CQ.AI Agents

Join ConQuest 2025 | ComplianceQuest User Conference | April 8–10, Clearwater Beach, FL

Discover your potential savings with our ROI Calculator

  Platform  >  Salesforce  >  Trust

SFDC Certifications

sfdc-banner

Salesforce maintains a comprehensive set of compliance certifications and attestations to validate the #1 value of trust

Request Demo
sfdc-banner

ComplianceQuest is a 100% native force.com application suite, built and run on the Salesforce platform. As such, ComplianceQuest Product Lifecycle, Quality and Safety suite inherits all attributes of the Salesforce platform such as:

attributes of the Salesforce platform

Certifications, Standards and Regulations

Clear Filter
TYPES
REGIONS
INDUSTRIES
truste-apec-processor

APEC Certification for Processors and Controllers

Asia-Pacific Economic Cooperation Privacy Recognition for Processors Certification

asip

ASIP Santé HDS

Enables certified companies to host French personal health data

asp-saas

ASP/SaaS

Information Disclosure Certification System for organizations in Japan

c5

C5 (ISAE 3000)

ISAE 3000 Report on the Cloud Computing Compliance Controls Catalogue (C5)

cccs

CCCS Assessment

Canadian Centre for Cyber Security (CCCS) Assessment

csastar

CSA STAR

Registry of security and privacy controls for cloud computing offerings

csmark

CS Gold Mark

Registry of security and privacy controls for cloud computing offerings

cybergrx

CyberGRX

CyberGRX assessments apply a dynamic and comprehensive approach to third party risk assessment

drbcp

Disaster Recovery & BCP

Business Continuity and Disaster Recovery

dod

DoD IL2

Cloud computing security requirements for the US Department of Defense for Impact Level 2

dod

DoD IL4

Cloud computing security requirements for the US Department of Defense for Impact Level 4

eucdp

EU Cloud Code of Conduct

Adherence with EU Cloud Code of Conduct

pentest

External Security Assessments

Attestation of penetration tests and security assessments performed by third parties

fedramp

FedRAMP High

U.S. government program providing a standard approach to security, authorization and monitoring

fedramp

FedRAMP Moderate

U.S. government program providing a standard approach to security, authorization and monitoring

finserv

Financial Services Compliance

How Salesforce helps support financial service institutions with regulatory requirements

gdpr

GDPR

How Salesforce helps support our customers on their GDPR compliance journeys

hipaa

HIPAA

U.S. Privacy requirements for personal health information held by covered entities

hitrust

HITRUST

Comprehensive, flexible and efficient approach to regulatory compliance and risk management

irap

IRAP

Security assessment for Australian government customers

gov

IRS 1075

U.S. government program providing guidance to protect the confidentiality of Federal Tax Information (FTI)

gov

ISMAP

Japanese government program to assess and register cloud services that meet government security requirements

pubcloud

ISO 27001

Compliance with specific information security and risk management requirements

pubcloud

ISO 27017

Adherence with ISO/IEC 27002 Code of Practice controls for cloud services

pubcloud

ISO 27018

Adherence with Code of Practice controls for protection of personal information

nen7510

NEN 7510

Protecting health information for organizations in the Netherlands

pubcloud

NHS DSPT

Online self-assessment tool for UK organizations

nist

NIST SP 800-171

U.S. security requirements for protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

pcidss

PCI DSS

Validation of controls around cardholder data to reduce credit card fraud

privacymark

PrivacyMark

Privacy-centric certification for organizations in Japan

privacyshield

Privacy Shield

A framework for complying with EU General Data Protection Regulation (GDPR) requirements

sfdcbcr

Salesforce BCRs

Binding Corporate Rules for the Processing of European Personal Data

soc

SOC 1

Type II report covering internal controls over financial reporting systems

soc

SOC 2

Type II report covering Security, Availability, Integrity, Confidentiality, and Privacy

soc

SOC 3

Public report of Security, Availability, Integrity, Confidentiality, and Privacy controls

ens

Spain Esquema Nacional de Seguridad (ENS)

Set of security standards applied to service providers for servicing the Spanish Public Sector and government agencies

privacy

Standard Questionnaires, FAQ's and Whitepapers

Standardised questionnaires from industry groups, answers to common questions and white papers

tisax

TISAX

A European information security assessment (ISA) for the z industry.

truste-apec-processor

TRUSTe Privacy Verified Seal

Responsible data collection and processing practices consistent with regulatory expectations

uk-cyber-essentials

UK Cyber Essentials Plus

UK government information security assurance scheme

wcag

WCAG 2.1 AA

WCAG defines how to make web content more accessible to people with disabilities

spinner
Consult Now

Comments