
Pegasystems
Security and trust center evidence
Summary
Pegasystems has 3 registry-verified rows and 1 third-party reported row in the CertReports index, last verified 17 Sep 2026. The strongest row is FedRAMP: FedRAMP Authorized. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Pegasystems is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 18 Mar 2025 and audited by Kratos. As of 17 Sep 2026, Pegasystems is listed in the CSA STAR registry with a STAR Level 2 certification and Trusted Cloud Provider status, issued 14 Nov 2019, which the registry notes is built on an ISO/IEC 27001 certification. As of 17 Sep 2026, no separately verified ISO/IEC 27001 certificate evidence was provided beyond this CSA STAR registry reference. As of 17 Sep 2026, Pegasystems is listed in the EU-US Data Privacy Framework registry as active for EU-US, Swiss-US, and UK Extension certifications, originally issued 16 Feb 2017 and currently set to expire 18 Feb 2027. As of 17 Sep 2026, no public evidence was found for SOC 2 or HIPAA for Pegasystems, and the subprocessor list evidence row indicates a count of zero disclosed subprocessors.
- FedRAMP: listed in FedRAMP registry as 'FedRAMP Authorized', issued 18 Mar 2025, audited by Kratos (as of 17 Sep 2026).
- CSA STAR / ISO 27001: listed in CSA STAR registry at Level 2 (Trusted Cloud Provider), issued 14 Nov 2019, noted as built on an ISO/IEC 27001 certification (as of 17 Sep 2026).
- EU-US Data Privacy Framework: listed in DPF registry as active (EU-US, SW-US, UK Extension), issued 16 Feb 2017, expires 18 Feb 2027 (as of 17 Sep 2026).
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among no-code and automation vendors
3verified rows
Category median 1, across 61 indexed no-code and automation vendors. Pegasystems has more verified rows than 100 percent of them.
business process automationcustomer engagementlow-code platformworkflow automation
Compare with similar vendors
Pick your own comparisonCompliance grid
- FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Kratos
ISO/IEC 27001ReportedCSA STAR Level 2 certification on the registry, which is built on an ISO/IEC 27001 certification
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 2 certification, Trusted Cloud Provider
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 20261 source
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this.
Subprocessors
No subprocessor list captured yet.
Similar vendors with evidence
Related by product tags and the No-code and automation category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.