
Summary
KnowBe4 has 2 registry-verified rows and 10 vendor-stated rows, and 1 expired in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 Type 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, KnowBe4 states on its trust centre that it holds SOC 2 Type II, and has a SOC 2 Type II report per that same 17 Sep 2026 evidence. As of 17 Sep 2026, KnowBe4 is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 14 Nov 2023 and audited by Fortreum, LLC. As of 17 Sep 2026, KnowBe4 is listed in the CSA STAR registry at Level 1 self-assessment (CAIQ), Trusted Cloud Provider, with an entry dated 11 Dec 2018. As of 17 Sep 2026, KnowBe4 states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 27701:2019, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 42001:2023, SOC 3, Cyber Essentials, GDPR, and CCPA compliance, and the EU-US Data Privacy Framework entry as of 17 Sep 2026 is marked expired, with an original entry dated 23 May 2018. No public evidence found for a HIPAA BAA as of 17 Sep 2026, and no subprocessor list was found in the evidence provided as of 17 Sep 2026.
- SOC 2: vendor states on its trust centre it has a SOC 2 Type II report (as of 17 Sep 2026, source: Drata).
- FedRAMP: listed in FedRAMP registry as Authorized, issued 14 Nov 2023, auditor Fortreum, LLC (as of 17 Sep 2026).
- EU-US Data Privacy Framework: expired entry dated 23 May 2018 (as of 17 Sep 2026); no public evidence found for HIPAA BAA as of 17 Sep 2026.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among security vendors
2verified rows
Category median 1, across 174 indexed security vendors. KnowBe4 has more verified rows than 91 percent of them.
email securityhuman riskphishing preventionsecurity awareness training
Compare with similar vendors
Pick your own comparisonCompliance grid
SOC 2Vendor-statedVendor states SOC 2 Type 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source - FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Fortreum, LLC
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 1 self-assessment (CAIQ), Trusted Cloud Provider
as of 17 Sep 20261 source
Cyber EssentialsVendor-statedVendor states Cyber Essentials on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27701Vendor-statedVendor states ISO/IEC 27701:2019 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 17 Sep 20261 source
SOC 3Vendor-statedVendor states SOC 3 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkExpiredInactive
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 17 Sep 20261 source
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.
Change history
- 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
- 17 Sep 2026Cyber Essentials evidence addedA Cyber Essentials row entered the index with state Vendor-stated.
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27701 evidence addedA ISO/IEC 27701 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 3 evidence addedA SOC 3 row entered the index with state Vendor-stated.
Similar vendors with evidence
Related by product tags and the Security category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.