
Vendor-statedCrowdStrike and ISO/IEC 27001
CrowdStrike states it holds an ISO/IEC 27001 certificate. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- certificate
- Issued or listed
- 28 Feb 2017
| Source | Captured | Quote | Links |
|---|---|---|---|
CSA STAR registry (Level 2 basis) Official registry · HTTP 200 | 17 Sep 2026 | crowdstrike, inc: STAR Level 2 certification | Live pagesha256 e7f124247f |
What is not public
- The certificate expiry and scope statement are not in a public source yet; the state will move to Verified when a certification body register or the IAF CertSearch API confirms them.
What ISO/IEC 27001 means, and what it does not
Certified by an accredited certification body on a three-year cycle with annual surveillance. Scope statements matter and expiry drives the state. Any certificate still citing ISO/IEC 27001:2013 is treated as lapsed because the IAF transition deadline of 31 October 2025 has passed.
Read the ISO/IEC 27001 guide and browse all vendors with evidenceQuestions buyers ask
Is CrowdStrike ISO 27001 certified?
CrowdStrike states it holds an ISO/IEC 27001 certificate as of 17 Sep 2026. Scope statements matter; check the certificate scope covers the product you are buying.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
Alternatives with ISO 27001 evidence
Similar vendors (shared product tags or the Security category) whose ISO 27001 row is verified or vendor-stated, ranked by similarity.