2026-09-24 · 4 min read

CrowdStrike SOC 2 & ISO 27001 Report Guide

Quick answer. CrowdStrike holds SOC 2 Type II reports for both Corporate Operations and the Falcon Platform (plus a SOC 2 Type I for its Forensic Lab), ISO/IEC 27001:2022 with ISO 27017:2015, ISO 42001:2023, FedRAMP High for Falcon Platform for Government, and PCI DSS v4.0.1. All documentation is available, with access requests, through trust.crowdstrike.com.

CrowdStrike shows up in two different conversations during a SOC 2 or ISO 27001 audit. First: what has CrowdStrike itself certified, since it's a subservice organization in your vendor inventory. Second: what does the Falcon agent running on your endpoints actually prove to your own auditor. Both questions have specific, verifiable answers.

CrowdStrike's own certifications

Verified against CrowdStrike's public compliance certifications page and trust center.

CertificationScope / notes
SOC 2 Type IICorporate Operations (separate report)
SOC 2 Type IIFalcon Platform (separate report)
SOC 2 Type IForensic Lab
ISO/IEC 27001:2022Includes ISO/IEC 27017:2015 cloud controls
ISO/IEC 42001:2023AI management system
ISO 22301:2019Business continuity management
FedRAMP HighFalcon Platform for Government
DoD IL5Provisional authorization, via DISA
PCI DSS v4.0.1Requirement 5 (malware protection) plus 4 supporting requirements, audited by Coalfire
CSA STAR Level 2Third-party audit against CCM v4.0
C5, TISAX, ENS High, UK Cyber Essentials, IRAPRegional government and industry frameworks

Common gap

CrowdStrike issues three separate SOC 2 reports, not one. Corporate Operations covers CrowdStrike's internal business systems. The Falcon Platform report covers the actual product running in your environment. If you cite CrowdStrike's SOC 2 report as subservice organization evidence in your own audit, make sure you have the Falcon Platform report, not just Corporate Operations.

How to get the reports

CrowdStrike's trust center (trust.crowdstrike.com, powered by SafeBase) gates most documents behind an access request, and some behind an NDA. Request the specific report by name (Falcon Platform SOC 2 Type II, ISO 27001 certificate, FedRAMP package) rather than a generic "compliance documentation" ask, since the portal issues them separately.

Mapping Falcon evidence to your own SOC 2 and ISO 27001 controls

This is the part that matters day to day: what does having Falcon deployed actually prove to your auditor.

SOC 2 CC6.8: Malware prevention

CC6.8 is written around preventing or detecting the introduction of unauthorized or malicious software. Falcon's endpoint detection and response coverage is the primary control here for most companies. Auditors want to see:

  • Sensor deployment coverage across production endpoints, ideally close to 100%
  • Detection and prevention policies applied, not just installed in monitor-only mode
  • A log of detections and how they were triaged during the audit period

SOC 2 CC7.1 and CC7.2: Threat detection and monitoring

CC7.1 covers vulnerability and threat detection, CC7.2 covers anomaly detection tied to an active response process. Falcon contributes to both, alongside a dedicated monitoring tool. See our SOC 2 CC7 monitoring guide for the full breakdown of CC7.1 through CC7.5.

Tip

Falcon detections routed to a silent Slack channel or an unmonitored inbox do not satisfy CC7.2, the same gap we flagged in our Datadog SOC 2 guide. Auditors check that alerts reach an actual on-call or triage workflow.

ISO 27001: Annex A malware and operations controls

Under ISO/IEC 27001:2022, Falcon evidence supports Annex A 8.7 (protection against malware) directly, and contributes to 8.16 (monitoring activities) when detection logs feed a broader monitoring program.

Evidence to pull from the Falcon console for your own audit

  • Sensor deployment / coverage report, showing the percentage of in-scope endpoints running the agent
  • Active prevention policy configuration, not a default or monitor-only policy
  • Detection and incident log for the audit period, with disposition (false positive, remediated, escalated) recorded
  • Evidence the detection feed routes into your incident response process, not just the Falcon console

Common gaps auditors find

Falcon deployed but not enforced everywhere. Coverage gaps on contractor laptops, build servers, or ephemeral cloud instances are the most common finding. Auditors will ask for a full asset inventory and reconcile it against sensor coverage.

Monitor-only policy mistaken for active prevention. A sensor installed in detection-only mode generates alerts but doesn't block anything. Confirm your policy actually prevents, not just observes, if you're claiming CC6.8 coverage.

No documented triage process for detections. Having Falcon is not the control. Showing that detections get reviewed and closed out is the evidence auditors actually test.

Wrong SOC 2 report cited. Pulling CrowdStrike's Corporate Operations SOC 2 report when you needed the Falcon Platform report is a common mix-up, since both are labeled simply "CrowdStrike SOC 2" in casual conversation.

Deciding which vendor reports actually satisfy which controls, and building the evidence trail an auditor accepts the first time, is exactly the kind of work a fractional CISO owns for you. Book a call if you want your endpoint and vendor evidence reviewed before your next audit.

Related reading

Frequently asked questions

Does CrowdStrike have a SOC 2 report?
Yes, and there are three separate reports, not one. CrowdStrike publishes a SOC 2 Type II report for Corporate Operations, a separate SOC 2 Type II report for the Falcon Platform, and a SOC 2 Type I report for its Forensic Lab. Request access through trust.crowdstrike.com; most reports require an access request and may be under NDA.
Is CrowdStrike ISO 27001 certified?
Yes. CrowdStrike is independently certified to ISO/IEC 27001:2022, updated to include ISO/IEC 27017:2015 cloud security controls. It also holds ISO/IEC 42001:2023 for AI management and ISO 22301:2019 for business continuity.
Is CrowdStrike FedRAMP authorized?
Yes. The Falcon Platform for Government holds FedRAMP High authorization, the highest impact level in the FedRAMP program, plus a DoD IL5 provisional authorization. This is separate from the commercial Falcon Platform's standard SOC 2 and ISO certifications.
Which CrowdStrike report do I need for my own SOC 2 audit?
If Falcon runs as an agent on your production systems, request the SOC 2 Type II report for the Falcon Platform, not the Corporate Operations report. Corporate Operations covers CrowdStrike's internal business systems; the Falcon Platform report covers the service you're actually relying on as a subservice organization.
How does CrowdStrike Falcon map to SOC 2 controls?
Falcon is direct evidence for CC6.8 (prevention or detection of unauthorized or malicious software) and CC7.1 (vulnerability and threat detection). Falcon's monitoring and alerting also supports CC7.2 (anomaly detection) when alerts route to an active on-call or incident process, not a silent channel.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.