
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Fri, 10 Apr 2026 11:35:46 GMT</lastBuildDate>
        <item>
            <title><![CDATA[Cloudflare re-enforces commitment to security in Germany via BSIG audit]]></title>
            <link>https://blog.cloudflare.com/bsig-audit-and-beyond/</link>
            <pubDate>Thu, 24 Feb 2022 17:30:16 GMT</pubDate>
            <description><![CDATA[ As Cloudflare expands globally, Rebecca Rogers, Manager of Security Validations, discusses an exciting update to Cloudflare’s commitment to customer security for our German customers ]]></description>
            <content:encoded><![CDATA[ <p></p><p>As a large data processing country, Germany is at the forefront of security and privacy regulation in Europe and sets the tone for other countries to follow. Analyzing and meeting the requirements to participate in Germany’s cloud security industry requires adherence to international, regional, and country-specific standards. Cloudflare is pleased to announce that we have taken appropriate organizational and technical precautions to prevent disruptions to the availability, integrity, authenticity, and confidentiality of Cloudflare’s production systems in accordance with BSI-KritisV. TÜViT, the auditing body tasked with auditing Cloudflare and providing the evidence to BSI every two years. Completion of this audit allows us to comply with the NIS Directive within Germany.</p>
    <div>
      <h3>Why do cloud companies operating in Germany need to go through a BSI audit?</h3>
      <a href="#why-do-cloud-companies-operating-in-germany-need-to-go-through-a-bsi-audit">
        
      </a>
    </div>
    <p>In 2019, Cloudflare registered as an Operator of Essential Services’ under the EU Directive on Security of Network and Information Systems (NIS Directive). The NIS Directive is cybersecurity legislation with the goal to enhance <a href="https://www.cloudflare.com/learning/security/what-is-cyber-security/">cybersecurity</a> across the EU. Every member state has started to adopt national legislation for the NIS Directive and the criteria for compliance is set individually by each country. As an ‘Operator of Essential Services’ in Germany, Cloudflare is regulated by the <a href="https://www.bsi.bund.de/DE/Home/home_node.html">Federal Office for Information Security</a> (The BSI) and must adhere to the requirements set by The BSI.</p>
    <div>
      <h3>What does the audit prove?</h3>
      <a href="#what-does-the-audit-prove">
        
      </a>
    </div>
    <p>This audit includes a thorough review of Cloudflare’s security controls in the following areas:</p><ul><li><p>Asset Management</p></li><li><p>Risk Analysis</p></li><li><p>Business Continuity and Disaster Recovery</p></li><li><p>Personnel and Organizational Security</p></li><li><p>Encryption</p></li><li><p>Network Security</p></li><li><p>Security Authentication</p></li><li><p>Incident Response</p></li><li><p>Vendor Security</p></li><li><p>Physical Security</p></li></ul><p>In addition to an audit of Cloudflare’s security controls in the aforementioned areas, TÜViT also conducted a thorough review of Cloudflare’s Information Security Management System (ISMS).</p><p>By having these areas audited, German customers can rest assured that Cloudflare respects the requirements put forth by the governing bodies tasked with protecting their data.</p>
    <div>
      <h3>Are there any additional German-specific audits on the horizon?</h3>
      <a href="#are-there-any-additional-german-specific-audits-on-the-horizon">
        
      </a>
    </div>
    <p>Yes. Cloudflare is currently undergoing an independent third-party audit for the Cloud Computing Compliance Criteria Catalog (C5) certification. The C5 was introduced by BSI Germany in 2016 and reviews operational security within cloud services. Industries that place a high level of importance on C5 include cloud computing and German federal agencies. Learn more <a href="https://www.bsi.bund.de/EN/Topics/CloudComputing/Compliance_Criteria_Catalogue/Compliance_Criteria_Catalogue_node.html">here</a>.</p>
    <div>
      <h3>What other certifications does Cloudflare hold that demonstrate its dedication to privacy and security?</h3>
      <a href="#what-other-certifications-does-cloudflare-hold-that-demonstrate-its-dedication-to-privacy-and-security">
        
