certification
ISO/IEC 27001 evidence across 26 vendors
ISO/IEC 27001 certificates are issued by accredited certification bodies on a three-year cycle with annual surveillance audits. There is no crawlable public registry, so most rows begin as vendor-stated with a certificate number and upgrade to Verified through certification-body registers and the IAF CertSearch API.
- Verified rows
- 0
- Vendor-stated
- 26
- Expired
- 0
- Last verified
- 17 Sep 2026
Vanta
Compliance and GRC
Vanta—the proven leader in automated compliance helping startups…
CrowdStrike
Security
Datadog
DevOps and observability
Snowflake
Data platforms
Armis
Security
Drata
Compliance and GRC
Cyera
Security
GitLab
DevOps and observability
A complete DevOps platform delivered as a single application.
OpenAI
AI infrastructure
Wiz
Security
Okta
Identity and access
Twilio
Communications and CPaaS
Fortinet
Security
Diligent
Compliance and GRC
A-LIGN
Compliance and GRC
Ramp
Finance and accounting
KnowBe4
Security
Axon
Government and public sector
Intercom
Customer support
Zoom
Video conferencing
Vercel
Cloud and hosting
checkout
Payments
Bird
Communications and CPaaS
The world’s largest omnichannel communications platform
Sim
AI infrastructure
The AI Workspace for Building and Managing AI Agents.
The 2013 edition is lapsed
IAF MD 26:2023 set 31 October 2025 as the deadline for the transition to ISO/IEC 27001:2022. Any certificate still citing the 2013 edition is treated as lapsed regardless of its printed expiry.
Scope statements matter
A certificate covers the scope written on it. Check that the product you are buying is inside the certified scope and that the sites listed include where your data is processed.
