Skip to main content
CrowdStrike logo

CrowdStrike

ISO/IEC 27001 evidence

crowdstrike.comSecurityLast verified 17 Sep 2026
ISO/IEC 27001 mark, CertReports state Vendor-stated as of 17 Sep 2026Vendor-stated

CrowdStrike and ISO/IEC 27001

CrowdStrike states it holds an ISO/IEC 27001 certificate. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
CrowdStrike trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026ISO/IEC 27001
Live page Snapshotsha256 feee5929a6
ReportedCSA STAR Level 2 certification on the registry, which is built on an ISO/IEC 27001 certification
as of 17 Sep 2026 · confidence 80%
Kind
certificate
Issued or listed
28 Feb 2017
SourceCapturedQuoteLinks
CSA STAR registry (Level 2 basis)
Official registry · HTTP 200
17 Sep 2026crowdstrike, inc: STAR Level 2 certification
Live pagesha256 e7f124247f
Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
CrowdStrike trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026ISO/IEC 27017:2015
Live page Snapshotsha256 feee5929a6
Vendor-statedVendor states ISO 22301:2019 on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
CrowdStrike trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026ISO 22301:2019
Live page Snapshotsha256 feee5929a6

What is not public

  • The certificate expiry and scope statement are not in a public source yet; the state will move to Verified when a certification body register or the IAF CertSearch API confirms them.
What ISO/IEC 27001 means, and what it does not

Certified by an accredited certification body on a three-year cycle with annual surveillance. Scope statements matter and expiry drives the state. Any certificate still citing ISO/IEC 27001:2013 is treated as lapsed because the IAF transition deadline of 31 October 2025 has passed.

Read the ISO/IEC 27001 guide and browse all vendors with evidence

Questions buyers ask

Is CrowdStrike ISO 27001 certified?

CrowdStrike states it holds an ISO/IEC 27001 certificate as of 17 Sep 2026. Scope statements matter; check the certificate scope covers the product you are buying.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.

Alternatives with ISO 27001 evidence

Similar vendors (shared product tags or the Security category) whose ISO 27001 row is verified or vendor-stated, ranked by similarity.