Summary
Fortinet has 2 registry-verified rows and 10 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Fortinet states on its trust centre that it holds SOC 2, though no separate report detail is provided in this evidence. As of 17 Sep 2026, Fortinet displays a HIPAA badge on its trust centre as a vendor claim, with BAA availability not yet captured, so this should be confirmed directly with the vendor. As of 17 Sep 2026, Fortinet states on its trust centre that it holds GDPR, ISO/IEC 27001, ISO/IEC 27017:2015, ISO/IEC 27018:2019, TISAX, BSI C5, ENS, and ISMAP alignment, all as unverified vendor statements. As of 15 Dec 2022, Fortinet is listed in the CSA STAR registry with a Level 1 self-assessment (CAIQ), a status that has not been refreshed in subsequent rows as of 17 Sep 2026. As of 17 Sep 2026, Fortinet is listed in the EU-US Data Privacy Framework registry as active for EU-US, Swiss-US, and UK Extension certifications, with an issue date of 12 Sep 2024 and an expiry date of 22 Oct 2026 that reviewers should monitor as it approaches.
- SOC 2: Fortinet states on its trust centre that it holds SOC 2 (vendor statement, as of 17 Sep 2026); no independent report evidence supplied.
- HIPAA: Fortinet displays a HIPAA badge on its trust centre as of 17 Sep 2026, but BAA availability is not yet captured — confirm directly with vendor.
- EU-US Data Privacy Framework: listed in DPF registry as active (EU-US, SW-US, UK Extension), issued 12 Sep 2024, expiring 22 Oct 2026, as of 17 Sep 2026.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among security vendors
2verified rows
Category median 1, across 174 indexed security vendors. Fortinet has more verified rows than 91 percent of them.
endpoint securityfirewallnetwork securitythreat protection
Compare with similar vendors
Pick your own comparisonCompliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 17 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 1 self-assessment (CAIQ)
as of 17 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 20261 source
TISAXVendor-statedVendor states TISAX on its trust centre
as of 17 Sep 20261 source
BSI C5Vendor-statedVendor states C5 on its trust centre
as of 17 Sep 20261 source
ENSVendor-statedVendor states ENS on its trust centre
as of 17 Sep 20261 source
ISMAPVendor-statedVendor states ISMAP on its trust centre
as of 17 Sep 20261 source
No public evidence yet for FedRAMP, PCI DSS, Cyber Essentials, ISO 27701, ISO 42001. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
Subprocessors (8)
- APAdded Pendo for FortiDLP. Added AWS
- FCFortiMail Cloud became FortiMail Cloud
- FCFortiManager Cloud
- FOFortiWebCloud
- GUGeneral Updates to Fortinet Cloud
- GCGrafana Cloud and Slack. Oracle Cloud
- SASubprocessors Added MS Azure
- UTUpdates to Cloud
Change history
- 17 Sep 2026BSI C5 evidence addedA BSI C5 row entered the index with state Vendor-stated.
- 17 Sep 2026ENS evidence addedA ENS row entered the index with state Vendor-stated.
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
- 17 Sep 2026ISMAP evidence addedA ISMAP row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 17 Sep 2026TISAX evidence addedA TISAX row entered the index with state Vendor-stated.
Similar vendors with evidence
Related by product tags and the Security category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.