerateFedRAMP Marketplace

Microsoft 365 Government Community Cloud & Supporting Services

FedRAMP Authorized, Moderate impact; authorized 2014-11-20 (Agency); assessor Kratos; 91 agency authorizations
Captured Sep 23, 2026Since Nov 20, 2014Open source
In process ยท HighFedRAMP Marketplace

Microsoft 365 Government Community Cloud & Supporting Services

FedRAMP In Process, High impact; assessor Kratos
Captured Sep 23, 2026Open source

DoD Impact Level1 source

Held ยท IL5Vendor compliance page
...27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10 CFR Part 810 EAR (US Export Adm. Reg.) US Government FedRAMP FIPS 140-2 IRS 1075 ITAR NIST 800-171...
Captured Sep 24, 2026Open source

CJIS1 source

HeldVendor compliance page
...Global ISO 27017 ISO 27018 ISO 27701 ISO 42001 ISO 9001 SOC 1 SOC 2 SOC 3 WCAG US Government CJIS CNSSI 1253 DFARS DoD IL2 DoD IL5 DoE 10 CFR Part 810 EAR (US Export Adm. Reg.) US Government FedRAMP FIPS 140-2...
Captured Sep 24, 2026Open source

HIPAA (BAA)1 source

HeldVendor compliance page
...FFIEC (US) FINMA (Switzerland) FISC (Japan) FSA (Denmark) GLBA (US) GSMA GxP HDS (France) HIPAA / HITECH Industry HITRUST KNF (Poland) Know Your Third Party (KY3P) MARS-E (US) MAS + ABS (Singapore) MPA NBB...
Captured Sep 24, 2026Open source

HITRUST1 source

HeldVendor compliance page
...(Switzerland) FISC (Japan) FSA (Denmark) GLBA (US) GSMA GxP HDS (France) HIPAA / HITECH Industry HITRUST KNF (Poland) Know Your Third Party (KY3P) MARS-E (US) MAS + ABS (Singapore) MPA NBB + FSMA (Belgium) NEN-7510...
Captured Sep 24, 2026Open source

PCI DSS1 source

HeldVendor compliance page
...(Singapore) MPA NBB + FSMA (Belgium) NEN-7510 (Netherlands) NERC OSFI (Canada) Industry PCI-3DS PCI-DSS RBI + IRDAI (India) SEC 17a-4, SEC 18a-6, FINRA 4511, & CFTC 1.31 SEC Regulation SCI (US) Shared Assessments SOX...
Captured Sep 24, 2026Open source

Data Privacy Framework1 source

HeldData Privacy Framework List

EU-US, UK extension, Swiss-US; non-HR data and HR data. Microsoft Corporation

EU-US status: Active - Re-certification under Review; certified since 2016-08-12; recertification due 2027-08-31; verification: Self-Assessment
Captured Sep 23, 2026Since Aug 12, 2016Renewal due Aug 31, 2027Open source

EU Cloud Code of Conduct1 source

HeldCSA STAR Registry

Partner entry in the STAR Registry

Listed as Microsoft since 2016-04-05; EU Cloud Code of Conduct entry
Captured Sep 23, 2026Since Apr 5, 2016Open source

CSA STAR1 source

Held ยท Level 2CSA STAR Registry

CAIQ, certification

Listed as Microsoft since 2016-04-05; Level 2 (third-party audit)
Captured Sep 23, 2026Since Apr 5, 2016Open source

IRAP1 source

HeldVendor compliance page
...Canada Controlled Goods Canadian Privacy Laws CCCS Medium (Canada) Cyber Essentials Plus (UK) IRAP (Australia) Regional DJCP (China) DORA (EU) EN 301 549 (EU) ENISA IAF (EU) ENS (Spain) EU Model Clauses GB 18030...
Captured Sep 24, 2026Open source

BSI C51 source

HeldVendor compliance page
...SCI (US) Shared Assessments SOX TISAX Regional ABS OSPAR (Singapore) BIR 2012 (Netherlands) C5 (Germany) Canada Controlled Goods Canadian Privacy Laws CCCS Medium (Canada) Cyber Essentials Plus (UK) IRAP (Australia)...
Captured Sep 24, 2026Open source

ISMAP1 source

HeldVendor compliance page
...(Spain) EU Model Clauses GB 18030 (China) GDPR (EU) Regional G-Cloud (UK) IDW PS 951 (Germany) ISMAP (Japan) ISMS (Korea) IT-Grundschutz workbook (Germany) MeitY (India) MTCS (Singapore) My Number (Japan) Regional...
Captured Sep 24, 2026Open source

TISAX1 source

HeldVendor compliance page
...17a-4, SEC 18a-6, FINRA 4511, & CFTC 1.31 SEC Regulation SCI (US) Shared Assessments SOX TISAX Regional ABS OSPAR (Singapore) BIR 2012 (Netherlands) C5 (Germany) Canada Controlled Goods Canadian Privacy Laws...
Captured Sep 24, 2026Open source

Compare with

Weekly: vendors that gained or lost a certification, Wednesdays.