Zscaler adheres to rigorous security, availability, and privacy standards so customers can adopt our services with confidence.
Our compliance team works to ensure all Zscaler products are aligned and certified against internationally recognized government and commercial standards—frameworks to build customers' confidence by providing pertinent solutions. Zscaler compliance enablers are built on foundational programs focusing on data protection and regulatory requirements, including ISO 27001, ISO 27701, SOC 2, and various others, depending on the specific Zscaler product and customer needs. We are committed to ensuring that our global customers and partners can meet diverse compliance requirements.
View Zscaler's Website
SOC 2 Type 2
ISO/IEC 27001
ISO 22301- CSA STAR Level 2
FIPS 140-2
SOC 3
ISO/IEC 27017:2015
FIPS 140-3
ISO/IEC 27018:2019
CISA: Secure-by-Design Pledge- HIPAA
ISO/IEC 27701
C5
Cyber Essentials Plus
HITRUST- GDPR
TISAX
ISMAP
PCI DSS
CCCS - CSP ITS
DCSO Security Assessment
NIST 800-53 Rev. 5
MTCS Level 3
ENS
IRAP
G-Cloud
EU-US DPF
Swiss-US DPF
UK Extension to EU-US DPF
CPSTIC Prod Med
ITAR
China Cybersecurity Law (CSL)
ACN
FSQS- TruSight
CyberVadis Gold
SBOM
We are currently working with experts to put together our company policies. Please contact us for more details.
Compliance Center Updates
2026_CMMC Level 2 Certificate Published
Zscaler-2026_CMMC Level 2 Certificate Published
Zscaler-PCI Responsibility Matrix Published
Zscaler-PCI Responsibility Matrix Published
2026 C5 Report is now available.
2026 C5 Report is now available.