      </a>
    </div>
    <p>Different certifications measure different elements of a company’s security or privacy posture. Cloudflare has met the requirements of the following standards:</p><ul><li><p><b>ISO 27001 -</b> Cloudflare has been ISO 27001 certified since 2019. Customers can be assured that Cloudflare has a formal information security management program that adheres to a globally recognized standard.</p></li><li><p><b>SOC2 Type II</b> - Cloudflare maintains SOC reports that include the security, confidentiality, and availability trust principles.</p></li><li><p><a href="https://www.cloudflare.com/learning/privacy/what-is-pci-dss-compliance/"><b>PCI DSS</b></a><b> -</b> Cloudflare engages with a QSA (Qualified Security Assessor) on an annual basis to evaluate us as a Level 1 Merchant and a Service Provider.</p></li><li><p><b>ISO 27701</b> - Cloudflare was one of the first companies in the industry to achieve ISO 27701 certification as both a data processor and controller. The certification provides assurance to our customers that we have a formal privacy program that is aligned to GDPR.</p></li><li><p><b>FedRAMP In Process</b> - Cloudflare hit a major milestone by being listed on the <a href="https://marketplace.fedramp.gov/#!/product/cloudflare-federal?sort=productName">FedRAMP Marketplace</a> as ‘In Process’ for receiving an <a href="https://www.cloudflare.com/learning/privacy/what-is-fedramp/">agency authorization</a> at a moderate baseline. Once an Authorization to Operate (ATO) is granted, it will allow agencies and other cloud service providers to leverage our product and services in a public sector capacity.</p></li></ul><p>Pro, Business, and Enterprise customers now have the ability to obtain a copy of Cloudflare’s certifications, reports, and overview through the <a href="https://support.cloudflare.com/hc/en-us/articles/4412661740941-Access-Compliance-Documentation">Cloudflare Dashboard</a>. For the latest information about our certifications and reports, please visit <a href="https://www.cloudflare.com/trust-hub">our</a> <a href="https://www.cloudflare.com/trust-hub/compliance-resources/">Trust Hub</a>.</p> ]]></content:encoded>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Compliance]]></category>
            <category><![CDATA[Germany]]></category>
            <guid isPermaLink="false">3HT4Z1ecBFLF022fEGO0lz</guid>
            <dc:creator>Rebecca Rogers</dc:creator>
        </item>
        <item>
            <title><![CDATA[Security Compliance at Cloudflare]]></title>
            <link>https://blog.cloudflare.com/security-compliance-at-cloudflare/</link>
            <pubDate>Sun, 16 Jun 2019 13:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare believes trust is fundamental to helping build a better Internet. One way Cloudflare is helping our customers earn their users’ trust is through industry standard security compliance certifications and regulations.  ]]></description>
            <content:encoded><![CDATA[ <p>Cloudflare believes trust is fundamental to helping build a better Internet. One way Cloudflare is helping our customers earn their users’ trust is through industry standard security compliance certifications and regulations.</p><p>Security compliance certifications are reports created by independent, third-party auditors that validate  and document a company’s commitment to security. These external auditors will conduct a rigorous review of a company’s technical environment and evaluate whether there are thorough controls - or safeguards - in place to protect the security, confidentiality, and availability of information stored and processed in the environment. SOC 2 was established by the American Institute of CPAs and is important to many of our U.S. companies, as it is a standardized set of requirements a company must meet in order to comply. Additionally, PCI and ISO 27001 are international standards. Cloudflare cares about achieving certifications because our adherence to these standards creates confidence to customers across the globe that we are committed to security. So, the Security team has been hard at work obtaining these meaningful compliance certifications.</p><p>Since the beginning of this year, we have been renewing our PCI DSS certification in February, achieving SOC 2 Type 1 compliance in March, obtaining our ISO 27001 certification in April, and today we are proud to announce we are SOC 2 Type 2 compliant!</p>
    <div>
      <h3>Our SOC 2 Journey</h3>
      <a href="#our-soc-2-journey">
        
      </a>
    </div>
    <p>SOC 2 is a compliance certification that focuses on internal controls of an organization related to five trust services criteria. These criteria are: Security, Confidentiality, Availability, Processing Integrity, and Privacy. Each criterion presents a set of control standards that are established by the American Institute of Certified Public Accountants (AICPA) and are to be used to implement controls on the information systems of a company.</p><p>Cloudflare’s Security team made the decision to evaluate our companies’ controls around three of the five criteria. We determined to pursue our SOC 2 compliance by evaluating our controls around Security, Confidentiality, and Availability across our entire organization. We first worked across the company to design and implement strong controls that meet the requirements set forth by the AICPA. This took effort and collaboration between teams in Engineering, IT, Legal, and HR to create strong controls that also make sense to our environment. Our external auditors then performed an audit of Cloudflare’s controls, and determined our security controls were suitably designed as of January 31, 2019.</p><img src="http://staging.blog.mrk.cfdata.org/content/images/2019/06/21972-312_SOC_NonCPA.jpg" /><p>Three months after obtaining SOC 2 Type 1 compliance, the next step for Cloudflare was to demonstrate the controls we designed were actually operating effectively. Our SOC 2 Type 2 audit tested the operating effectiveness of Cloudflare’s security controls over this three-month period. Cloudflare’s SOC 2 Type 2 report can be available upon request and describes the design of Cloudflare’s internal control framework around security, confidentiality and availability and the products and services in-scope for our certification.</p>
    <div>
      <h3>What else?</h3>
      <a href="#what-else">
        
