Skip to main content

Is Cyber Crucible ISO 27001, PCI-DSS, CMMC, or FedRAMP certified?

Short answer: No. Cyber Crucible has not obtained, and does not claim, ISO/IEC 27001, PCI-DSS, HIPAA, CMMC, or FedRAMP certification or authorization. It states this directly, because claiming a certification a vendor does not hold is exactly the kind of inconsistency that undermines trust in a due-diligence review.

What this means in practice

  • PCI-DSS: Cyber Crucible does not process, store, or transmit cardholder data, so it is out of scope as a card-data processor while still supporting a customer's endpoint-security control objectives.
  • HIPAA: because no customer content is collected, Cyber Crucible avoids creating a protected-health-information custody relationship; a Business Associate Agreement can be executed where a customer requires one.
  • ISO 27001 / CMMC / FedRAMP: not held, and not represented as held.

What Cyber Crucible does hold

Independent, objective validation exists where it matters most — see What independent security validation does Cyber Crucible have? Framework references elsewhere in this knowledge base are self-assessed mappings that help a reviewer relate Cyber Crucible's controls to a standard they already use; they are not third-party audit opinions.