CrowdStrike SOC 2 & ISO 27001 Report Guide
Quick answer. CrowdStrike holds SOC 2 Type II reports for both Corporate Operations and the Falcon Platform (plus a SOC 2 Type I for its Forensic Lab), ISO/IEC 27001:2022 with ISO 27017:2015, ISO 42001:2023, FedRAMP High for Falcon Platform for Government, and PCI DSS v4.0.1. All documentation is available, with access requests, through trust.crowdstrike.com.
CrowdStrike shows up in two different conversations during a SOC 2 or ISO 27001 audit. First: what has CrowdStrike itself certified, since it's a subservice organization in your vendor inventory. Second: what does the Falcon agent running on your endpoints actually prove to your own auditor. Both questions have specific, verifiable answers.
CrowdStrike's own certifications
Verified against CrowdStrike's public compliance certifications page and trust center.
| Certification | Scope / notes |
|---|---|
| SOC 2 Type II | Corporate Operations (separate report) |
| SOC 2 Type II | Falcon Platform (separate report) |
| SOC 2 Type I | Forensic Lab |
| ISO/IEC 27001:2022 | Includes ISO/IEC 27017:2015 cloud controls |
| ISO/IEC 42001:2023 | AI management system |
| ISO 22301:2019 | Business continuity management |
| FedRAMP High | Falcon Platform for Government |
| DoD IL5 | Provisional authorization, via DISA |
| PCI DSS v4.0.1 | Requirement 5 (malware protection) plus 4 supporting requirements, audited by Coalfire |
| CSA STAR Level 2 | Third-party audit against CCM v4.0 |
| C5, TISAX, ENS High, UK Cyber Essentials, IRAP | Regional government and industry frameworks |
Common gap
CrowdStrike issues three separate SOC 2 reports, not one. Corporate Operations covers CrowdStrike's internal business systems. The Falcon Platform report covers the actual product running in your environment. If you cite CrowdStrike's SOC 2 report as subservice organization evidence in your own audit, make sure you have the Falcon Platform report, not just Corporate Operations.
How to get the reports
CrowdStrike's trust center (trust.crowdstrike.com, powered by SafeBase) gates most documents behind an access request, and some behind an NDA. Request the specific report by name (Falcon Platform SOC 2 Type II, ISO 27001 certificate, FedRAMP package) rather than a generic "compliance documentation" ask, since the portal issues them separately.
Mapping Falcon evidence to your own SOC 2 and ISO 27001 controls
This is the part that matters day to day: what does having Falcon deployed actually prove to your auditor.
SOC 2 CC6.8: Malware prevention
CC6.8 is written around preventing or detecting the introduction of unauthorized or malicious software. Falcon's endpoint detection and response coverage is the primary control here for most companies. Auditors want to see:
- Sensor deployment coverage across production endpoints, ideally close to 100%
- Detection and prevention policies applied, not just installed in monitor-only mode
- A log of detections and how they were triaged during the audit period
SOC 2 CC7.1 and CC7.2: Threat detection and monitoring
CC7.1 covers vulnerability and threat detection, CC7.2 covers anomaly detection tied to an active response process. Falcon contributes to both, alongside a dedicated monitoring tool. See our SOC 2 CC7 monitoring guide for the full breakdown of CC7.1 through CC7.5.
Tip
Falcon detections routed to a silent Slack channel or an unmonitored inbox do not satisfy CC7.2, the same gap we flagged in our Datadog SOC 2 guide. Auditors check that alerts reach an actual on-call or triage workflow.
ISO 27001: Annex A malware and operations controls
Under ISO/IEC 27001:2022, Falcon evidence supports Annex A 8.7 (protection against malware) directly, and contributes to 8.16 (monitoring activities) when detection logs feed a broader monitoring program.
Evidence to pull from the Falcon console for your own audit
- Sensor deployment / coverage report, showing the percentage of in-scope endpoints running the agent
- Active prevention policy configuration, not a default or monitor-only policy
- Detection and incident log for the audit period, with disposition (false positive, remediated, escalated) recorded
- Evidence the detection feed routes into your incident response process, not just the Falcon console
Common gaps auditors find
Falcon deployed but not enforced everywhere. Coverage gaps on contractor laptops, build servers, or ephemeral cloud instances are the most common finding. Auditors will ask for a full asset inventory and reconcile it against sensor coverage.
Monitor-only policy mistaken for active prevention. A sensor installed in detection-only mode generates alerts but doesn't block anything. Confirm your policy actually prevents, not just observes, if you're claiming CC6.8 coverage.
No documented triage process for detections. Having Falcon is not the control. Showing that detections get reviewed and closed out is the evidence auditors actually test.
Wrong SOC 2 report cited. Pulling CrowdStrike's Corporate Operations SOC 2 report when you needed the Falcon Platform report is a common mix-up, since both are labeled simply "CrowdStrike SOC 2" in casual conversation.
Deciding which vendor reports actually satisfy which controls, and building the evidence trail an auditor accepts the first time, is exactly the kind of work a fractional CISO owns for you. Book a call if you want your endpoint and vendor evidence reviewed before your next audit.