Summary
Cyera has 3 registry-verified rows and 8 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Cyera states on its trust centre that it holds SOC 2, and no auditor or report date is provided in the evidence. As of 17 Sep 2026, Cyera displays a HIPAA badge on its trust centre, described as a claim with BAA availability not yet captured, so this should be treated as offers a BAA pending confirmation rather than a verified attestation. As of 17 Sep 2026, Cyera is listed in the FedRAMP registry with status 'Agency In Process', with Schellman Compliance, LLC named as auditor. As of 17 Sep 2026, Cyera is listed in the CSA STAR registry with a Level 1 self-assessment (CAIQ) issued 6 Dec 2023, and is listed in the EU-US Data Privacy Framework registry as active (EU-US Certification, UK Extension Certification) issued 23 Oct 2025 and expiring 23 Oct 2026. As of 17 Sep 2026, Cyera also states on its trust centre that it holds GDPR, PCI DSS, ISO/IEC 27001:2022, CCPA/CPRA, BSI C5, and ENS coverage, with no public evidence found to independently verify these vendor statements.
- SOC 2: vendor states on its trust centre that it holds a SOC 2 report (as of 17 Sep 2026); no auditor or report period supplied.
- FedRAMP: listed in FedRAMP registry as 'Agency In Process' with auditor Schellman Compliance, LLC (as of 17 Sep 2026); CSA STAR Level 1 self-assessment issued 6 Dec 2023; EU-US Data Privacy Framework listing active from 23 Oct 2025 to 23 Oct 2026 (as of 17 Sep 2026).
- HIPAA: vendor displays a HIPAA badge on its trust centre described as a claim, with BAA availability not yet captured (as of 17 Sep 2026); ISO/IEC 27001:2022, GDPR, PCI DSS, CCPA/CPRA, BSI C5, and ENS are all vendor-stated on its trust centre with no public evidence found to verify them independently.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among security vendors
3verified rows
Category median 1, across 174 indexed security vendors. Cyera has more verified rows than 100 percent of them.
data classificationdata discoverydata protectiondlp
Compare with similar vendors
Pick your own comparisonCompliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 17 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source - FedRAMPVerified
Agency In Process
as of 17 Sep 20261 source · Schellman Compliance, LLC
PCI DSSVendor-statedVendor states PCI DSS on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001:2022 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 1 self-assessment (CAIQ)
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, UK Extension Certification
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 17 Sep 20261 source
BSI C5Vendor-statedVendor states C5 on its trust centre
as of 17 Sep 20261 source
ENSVendor-statedVendor states ENS on its trust centre
as of 17 Sep 20261 source
No public evidence yet for Cyber Essentials, ISO 27701, ISO 42001. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
Subprocessors (1)
- SMStatus Monitoring Amazon Web Services
Change history
- 17 Sep 2026BSI C5 evidence addedA BSI C5 row entered the index with state Vendor-stated.
- 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
- 17 Sep 2026ENS evidence addedA ENS row entered the index with state Vendor-stated.
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 17 Sep 2026Subprocessor added: Status Monitoring Amazon Web ServicesStatus Monitoring Amazon Web Services appeared on the subprocessor list.
Similar vendors with evidence
Related by product tags and the Security category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.
