Compliance frameworks, security audits, and quality certifications this company maintains.
CyberArk maintains ISO 27001 certification across its cloud-delivered identity security platform, providing enterprise customers assurance that the vault infrastructure protecting their most sensitive privileged credentials meets international information security management standards.
CyberArk's SaaS-delivered identity security platform holds SOC 2 Type II certification, independently verifying that its privileged access vaulting, session recording, and identity services meet AICPA Trust Service Criteria for security and availability.
Regulatory
FedRAMP Moderate
CertifiedCyberArk's Privileged Access Manager is FedRAMP Moderate authorized, enabling U.S. federal agencies to secure privileged accounts across their cloud and on-premises environments in compliance with federal cloud security requirements.
CyberArk helps payment card industry organizations meet PCI DSS Requirement 7 and 8 by vaulting shared privileged credentials, enforcing least-privilege access, and providing full audit trails for all privileged sessions touching cardholder data environments.
CyberArk's identity security platform supports HIPAA compliance for healthcare organizations by controlling privileged access to electronic protected health information (ePHI) systems and generating audit logs required by the HIPAA Security Rule.
CyberArk complies with GDPR data processing obligations for European customers, with data residency options and DPA agreements that govern how privileged session recordings and credential data are stored and processed within EU borders.
CyberArk enables publicly traded companies to satisfy SOX IT general controls by providing vaulted privileged access with full session audit trails, demonstrating to external auditors that access to financial systems is properly controlled and monitored.
CyberArk's cryptographic modules are FIPS 140-2 validated, ensuring the encryption protecting privileged credentials stored in the CyberArk Vault meets U.S. government standards required by federal agency customers.
CyberArk holds ISO 27018 certification for its cloud services, demonstrating that personally identifiable information processed through the CyberArk Identity and Vault SaaS platform is protected to international cloud privacy standards.
Security
Common Criteria EAL2+
CertifiedCyberArk Enterprise Password Vault holds Common Criteria EAL2+ certification, providing government and defense customers independent validation of its security design for protecting privileged credentials in high-security classified environments.