
Iron Mountain
Security and trust center evidence
Summary
Iron Mountain has 2 registry-verified rows, and 1 expired in the CertReports index, last verified 17 Sep 2026. The strongest row is FedRAMP: FedRAMP Authorized. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Iron Mountain is listed in the FedRAMP registry as FedRAMP Authorized, with the authorization issued 15 Apr 2026 and audited by Coalfire Systems, Inc. As of 17 Sep 2026, Iron Mountain is listed in the Visa Global Registry as PCI DSS validated, but this validation expired on 31 Aug 2026 and should be treated as expired. As of 17 Sep 2026, Iron Mountain is listed in the EU-US Data Privacy Framework registry as holding Active EU-US, Swiss-US, and UK Extension certifications, effective since 07 Dec 2016 and current through 06 Sep 2027. As of 17 Sep 2026, no public evidence found for SOC 2 or ISO 27001 frameworks for Iron Mountain. As of 17 Sep 2026, no public evidence found for HIPAA compliance for Iron Mountain, so no BAA offering can be confirmed at this time.
- FedRAMP: listed in FedRAMP registry as FedRAMP Authorized, issued 15 Apr 2026, audited by Coalfire Systems, Inc. (as of 17 Sep 2026).
- PCI DSS: listed in Visa Global Registry as PCI DSS validated, but validation expired 31 Aug 2026 (as of 17 Sep 2026).
- EU-US Data Privacy Framework: listed in DPF registry as Active (EU-US, SW-US, UK Extension), effective 07 Dec 2016, expires 06 Sep 2027 (as of 17 Sep 2026).
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among cloud storage vendors
2verified rows
Category median 1, across 20 indexed cloud storage vendors. Iron Mountain has more verified rows than 95 percent of them.
compliance storagedata archivaldocument managementrecords management
Compare with similar vendors
Pick your own comparisonCompliance grid
- FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Lazarus Alliance, Inc.
PCI DSSExpiredListed on the Visa Global Registry as PCI DSS validated through 2026-08-31 (validation date passed)
as of 17 Sep 20261 source · Crowe LLP
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 20261 source
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this.
Subprocessors
No subprocessor list captured yet.
Similar vendors with evidence
Related by product tags and the Cloud storage category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.