2026-09-26 · 5 min read

Is KnowBe4 SOC 2 or ISO 27001 Certified?

Quick answer. KnowBe4 states all products are SOC 2 Type 2 certified (SSAE 18, all five Trust Services Criteria) and publishes an annual SOC 3 report. It holds ISO/IEC 27001:2022 plus 27701, 27017, 27018, and 42001, and a FedRAMP Moderate ATO scoped to KSAT and PhishER only. We found no HIPAA certification on its trust center.

If you run security awareness training through KnowBe4 and you're preparing for SOC 2, ISO 27001, or a HIPAA workforce training requirement, two things matter: what KnowBe4 has certified about itself, and what evidence its training and phishing data gives your own auditor. Here's what we verified against KnowBe4's own materials.

What KnowBe4 has certified

Verified against KnowBe4's security statement, security measures page, and trust center, powered by SafeBase.

CertificationScope / notes
SOC 2 Type 2 (SSAE 18)All KnowBe4 products; covers Security, Availability, Processing Integrity, Confidentiality, and Privacy
SOC 3Public report, no NDA required, published annually
ISO/IEC 27001:2022Certificate issued by A-LIGN
ISO/IEC 27701:2019Privacy information management
ISO/IEC 27017:2015Cloud security controls
ISO/IEC 27018:2019PII protection in public cloud
ISO/IEC 42001:2023AI management system
FedRAMP Moderate ATOKSAT and PhishER only, effective 11/14/2023
Cyber Essentials, CSA STAR Level 1UK and cloud-security frameworks

Common gap

KnowBe4 covers all five SOC 2 Trust Services Criteria, which most vendors don't bother with (Security and Availability alone is common). That's a genuinely strong signal, but it doesn't mean every KnowBe4 product is in scope for every certification. The FedRAMP authorization, for example, names KSAT and PhishER specifically, not the full catalog. Check the report's system description before assuming a product you use is covered.

The SOC 2 report scope covers user entities of KnowBe4's Cloud Hosted Data Platforms and includes complementary subservice organization controls for its AWS hosting. Encryption is TLS 1.2 or higher in transit and AES-GCM 256 at rest, with keys managed through AWS KMS or Azure Key Vault.

Covering all five Trust Services Criteria, rather than just Security and Availability, is worth noticing on its own. Most SaaS vendors scope their SOC 2 audit to the minimum two categories, since Processing Integrity, Confidentiality, and Privacy require more control evidence to test. A vendor handling employee data, phishing simulation results, and training records touching every employee in your company is a reasonable candidate for the fuller scope, and it's a genuine positive signal when you're doing vendor risk review, not just a checkbox.

We found no HIPAA certification claim anywhere in KnowBe4's published trust materials. KnowBe4 sells HIPAA-specific training modules, which is a content offering, not a compliance status for KnowBe4 itself. If your audit or a customer questionnaire needs a signed BAA with KnowBe4, request it directly rather than assuming one exists because HIPAA training content is available.

Source: KnowBe4 Trust Center, KnowBe4 Security Statement.

Getting the reports

KnowBe4's trust center at trust.knowbe4.com hosts the SOC 2 Type 2 report (access request required), the public SOC 3 report, ISO certificates, and the FedRAMP package. The SOC 3 is the fastest path if you just need a public-facing attestation to cite in a vendor risk questionnaire.

How startups use KnowBe4 as compliance evidence

KnowBe4 is people-controls evidence, specifically for the security awareness piece that shows up in nearly every framework.

SOC 2 CC2.2 (internal communication of security responsibilities). Training completion data is direct evidence. Pull a completion-rate report for the audit period, broken out by employee, not just an aggregate percentage.

ISO 27001 Annex A 6.3 (information security awareness, education, and training). Same evidence, mapped to a different framework. Auditors want proof training happened before or shortly after start date, not just that it's assigned.

HIPAA workforce training (45 CFR 164.308(a)(5)). If you're a HIPAA-covered entity or business associate, this is a required control. KnowBe4's completion records are the evidence, even though KnowBe4 itself isn't HIPAA-certified as a vendor, the same distinction we called out above.

PhishER for incident response (SOC 2 CC7.3, CC7.4). PhishER's triage and response workflow for reported phishing emails is evidence of an active incident-handling process, not just a passive inbox.

What auditors look for: a training completion report covering the full audit period, evidence that new hires complete initial training within a defined window (commonly 30 days), phishing simulation click-rate and report-rate trends, and a PhishER or equivalent log showing reported emails got triaged, not just collected.

Gaps that show up at audit

Training assigned but not enforced to completion. A 100% assignment rate with a 70% completion rate is a common finding. Set a hard deadline and follow up, since auditors sample individual employee records, not just the campaign-level summary.

New hires granted system access before training completes. If onboarding doesn't gate access on training completion, that's a timing gap between CC2.2 and your access provisioning controls.

Phishing failures with no follow-up. Running simulations without assigning remediation training to employees who clicked is a common gap; auditors increasingly ask for the remediation loop, not just the click-rate metric.

Assuming HIPAA coverage from HIPAA-themed training content. As above, training modules labeled "HIPAA" don't make KnowBe4 itself HIPAA certified. Keep those two claims separate in your own documentation.

Citing the FedRAMP authorization for products it doesn't cover. KnowBe4's FedRAMP Moderate ATO names KSAT and PhishER. If your organization relies on a different KnowBe4 product for a federal contract requirement, confirm scope with KnowBe4 directly before you put it in a compliance filing.

Mapping training and phishing data to the right control, and closing the gaps above before your auditor finds them, is the kind of recurring work a fractional CISO runs alongside whatever tools you already have. Book a call or see pricing if you want your security awareness program reviewed before your next audit.

Related reading

Frequently asked questions

Does KnowBe4 have a SOC 2 report?
Yes. KnowBe4 states all its products are SSAE 18 SOC 2 Type 2 certified, covering all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. KnowBe4 also publishes an annual SOC 3 report, which unlike the Type 2 report is public and doesn't require an NDA to read.
Is KnowBe4 ISO 27001 certified?
Yes. KnowBe4 holds ISO/IEC 27001:2022 certification issued by A-LIGN, an ANSI-ASQ National Accreditation Board accredited certifier, plus ISO/IEC 27701:2019 (privacy), 27017:2015 (cloud security), 27018:2019 (PII in public cloud), and ISO/IEC 42001:2023 for AI management systems.
Is KnowBe4 FedRAMP authorized?
Yes, but scoped narrowly. KnowBe4 holds a FedRAMP Moderate Authority to Operate, effective since November 14, 2023, covering its KSAT (security awareness training) and PhishER products specifically, not KnowBe4's entire product line.
Is KnowBe4 HIPAA certified?
We found no HIPAA certification listed on KnowBe4's public trust center. KnowBe4 sells HIPAA-specific training content your workforce can complete, which is different from KnowBe4 itself holding a HIPAA certification. If you need a signed BAA with KnowBe4, confirm directly with their sales or legal team.
How does KnowBe4 map to my own SOC 2 audit?
KnowBe4 is your primary evidence source for SOC 2 CC2.2 (security awareness and communication) and ISO 27001 Annex A 6.3 (security awareness, education, and training). Pull training completion percentage by employee, new-hire training completion timing, and phishing simulation click and report rates for the audit period.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.