Cloudflare was built to help you and your customers be more secure on the Internet. Learn about the certifications that help us preserve that security.
ISO/IEC 27001:2013 is an industry-wide accepted information security certification that focuses on the implementation of an Information Security Management System (ISMS) and security risk management processes. Cloudflare has been ISO 27001 certified since 2019 and the certificate is available upon request.
ISO/IEC 27701:2019 is a new ISO privacy certification, implementing a comprehensive Privacy Information Management System (PIMS) aligned with various privacy regulations including the GDPR. Cloudflare has been ISO 27701 certified as a PII Processor and PII Controller since 2021 and the certificate is available upon request.
Cloudflare has undertaken the AICPA SOC 2 Type II certification to attest to Security, Confidentiality, and Availability controls in place in accordance to the AICPA Trust Service Criteria. Cloudflare's SOC 2 Type II report covers security, confidentiality, and availability controls to protect customer data and is available upon request.
Cloudflare maintains PCI DSS Level 1 compliance and has been PCI compliant since 2014. Cloudflare's Web Application Firewall (WAF), Cloudflare Access, Content Delivery Network (CDN), Time Service, Workers, and Workers KV are PCI compliant solutions. Cloudflare is audited annually by a third-party Qualified Security Assessor QSA. Cloudflare's Attestation of Compliance is available upon request
On April 1, 2018, we took a big step toward improving Internet privacy and security with the launch of the 18.104.22.168 public DNS resolver - the Internet's fastest, privacy-first public DNS resolver. Cloudflare conducted a first-of-its-kind privacy examination by a Big Four accounting firm to determine whether the 22.214.171.124 resolver was effectively configured to meet Cloudflare’s privacy commitments. See below for more information.
Cloudflare has been recognized by the German government's Federal Office for Information Security as an qualified provider of DDoS mitigation services. Download this qualification to learn more.