Saltar a contenido
Shared - Banner with Media - Background

Security compliance and certifications

Sophos continuously monitors evolving regulatory standards across the globe. We incorporate the latest relevant controls into our organisation, products, and technology to help our customers meet their compliance obligations.

22 Compliance frameworks

AICPA SOC logo

SOC 2

Validates how we manage customer data across security, availability, confidentiality, and privacy.

ISO

ISO 27001:2022

Demonstrates integration of security, privacy, and ongoing improvement into our daily operations.

ISO

ISO 27017:2015

Establishes information security controls that are specific to public cloud environments.

ISO

ISO 27018:2019

Establishes information security controls for protecting personally identifiable information (PII) data in public cloud environments.

TX RAMP

TX-RAMP

Products certified under the Texas Risk and Authorization Management Program (TX-RAMP) demonstrate compliance with rigorous security standards required for Texas state agencies and public institutions.

PCI DSS logo

PCI DSS

Protects credit card data by ensuring secure storage, transmission, and handling of payment info.

C5 Germany

Established by the German Federal Office for Information Security (BSI) to define a comprehensive set of security and compliance requirements for cloud service providers.

HIPAA logo

HIPAA

Protects the privacy and security of medical records and health information in the U.S. healthcare industry.

GDPR logo

GDPR

Ensures data protection and privacy for individuals in the EU and EEA, including data transfers beyond these regions.

CPRA logo

CPRA

Expands California consumer privacy rights and protections, with new enforcement through the CPPA.

NIST logo

NIST SP800-171

Outlines safeguards for controlled unclassified information in non-federal systems.

HITRUST logo

HITRUST CSF

Combines multiple standards to manage risk and ensure compliance across the healthcare industry.

NIS2 logo

NIS2

Sets stricter cybersecurity rules across the EU for infrastructure and digital service providers.

Digital Operational Resilience Act (DORA 2022/2554)

The EU’s Digital Operational Resilience Act (DORA 2022/2554) regulates financial entities through contractual requirements with technology providers, including cybersecurity.

SOX

US federal law enacted to improve corporate governance and provide more transparency for investors.

FCC logo

CIPA

Establishes technologic requirements to protect children from harmful content online.

NIS2 logo

NIS Directive

The first piece of EU-wide legislation on cybersecurity, it provides legal measures to boost the overall level of cybersecurity in the EU.

POPI

South African data protection law designed to safeguard personal information and establishes rights for individuals to have control over their personal data.

NIST logo

NIST CSF

Framework based on five core functions to manage cybersecurity risks: identify, protect, detect, respond, and recover.

New York State

NYDFS

The New York State Department of Financial Services (NYDFS) regulates financial institutions and services operating in New York State.

Ohio DPA

State-level legislation designed to protect Ohioans’ sensitive personal information and establishes cybersecurity standards for organizations to follow.

ASD logo

ASD

Data sovereignty and security solutions for organizations in Australia that have strict national or local regulatory or policy requirements

CIS Controls logo

CIS Controls

Set of best practices and cybersecurity requirements developed by the Center of Internet Security (CIS)

*Reports available to interested parties once an NDA has been signed. Please contact your account manager or Sophos sales to request a copy.