Compliance frameworks, security audits, and quality certifications this company maintains.
PTC's software development and professional services operations are certified to ISO 9001:2015, ensuring systematic quality management processes across the Windchill and Creo product development lifecycle and global customer delivery organization.
PTC's cloud platform infrastructure — including Windchill+ and Creo+ SaaS environments — is certified to ISO/IEC 27001, demonstrating that PTC maintains a rigorous information security management system protecting customer product data and IP in cloud-hosted PLM environments.
PTC's SaaS products including Windchill+ PLM and ThingWorx cloud undergo annual SOC 2 Type II audits, verifying that PTC's controls for security, availability, and confidentiality meet AICPA standards for customers entrusting sensitive product design data to PTC cloud environments.
PTC's Windchill PLM and Creo CAD products are used by U.S. defense contractors and primes for ITAR-controlled technical data management. PTC maintains ITAR compliance in its product architecture, cloud deployment options, and export control policies to support customers managing EAR/ITAR-controlled programs.
Regulatory
FedRAMP Moderate
In ProgressPTC is pursuing FedRAMP Moderate authorization for its Windchill+ cloud PLM platform to serve U.S. federal agencies and DoD customers who require cloud-hosted PLM solutions for defense acquisition programs under DFARS and CMMC compliance frameworks.
PTC's Windchill PLM deployment architectures support customers achieving CMMC Level 2 compliance for Controlled Unclassified Information (CUI) in defense manufacturing programs, with configuration guidance for on-premise and GovCloud deployments meeting NIST SP 800-171 controls.
PTC's cloud products including Windchill+, ThingWorx, and Vuforia maintain GDPR compliance for EU customers, with data processing agreements, EU data residency options, and privacy controls built into PTC's SaaS platform architecture to protect customer personal data in European manufacturing deployments.
PTC's cloud platforms comply with the California Consumer Privacy Act (CCPA/CPRA), providing customers and users with data access, deletion, and opt-out rights within PTC's SaaS product suite including Windchill+, Vuforia, and Servicemax for California-based enterprise customers.
PTC's Windchill Quality Management Solution (QMS) module supports customers maintaining AS9100D certification for aerospace and defense manufacturing quality management systems, with built-in nonconformance, CAPA, and audit management workflows aligned to AS9100D requirements.
PTC holds TISAX (Trusted Information Security Assessment Exchange) certification, enabling PTC to serve automotive OEM customers under VDA ISA security requirements. TISAX certification is required for suppliers and software vendors managing sensitive vehicle development data for German and European automotive manufacturers.