Compliance frameworks, security audits, and quality certifications this company maintains.
Ping Identity undergoes annual SOC 2 Type II audits across its PingOne cloud platform, PingFederate, and PingAccess products, providing enterprise customers with independent assurance of the security, availability, and confidentiality controls governing their identity infrastructure.
Ping Identity maintains ISO 27001 certification for its information security management system, demonstrating systematic management of sensitive identity and access data across its global cloud operations and enterprise product deployments.
Regulatory
FedRAMP Moderate
CertifiedPingOne for Government has achieved FedRAMP Moderate authorization, enabling U.S. federal agencies to deploy Ping Identity's cloud-native IAM platform for workforce and citizen identity use cases in compliance with NIST 800-53 federal security controls.
Ping Identity's identity platform and data processing practices are designed to support GDPR compliance, offering EU data residency options, privacy-by-design architecture, and data processing agreements for European enterprise customers managing workforce and customer identities.
Ping Identity supports CCPA compliance for its enterprise customers through its CIAM platform capabilities including consent management, data subject access requests, and opt-out workflows for California consumer identity data.
Ping Identity's identity platform supports HIPAA-compliant authentication and access control workflows for healthcare organizations, enabling hospitals and health systems to enforce least-privilege access to ePHI using MFA and role-based access management.
Ping Identity products implement FIPS 140-2 validated cryptographic modules for key management and authentication token generation, meeting federal and regulated industry requirements for cryptographic standards in identity systems.
Ping Identity's access management and MFA capabilities help financial services and e-commerce customers meet PCI DSS authentication requirements by enforcing strong authentication for cardholder data environment access.
Ping Identity is an OpenID Connect Certified provider, with PingFederate and PingOne certified across multiple conformance profiles ensuring standards-based interoperability with any OIDC-compliant application or identity provider.
Ping Identity's PingOne end-user authentication interfaces including login, MFA, and self-service flows conform to WCAG 2.1 Level AA accessibility standards, ensuring enterprise customers can deploy identity experiences accessible to users with disabilities.