      </a>
    </div>
    
    <div>
      <h4>SOC 3</h4>
      <a href="#soc-3">
        
      </a>
    </div>
    <p>In addition to SOC 2 Type 2, Cloudflare also obtained our SOC 3 report from our independent external auditors. SOC 3 is a report for public consumption on the external auditor’s opinion and a narrative of Cloudflare’s control environment. Cloudflare’s Security team decided on obtaining our SOC 3 report so all customers and prospects could access our auditor’s opinion of our implementation of security, confidentiality, and availability controls.</p>
    <div>
      <h4>ISO/IEC 27001: 2013</h4>
      <a href="#iso-iec-27001-2013">
        
      </a>
    </div>
    <p>Prior to Cloudflare’s SOC audit, Cloudflare was working to mature our organizations’ Information Security Management System in order to obtain our ISO/IEC 27001: 2013 certification. ISO 27001 is an international management system standard developed by the International Organization for Standardization (ISO) and is an industry-wide accepted information security certification. Cloudflare’s commitment to achieving ISO/IEC 27001: 2013 certification was to demonstrate to our customers that we are committed to preserving the confidentiality, integrity, and availability of information on a global scale.</p><p>The primary focus of ISO 27001:2013 requirements is the focus on implementation of an Information Security Management System (ISMS) and a comprehensive risk management program.  Cloudflare worked across the organization to implement the ISMS to ensure sensitive company information remains secure.</p><img src="http://staging.blog.mrk.cfdata.org/content/images/2019/06/ISO-27001-Certified-Logo.PNG" /><p>Cloudflare’s ISMS was assessed by a third-party auditor, A-LIGN, and we received our ISO 27001: 2013 certification in April 2019. Cloudflare’s ISO 27001:2013 certificate is also available to customers upon request.</p>
    <div>
      <h4>PCI DSS v3.2.1</h4>
      <a href="#pci-dss-v3-2-1">
        
      </a>
    </div>
    <p>Although Cloudflare has been PCI certified as a Level 1 Service Provider since 2014, our latest certification adheres to the newest security standards. The Payment Card Industry Data Security Standard (PCI DSS) is a global financial information security standards that ensures customers’ credit card data is safe and secure.</p><p>Maintaining PCI DSS compliance is important for Cloudflare because not only are we evaluated as a merchant, but we are also a service provider. Cloudflare’s WAF product satisfies PCI requirement 6.6, and may be used by Cloudflare’s customers as a solution to prevent web-based attacks in front of public-facing web applications.</p><img src="http://staging.blog.mrk.cfdata.org/content/images/2019/06/pasted-image-0-1.png" /><p>Early in 2019, Cloudflare was audited by an independent Qualified Security Assessor to validate our adherence to the PCI DSS security requirements. Cloudflare’s latest PCI Attestation of Compliance (AOC) is available to customers upon request.</p>
    <div>
      <h3>Compliance Page on the Website</h3>
      <a href="#compliance-page-on-the-website">
        
      </a>
    </div>
    <p>Cloudflare is committed to helping our customers’ earn their user’s trust by ensuring our products are secure. The Security team is committed to adhering to security compliance certifications and regulations that maintain the security, confidentiality, and availability of company and client information.In order to help our customers keep track of the latest certifications, Cloudflare has launched our Compliance certification page - <a href="http://www.cloudflare.com/compliance">www.cloudflare.com/compliance</a>. Today, you can view our status on all compliance certifications and download our SOC 3 report.</p> ]]></content:encoded>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Compliance]]></category>
            <guid isPermaLink="false">33ZTrE0PrezuBlQ5H6WwTF</guid>
            <dc:creator>Rebecca Rogers</dc:creator>
        </item>
    </channel>
</rss>