Is Cisco Duo SOC 2 or ISO 27001 Certified?
Quick answer. Duo (part of Cisco since 2018) describes its data centers as SOC 2 and ISO 27001 compliant, with documentation available through the Cisco Trust Portal, typically under NDA. Duo separately holds a FedRAMP Authorized, FIPS-compliant offering via the DHS CDM program. We could not confirm whether Duo issues its own standalone SOC 2 report or relies on Cisco's broader enterprise reporting; verify directly before citing a specific report to your auditor.
Duo has been part of Cisco since 2018, which changes how you verify its compliance claims compared to a standalone SaaS vendor. Two things matter here: what Duo (or Cisco, on Duo's behalf) has actually certified, and how Duo's MFA evidence maps to your own SOC 2, ISO 27001, or PCI DSS controls. Here's what we could and couldn't confirm.
What Duo has certified, and where the gaps are
Verified against Duo's Security & Reliability page and Duo Security and Compliance page.
| Certification / framework | What Duo states |
|---|---|
| SOC 2 | "Data centers are ISO27001 and SOC2 compliant"; docs via Cisco Trust Portal |
| ISO 27001 | Same statement; docs via Cisco Trust Portal |
| PCI DSS | Supports PCI DSS 4.0 Section 8.3 MFA requirements; hosted on PCI DSS-certified infrastructure |
| FedRAMP | FedRAMP Authorized, FIPS-compliant offering via the DHS CDM program |
| NIST | Helps meet NIST 800-63 and 800-171 access security guidelines |
| HIPAA, GDPR, FFIEC, PIPEDA, DEA EPCS | Positioned as supporting these frameworks, not certified against them |
Common gap
This is the one we flagged as unverified rather than guess at: Duo's public pages describe its infrastructure as "SOC2 compliant" but don't state whether Duo has its own standalone SOC 2 report or whether Duo compliance documentation is bundled into Cisco's enterprise-wide trust packages (the Cisco Trust Portal lists per-product packages for some Cisco products, such as Webex and Umbrella, but we could not confirm a dedicated Duo package on the portal's public listing). If your auditor needs a specific report to cite as subservice organization evidence, request it by name through your Cisco or Duo account team and get written confirmation of exactly what document you're receiving before you file it.
Duo's data centers span nine countries: the United States, Canada, Ireland, the UK, Australia, Germany, India, Singapore, and Japan, which matters if you have data residency commitments tied to where authentication data is processed.
This kind of gap is more common than it should be with acquired products. When a company buys a smaller vendor, compliance documentation often gets folded into the parent's enterprise trust program over time, and the acquired product's own public pages don't always get updated to reflect exactly how. That's not a knock on Duo's actual security posture, which by every account here is solid, it's a note that "verify before you cite" applies more, not less, once a product sits inside a larger company's compliance apparatus.
Source: Duo Security and Reliability, Duo Compliance, Cisco Trust Portal.
Getting Duo's compliance documentation
Duo directs compliance requests to the Cisco Trust Portal, Cisco's central repository for SOC 2, ISO 27001, FedRAMP, and other reports across its product line. Expect to request access and likely sign an NDA. Because Duo is a Cisco product rather than an independent company, expect the process to run through your Cisco account relationship, not a Duo-specific sales contact.
How startups use Duo as compliance evidence
Duo is access-control evidence. It shows up wherever your audit needs proof that authentication into sensitive systems requires more than a password.
SOC 2 CC6.1 and CC6.6: Logical access and authentication
CC6.1 covers logical access restrictions, CC6.6 covers protection against unauthorized access from outside your system boundary. MFA enforcement through Duo is one of the more direct, easy-to-demonstrate controls in a SOC 2 audit, provided it's actually required, not optional.
PCI DSS 4.0 Requirement 8.3
If you're in scope for PCI DSS, Requirement 8.3 explicitly calls for MFA on access to the cardholder data environment. Duo's own compliance page names this requirement directly, which makes it straightforward evidence to cite, as long as your policy configuration actually covers the CDE, not just your general SSO layer.
ISO 27001 Annex A 8.5: Secure authentication
Annex A 8.5 calls for secure authentication technologies and procedures based on access restrictions and policy. Duo's MFA policy configuration, applied consistently across admin and remote access, is the evidence here.
What auditors look for: an MFA enrollment coverage report showing what percentage of accounts are enrolled, the actual policy configuration proving MFA is enforced rather than optional, a list of any accounts excluded from the policy and why, and Duo admin console access logs for the audit period.
Gaps that show up at audit
MFA enabled but not enforced. Enrollment being possible isn't the same as enrollment being required. Auditors check the policy configuration, not just whether the Duo integration exists.
Service accounts and legacy systems excluded. Break-glass, service, and legacy application accounts are the most common carve-outs from MFA policy, and the most common finding when auditors ask for a full account inventory reconciled against MFA coverage.
SMS as the only fallback factor. SMS-based authentication is phishable and increasingly flagged by auditors as a weaker factor. If Duo push or WebAuthn isn't the primary method, document why and what compensating controls exist.
Coverage gaps between admin consoles and SaaS apps. MFA enforced on VPN and infrastructure access but not on individual SaaS applications is a common inconsistency; auditors will ask for the full list of in-scope systems and check each one.
Citing the wrong compliance claim. Given the ambiguity we flagged above, don't cite "Duo's SOC 2 report" in your own vendor documentation until you've confirmed with Cisco exactly which document you're pointing to.
Confusing "supports HIPAA" with a signed BAA. Duo helps satisfy the access-control safeguard HIPAA requires, but that's not the same as Cisco signing a Business Associate Agreement with you. If you need a BAA specifically, request it as its own document.
Reconciling MFA policy coverage against your actual account inventory, and sorting out which vendor claims are solid versus which need direct verification, is exactly the kind of work a fractional CISO runs for you before an auditor asks. Book a call or see pricing if you want your access control evidence reviewed before your next audit.