Is KnowBe4 SOC 2 or ISO 27001 Certified?
Quick answer. KnowBe4 states all products are SOC 2 Type 2 certified (SSAE 18, all five Trust Services Criteria) and publishes an annual SOC 3 report. It holds ISO/IEC 27001:2022 plus 27701, 27017, 27018, and 42001, and a FedRAMP Moderate ATO scoped to KSAT and PhishER only. We found no HIPAA certification on its trust center.
If you run security awareness training through KnowBe4 and you're preparing for SOC 2, ISO 27001, or a HIPAA workforce training requirement, two things matter: what KnowBe4 has certified about itself, and what evidence its training and phishing data gives your own auditor. Here's what we verified against KnowBe4's own materials.
What KnowBe4 has certified
Verified against KnowBe4's security statement, security measures page, and trust center, powered by SafeBase.
| Certification | Scope / notes |
|---|---|
| SOC 2 Type 2 (SSAE 18) | All KnowBe4 products; covers Security, Availability, Processing Integrity, Confidentiality, and Privacy |
| SOC 3 | Public report, no NDA required, published annually |
| ISO/IEC 27001:2022 | Certificate issued by A-LIGN |
| ISO/IEC 27701:2019 | Privacy information management |
| ISO/IEC 27017:2015 | Cloud security controls |
| ISO/IEC 27018:2019 | PII protection in public cloud |
| ISO/IEC 42001:2023 | AI management system |
| FedRAMP Moderate ATO | KSAT and PhishER only, effective 11/14/2023 |
| Cyber Essentials, CSA STAR Level 1 | UK and cloud-security frameworks |
Common gap
KnowBe4 covers all five SOC 2 Trust Services Criteria, which most vendors don't bother with (Security and Availability alone is common). That's a genuinely strong signal, but it doesn't mean every KnowBe4 product is in scope for every certification. The FedRAMP authorization, for example, names KSAT and PhishER specifically, not the full catalog. Check the report's system description before assuming a product you use is covered.
The SOC 2 report scope covers user entities of KnowBe4's Cloud Hosted Data Platforms and includes complementary subservice organization controls for its AWS hosting. Encryption is TLS 1.2 or higher in transit and AES-GCM 256 at rest, with keys managed through AWS KMS or Azure Key Vault.
Covering all five Trust Services Criteria, rather than just Security and Availability, is worth noticing on its own. Most SaaS vendors scope their SOC 2 audit to the minimum two categories, since Processing Integrity, Confidentiality, and Privacy require more control evidence to test. A vendor handling employee data, phishing simulation results, and training records touching every employee in your company is a reasonable candidate for the fuller scope, and it's a genuine positive signal when you're doing vendor risk review, not just a checkbox.
We found no HIPAA certification claim anywhere in KnowBe4's published trust materials. KnowBe4 sells HIPAA-specific training modules, which is a content offering, not a compliance status for KnowBe4 itself. If your audit or a customer questionnaire needs a signed BAA with KnowBe4, request it directly rather than assuming one exists because HIPAA training content is available.
Source: KnowBe4 Trust Center, KnowBe4 Security Statement.
Getting the reports
KnowBe4's trust center at trust.knowbe4.com hosts the SOC 2 Type 2 report (access request required), the public SOC 3 report, ISO certificates, and the FedRAMP package. The SOC 3 is the fastest path if you just need a public-facing attestation to cite in a vendor risk questionnaire.
How startups use KnowBe4 as compliance evidence
KnowBe4 is people-controls evidence, specifically for the security awareness piece that shows up in nearly every framework.
SOC 2 CC2.2 (internal communication of security responsibilities). Training completion data is direct evidence. Pull a completion-rate report for the audit period, broken out by employee, not just an aggregate percentage.
ISO 27001 Annex A 6.3 (information security awareness, education, and training). Same evidence, mapped to a different framework. Auditors want proof training happened before or shortly after start date, not just that it's assigned.
HIPAA workforce training (45 CFR 164.308(a)(5)). If you're a HIPAA-covered entity or business associate, this is a required control. KnowBe4's completion records are the evidence, even though KnowBe4 itself isn't HIPAA-certified as a vendor, the same distinction we called out above.
PhishER for incident response (SOC 2 CC7.3, CC7.4). PhishER's triage and response workflow for reported phishing emails is evidence of an active incident-handling process, not just a passive inbox.
What auditors look for: a training completion report covering the full audit period, evidence that new hires complete initial training within a defined window (commonly 30 days), phishing simulation click-rate and report-rate trends, and a PhishER or equivalent log showing reported emails got triaged, not just collected.
Gaps that show up at audit
Training assigned but not enforced to completion. A 100% assignment rate with a 70% completion rate is a common finding. Set a hard deadline and follow up, since auditors sample individual employee records, not just the campaign-level summary.
New hires granted system access before training completes. If onboarding doesn't gate access on training completion, that's a timing gap between CC2.2 and your access provisioning controls.
Phishing failures with no follow-up. Running simulations without assigning remediation training to employees who clicked is a common gap; auditors increasingly ask for the remediation loop, not just the click-rate metric.
Assuming HIPAA coverage from HIPAA-themed training content. As above, training modules labeled "HIPAA" don't make KnowBe4 itself HIPAA certified. Keep those two claims separate in your own documentation.
Citing the FedRAMP authorization for products it doesn't cover. KnowBe4's FedRAMP Moderate ATO names KSAT and PhishER. If your organization relies on a different KnowBe4 product for a federal contract requirement, confirm scope with KnowBe4 directly before you put it in a compliance filing.
Mapping training and phishing data to the right control, and closing the gaps above before your auditor finds them, is the kind of recurring work a fractional CISO runs alongside whatever tools you already have. Book a call or see pricing if you want your security awareness program reviewed before your next audit.