Skip to main content
CrowdStrike logo

CrowdStrike

Security and trust center evidence

crowdstrike.comSecurityLast verified 17 Sep 2026

Summary

CrowdStrike has 3 registry-verified rows and 12 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 17 Sep 2026, CrowdStrike states on its trust centre that it holds SOC 2, and separately states on its trust centre that it holds ISO/IEC 27001, PCI DSS, GDPR, ISO/IEC 42001, ISO/IEC 27017, ISO 22301, Cyber Essentials, GovRAMP, TISAX, BSI C5, and ENS coverage, though none of these are corroborated by a registry as of 17 Sep 2026. As of 17 Sep 2026, CrowdStrike is listed in the FedRAMP registry as FedRAMP Authorized, with the authorization issued 12 Mar 2025 and audited by Schellman Compliance, LLC. As of 17 Sep 2026, CrowdStrike is listed in the CSA STAR registry as holding a STAR Level 2 certification issued 28 Feb 2017. As of 17 Sep 2026, CrowdStrike is listed in the EU-US Data Privacy Framework registry as active for EU-US, Swiss-US, and UK Extension certifications, with the current certification period expiring 10 Oct 2026. No public evidence found for a HIPAA BAA offering as of 17 Sep 2026.

  • FedRAMP: listed in FedRAMP registry as Authorized, issued 12 Mar 2025, audited by Schellman Compliance, LLC (as of 17 Sep 2026).
  • CSA STAR: listed in CSA STAR registry, STAR Level 2 certification issued 28 Feb 2017 (as of 17 Sep 2026).
  • EU-US Data Privacy Framework: listed in DPF registry as active (EU-US, Swiss-US, UK Extension), current period expires 10 Oct 2026 (as of 17 Sep 2026).

Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.

Among security vendors

3verified rows

Category median 1, across 174 indexed security vendors. CrowdStrike has more verified rows than 100 percent of them.

endpoint-protectionincident-responsemanaged-detection-responsethreat-detection

Compliance grid

No public evidence yet for HIPAA, ISO 27701. This does not mean the vendor lacks them; it means nothing public was found at the last check.

Subprocessors (6)

  • BC
    Business Continuity Management System Cloud
  • CT
    Compliance The CrowdStrike Falcon Platform
  • CF
    CrowdStrike Falcon Platform
  • FP
    Falcon Platform
  • PM
    Patch Management Amazon Web Services
  • S2
    SOC 2 Type II Report for the Falcon Platform

Change history

  1. 17 Sep 2026BSI C5 evidence addedA BSI C5 row entered the index with state Vendor-stated.
  2. 17 Sep 2026Cyber Essentials evidence addedA Cyber Essentials row entered the index with state Vendor-stated.
  3. 17 Sep 2026ENS evidence addedA ENS row entered the index with state Vendor-stated.
  4. 17 Sep 2026FedRAMP evidence addedA FedRAMP row entered the index with state Verified.
  5. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  6. 17 Sep 2026GovRAMP evidence addedA GovRAMP row entered the index with state Vendor-stated.
  7. 17 Sep 2026ISO 22301 evidence addedA ISO 22301 row entered the index with state Vendor-stated.
  8. 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
  9. 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
  10. 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.

Similar vendors with evidence

Related by product tags and the Security category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.