{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"esri","name":"ESRI","domain":"esri.com","category":"Analytics","one_liner":"Esri’s GIS software is the most powerful mapping & spatial analytics technology","trust_center_url":null,"security_page_url":null,"url":"https://certreports.com/vendors/esri/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 19 Sep 2026.","kind":"authorization","status_text":"FedRAMP Authorized","issued_at":"2015-08-20","expires_at":null,"period_start":null,"period_end":null,"auditor":"Coalfire Systems, Inc.","impact_level":"Moderate","as_of":"2026-09-19","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/esri/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/F1311252651","fetched_at":"2026-09-19 08:30:01.700532+00","content_hash":"b2bb3e031fda16f1f3201a5640ae64a639a15e4997f9d1ca43ef13a2942600e6","wayback_url":null,"quote":"ESRI - Esri Managed Cloud Services Advanced Plus: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/F1311252651","fetched_at":"2026-09-18 22:35:17.44827+00","content_hash":"db2d03fa40cba0e5287b9cc7361e71b7c30c7ca9d51efb7b540477105fb30c7b","wayback_url":null,"quote":"ESRI - Esri Managed Cloud Services Advanced Plus: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/F1311252651","fetched_at":"2026-09-17 15:44:39.301965+00","content_hash":"395e7ad35dd25d1c547414140161c47ec22827b7ffae3bdbbd5256c38a3b940f","wayback_url":null,"quote":"ESRI - Esri Managed Cloud Services Advanced Plus: FedRAMP Authorized","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: UK Extension Certification, EU-US Certification, SW-US Certification","issued_at":"2017-02-07","expires_at":"2026-11-03","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/esri/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/5738","fetched_at":"2026-09-17 15:49:08.544366+00","content_hash":"41dee23e24e4bc2cea7af411e2b774fab85391aeeacd159255a2ab4feda66b5b","wayback_url":null,"quote":"Esri: Active: UK Extension Certification, EU-US Certification, SW-US Certification","confidence":1}]}],"brief":{"summary":"ESRI is listed in the FedRAMP registry as FedRAMP Authorized, originally authorized 20 Aug 2015 and audited by Coalfire Systems, Inc., as of 19 Sep 2026. The FedRAMP registry record for ESRI has been maintained since 2015, as of 19 Sep 2026. ESRI is also listed in the EU-US Data Privacy Framework registry as active for the EU-US, Swiss-US, and UK Extension certifications, as of 17 Sep 2026. That Data Privacy Framework listing dates from 7 Feb 2017 and is set to expire 3 Nov 2026, as of 17 Sep 2026. No public evidence was found for SOC 2, ISO/IEC, PCI DSS, or HIPAA frameworks for ESRI as of 19 Sep 2026.","bullets":["FedRAMP Authorized since 20 Aug 2015 (Coalfire Systems, Inc.), as of 19 Sep 2026.","EU-US Data Privacy Framework active (EU-US, SW-US, UK Extension), expires 3 Nov 2026, as of 17 Sep 2026.","No public evidence found for SOC 2, ISO/IEC, PCI DSS, or HIPAA as of 19 Sep 2026."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 11:57:36.010119+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T01:15:14.772Z"}