Cloudflare Expands Compliance Portfolio With New Certifications and Reports
Cloudflare has spent the past year broadening the scope of its existing security and privacy validations while adding several new certifications to its portfolio. The company also launched its Security Center product earlier this week, which helps customers map their attack surface and identify potential security risks. These compliance updates are intended to keep pace with the company's rapid product expansion and ensure customer confidence in how sensitive data is handled.
New Certifications and Milestones in 2021
Cloudflare has achieved several significant compliance milestones this year, including a major step toward serving the public sector.

Cloudflare is now listed as "In Process" on the FedRAMP Marketplace for receiving an agency authorization at a moderate baseline. Once an Authorization to Operate (ATO) is granted, the company will be able to offer its products and services to government agencies and other cloud service providers in a public sector capacity.
The company also achieved ISO 27701:2019 certification as both a data processor and controller, making it one of the first in the industry to do so. This certification demonstrates that Cloudflare maintains a formal privacy program aligned with GDPR requirements.
Additionally, Pro, Business, and Enterprise customers can now access Cloudflare's certifications, reports, and overview documentation directly through the Cloudflare Dashboard.
Maintained Security Certifications and Reports
Cloudflare periodically renews and expands the scope of its existing compliance validations to ensure all applicable products and services are covered. The company currently maintains the following certifications and reports.

Cloudflare's SOC-2 Type II and SOC 3 reports cover the security, confidentiality, and availability trust principles. The reports are produced annually by third-party assessors and provide assurance that Cloudflare's products and underlying infrastructure are secure, highly available, and protect customer data confidentiality.
The company has maintained ISO 27001:2013 certification since 2019, demonstrating that its information security management program adheres to a globally recognized standard.

Cloudflare is evaluated annually as a Level 1 Merchant and Service Provider by a Qualified Security Assessor (QSA) under the PCI Data Security Standard (DSS). This validates that the company meets requirements for securely transmitting payment data and that its services support customers' own DSS compliance.
Cloudflare also supports covered healthcare entities using its enterprise security products by signing Business Associates Agreements (BAA) under the HIPAA/HITECH Act.

In addition to these security certifications, Cloudflare conducted a first-of-its-kind privacy examination of its 1.1.1.1 public DNS resolver. A leading accounting firm assessed whether the resolver was effectively configured to meet Cloudflare's privacy commitments. A public summary of the assessment is available online.
Future Compliance Work
Cloudflare is currently evaluating ISO 27018, which would provide additional assurance that the company meets industry standards for handling personal data in its cloud platform. The company will also continue progressing through the FedRAMP authorization process and is evaluating other region-specific certifications. Existing customers can provide feedback on validations through their Account Executive.



