Microsoft Azure
Microsoft's cloud computing platform for building, deploying, and managing applications and services.
| Security & General Standards | |
|---|---|
| SOC 2 Type II | ✓ |
| SOC 3 | ✓ |
| SOC 1 Type II | ✓ |
| ISO 27001 (Information Security Management) | ✓ |
| ISO 27017 (Cloud Security) | ✓ |
| ISO 27018 (Cloud Privacy) | ✓ |
| ISO 27701 (Privacy Information Management) | ✓ |
| ISO 42001 (AI Management Systems) | ✓ |
| ISO 9001 (Quality Management) | ✓ |
| CSA STAR (Cloud Security Alliance) | ✓ |
| HITRUST CSF | ✓ |
| BSI C5 (German Cloud Security) | ✓ |
| Privacy & Data Transfer | |
| GDPR (EU) | ~ GDPR is a regulation, not a certification; Azure provides DPA/SCCs and control mappings. |
| CCPA / CPRA (California) | ? Not publicly documented |
| UK GDPR | ~ UK GDPR is a regulation, not a certification; covered via UK addendum and UK Extension to DPF. |
| LGPD (Brazil) | ? Not publicly documented |
| PIPEDA (Canada) | ✓ |
| DPDP Act (India) | ? Not publicly documented |
| PIPL (China) | ? Not publicly documented |
| EU-US Data Privacy Framework | ✓ |
| Swiss-US Data Privacy Framework | ✓ |
| Global CBPR (APEC) | ? Not publicly documented |
| Global PRP (APEC) | ? Not publicly documented |
| Industry & Government | |
| HIPAA (US Healthcare) | ~ HIPAA is a regulation; Azure offers BAA via Microsoft Product Terms and HIPAA/HITRUST built-in policy initiative. |
| PCI DSS (Payment Card Industry) | ✓ |
| FedRAMP (US Federal) | ✓ |
| StateRAMP / TX-RAMP (US State) | ✓ |
| DORA (EU Finance) | ✓ |
| CJIS (US Law Enforcement) | ✓ |
| FINRA (US Broker-Dealers) | ✓ |
| IRAP (Australian Government) | ✓ |
| Emerging & Strategic | |
| NIST CSF (Cybersecurity Framework) | ✓ |
Data last verified: September 2026
Is this data outdated?
Spotted an error or a recent change in Microsoft Azure's posture? Submit a correction.
Submit a correction →Work at Microsoft Azure?
Claim this profile to verify and enrich your compliance data.
Claim this profile →