2026-09-27 · 6 min read

Is Cisco Duo SOC 2 or ISO 27001 Certified?

Quick answer. Duo (part of Cisco since 2018) describes its data centers as SOC 2 and ISO 27001 compliant, with documentation available through the Cisco Trust Portal, typically under NDA. Duo separately holds a FedRAMP Authorized, FIPS-compliant offering via the DHS CDM program. We could not confirm whether Duo issues its own standalone SOC 2 report or relies on Cisco's broader enterprise reporting; verify directly before citing a specific report to your auditor.

Duo has been part of Cisco since 2018, which changes how you verify its compliance claims compared to a standalone SaaS vendor. Two things matter here: what Duo (or Cisco, on Duo's behalf) has actually certified, and how Duo's MFA evidence maps to your own SOC 2, ISO 27001, or PCI DSS controls. Here's what we could and couldn't confirm.

What Duo has certified, and where the gaps are

Verified against Duo's Security & Reliability page and Duo Security and Compliance page.

Certification / frameworkWhat Duo states
SOC 2"Data centers are ISO27001 and SOC2 compliant"; docs via Cisco Trust Portal
ISO 27001Same statement; docs via Cisco Trust Portal
PCI DSSSupports PCI DSS 4.0 Section 8.3 MFA requirements; hosted on PCI DSS-certified infrastructure
FedRAMPFedRAMP Authorized, FIPS-compliant offering via the DHS CDM program
NISTHelps meet NIST 800-63 and 800-171 access security guidelines
HIPAA, GDPR, FFIEC, PIPEDA, DEA EPCSPositioned as supporting these frameworks, not certified against them

Common gap

This is the one we flagged as unverified rather than guess at: Duo's public pages describe its infrastructure as "SOC2 compliant" but don't state whether Duo has its own standalone SOC 2 report or whether Duo compliance documentation is bundled into Cisco's enterprise-wide trust packages (the Cisco Trust Portal lists per-product packages for some Cisco products, such as Webex and Umbrella, but we could not confirm a dedicated Duo package on the portal's public listing). If your auditor needs a specific report to cite as subservice organization evidence, request it by name through your Cisco or Duo account team and get written confirmation of exactly what document you're receiving before you file it.

Duo's data centers span nine countries: the United States, Canada, Ireland, the UK, Australia, Germany, India, Singapore, and Japan, which matters if you have data residency commitments tied to where authentication data is processed.

This kind of gap is more common than it should be with acquired products. When a company buys a smaller vendor, compliance documentation often gets folded into the parent's enterprise trust program over time, and the acquired product's own public pages don't always get updated to reflect exactly how. That's not a knock on Duo's actual security posture, which by every account here is solid, it's a note that "verify before you cite" applies more, not less, once a product sits inside a larger company's compliance apparatus.

Source: Duo Security and Reliability, Duo Compliance, Cisco Trust Portal.

Getting Duo's compliance documentation

Duo directs compliance requests to the Cisco Trust Portal, Cisco's central repository for SOC 2, ISO 27001, FedRAMP, and other reports across its product line. Expect to request access and likely sign an NDA. Because Duo is a Cisco product rather than an independent company, expect the process to run through your Cisco account relationship, not a Duo-specific sales contact.

How startups use Duo as compliance evidence

Duo is access-control evidence. It shows up wherever your audit needs proof that authentication into sensitive systems requires more than a password.

SOC 2 CC6.1 and CC6.6: Logical access and authentication

CC6.1 covers logical access restrictions, CC6.6 covers protection against unauthorized access from outside your system boundary. MFA enforcement through Duo is one of the more direct, easy-to-demonstrate controls in a SOC 2 audit, provided it's actually required, not optional.

PCI DSS 4.0 Requirement 8.3

If you're in scope for PCI DSS, Requirement 8.3 explicitly calls for MFA on access to the cardholder data environment. Duo's own compliance page names this requirement directly, which makes it straightforward evidence to cite, as long as your policy configuration actually covers the CDE, not just your general SSO layer.

ISO 27001 Annex A 8.5: Secure authentication

Annex A 8.5 calls for secure authentication technologies and procedures based on access restrictions and policy. Duo's MFA policy configuration, applied consistently across admin and remote access, is the evidence here.

What auditors look for: an MFA enrollment coverage report showing what percentage of accounts are enrolled, the actual policy configuration proving MFA is enforced rather than optional, a list of any accounts excluded from the policy and why, and Duo admin console access logs for the audit period.

Gaps that show up at audit

MFA enabled but not enforced. Enrollment being possible isn't the same as enrollment being required. Auditors check the policy configuration, not just whether the Duo integration exists.

Service accounts and legacy systems excluded. Break-glass, service, and legacy application accounts are the most common carve-outs from MFA policy, and the most common finding when auditors ask for a full account inventory reconciled against MFA coverage.

SMS as the only fallback factor. SMS-based authentication is phishable and increasingly flagged by auditors as a weaker factor. If Duo push or WebAuthn isn't the primary method, document why and what compensating controls exist.

Coverage gaps between admin consoles and SaaS apps. MFA enforced on VPN and infrastructure access but not on individual SaaS applications is a common inconsistency; auditors will ask for the full list of in-scope systems and check each one.

Citing the wrong compliance claim. Given the ambiguity we flagged above, don't cite "Duo's SOC 2 report" in your own vendor documentation until you've confirmed with Cisco exactly which document you're pointing to.

Confusing "supports HIPAA" with a signed BAA. Duo helps satisfy the access-control safeguard HIPAA requires, but that's not the same as Cisco signing a Business Associate Agreement with you. If you need a BAA specifically, request it as its own document.

Reconciling MFA policy coverage against your actual account inventory, and sorting out which vendor claims are solid versus which need direct verification, is exactly the kind of work a fractional CISO runs for you before an auditor asks. Book a call or see pricing if you want your access control evidence reviewed before your next audit.

Related reading

Frequently asked questions

Is Cisco Duo SOC 2 compliant?
Duo's own materials describe its data centers as SOC 2 compliant and point to the Cisco Trust Portal for documentation. We could not independently confirm whether Duo publishes its own dedicated SOC 2 report or whether Duo's compliance documentation is issued as part of Cisco's broader enterprise reporting. Confirm directly with your Cisco or Duo account team before citing a specific report.
Is Duo ISO 27001 certified?
Duo describes its data centers as ISO 27001 compliant. As with SOC 2, documentation is requested through the Cisco Trust Portal, typically under NDA. We could not verify a Duo-specific certificate number independent of Cisco's broader ISO program.
Is Duo FedRAMP authorized?
Yes, for its federal offering specifically. Duo states it offers a FedRAMP Authorized, FIPS-compliant solution through the DHS Continuous Diagnostics and Mitigation (CDM) program. This is a separate authorization from the standard commercial Duo product.
Does Duo satisfy HIPAA requirements?
There's no such thing as a vendor being 'HIPAA certified' since HIPAA has no certification body. Duo markets that its MFA protects login into devices and systems handling protected health information, which supports the access-control technical safeguards a HIPAA-covered entity or business associate must implement, but Duo itself doesn't sign a HIPAA attestation.
How does Duo map to my own SOC 2 or PCI DSS controls?
Duo is primary evidence for SOC 2 CC6.1 and CC6.6 (logical access and authentication) and directly supports PCI DSS 4.0 Requirement 8.3 (multi-factor authentication). Pull an MFA enrollment coverage report, the enforced (not optional) policy configuration, and admin console access logs as evidence.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.