Compliance at Zoom
Trust requires transparency. Our extensive library of compliance certifications and attestations highlight our security and privacy practices to help you feel informed and work with ease.
Compliance made clear
From compliance audits to industry-standard certifications, our program is designed to support your most important security and privacy requirements.
Commercial certifications and attestations
ISO 27017 / 18
Globally recognized certification on privacy and cloud computing
SOC 2 Type 2
SOC 2 Type 2 report covering Security, Availability, Confidentiality, and Privacy
SOC 2 + HITRUST
SOC 2 Type 2 report that includes controls relevant to HITRUST
CSA STAR Level 2
Registry of security and compliance controls for cloud service offerings
UK Cyber Essentials Plus
UK Government information security assurance scheme
ENS
Security standards for all government agencies and public organizations in Spain
BSI C5
Security of cloud services that leverages internationally recognized security standards
ISMAP
Evaluates cloud service providers against Japanese government security requirements.
ETDA
Promotes digital governance of electronic transactions under the Electronic Transactions Act
PCI DSS
PCI compliant solution for Zoom Phone and Zoom Contact Center leveraging an integration with PCIpal
TX-RAMP
The Texas Risk and Authorization Management Program provides a standardized approach for security assessment.
Japanβs FISC
Promotes security measures for financial institutions and developed banking information system security guidelines
HDS
HΓ©bergeur de DonnΓ©es de SantΓ© is a French certification framework established by the Agence du NumΓ©rique en SantΓ© (ANS) to ensure secure hosting of health data
MASA
Promotes cybersecurity certification mechanisms for mobile applications in Taiwan
Zoom for Government certifications and attestations
FedRAMP Moderate
US Government security standard for cloud products and service
Gov-RAMP
State and local government
cybersecurity standard for service providers
TX-RAMP
The Texas Risk and Authorization Management Program provides a standardized approach for security assessment.
DODIL4
Cloud computing security requirements for the US Department of Defense
