
Summary
Mimecast has 3 registry-verified rows and 1 third-party reported row in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: CSA STAR Level 2 attestation on the registry, which is built on a SOC 2 examination. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Mimecast is listed in the CSA STAR registry with a Level 2 attestation issued 28 Sep 2015, which the registry notes is built on a SOC 2 examination, though no separate SOC 2 Type II report evidence is provided as of 17 Sep 2026. As of 17 Sep 2026, Mimecast is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 8 Dec 2020 and audited by Deloitte & Touche LLP. As of 17 Sep 2026, Mimecast is listed in the CSA STAR registry with a Level 2 attestation dated 28 Sep 2015. As of 17 Sep 2026, Mimecast is listed in the EU-US Data Privacy Framework registry as active, covering SW-US, UK Extension, and EU-US certifications, issued 31 Jul 2018 and expiring 10 Jul 2027. As of 17 Sep 2026, no public evidence found for HIPAA compliance or subprocessor disclosures for Mimecast.
- Listed in FedRAMP registry as FedRAMP Authorized (issued 8 Dec 2020; auditor Deloitte & Touche LLP) as of 17 Sep 2026.
- Listed in CSA STAR registry with a Level 2 attestation issued 28 Sep 2015, noted as built on a SOC 2 examination, as of 17 Sep 2026.
- Listed in EU-US Data Privacy Framework registry as active (SW-US, UK Extension, EU-US Certifications), issued 31 Jul 2018, expiring 10 Jul 2027, as of 17 Sep 2026.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among security vendors
3verified rows
Category median 1, across 174 indexed security vendors. Mimecast has more verified rows than 100 percent of them.
cloud emaildata loss preventionemail securitythreat protection
Compare with similar vendors
Pick your own comparisonCompliance grid
SOC 2ReportedCSA STAR Level 2 attestation on the registry, which is built on a SOC 2 examination
as of 17 Sep 20261 source- FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Deloitte & Touche LLP - CSA STARVerified
STAR Level 2 attestation
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: SW-US Certification, UK Extension Certification, EU-US Certification
as of 17 Sep 20261 source
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.
Similar vendors with evidence
Related by product tags and the Security category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.