Cloudflare logo

Cloudflare

Global CDN, DDoS mitigation, DNS, Zero Trust, and edge computing services delivered over Cloudflare's network.

✓ 20 of 32 frameworks
+ 3 partial
Security & General Standards
SOC 2 Type II

SOC 3

SOC 1 Type II

ISO 27001 (Information Security Management)

ISO 27017 (Cloud Security)

ISO 27018 (Cloud Privacy)

ISO 27701 (Privacy Information Management)

ISO 42001 (AI Management Systems)

ISO 9001 (Quality Management)

CSA STAR (Cloud Security Alliance)

HITRUST CSF

BSI C5 (German Cloud Security)

Privacy & Data Transfer
GDPR (EU)
~

GDPR is a regulation, not a certification; Cloudflare provides DPA/SCCs and dedicated GDPR trust-hub page.

CCPA / CPRA (California)

UK GDPR
~

UK GDPR is a regulation, not a certification; covered via UK addendum and UK Extension to DPF.

LGPD (Brazil)

PIPEDA (Canada)

DPDP Act (India)

PIPL (China)

EU-US Data Privacy Framework

Swiss-US Data Privacy Framework

Global CBPR (APEC)

Global PRP (APEC)

Industry & Government
HIPAA (US Healthcare)
~

HIPAA/HITECH: Cloudflare can sign BAAs for enterprise customers using its security products.

PCI DSS (Payment Card Industry)

FedRAMP (US Federal)

StateRAMP / TX-RAMP (US State)

DORA (EU Finance)

CJIS (US Law Enforcement)
?

Not publicly documented

FINRA (US Broker-Dealers)
?

Not publicly documented

IRAP (Australian Government)
?

Not publicly documented

Emerging & Strategic
NIST CSF (Cybersecurity Framework)

Data last verified: September 2026

Is this data outdated?

Spotted an error or a recent change in Cloudflare's posture? Submit a correction.

Submit a correction →

Work at Cloudflare?

Claim this profile to verify and enrich your compliance data.

Claim this profile →
← All Infrastructure & Cloud tools

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026