
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Fri, 24 Jul 2026 13:47:59 GMT</lastBuildDate>
        <item>
            <title><![CDATA[Cloudflare proudly joins the UK government's Cyber Resilience Pledge]]></title>
            <link>https://blog.cloudflare.com/cloudflare-joins-uk-cyber-resilience-pledge/</link>
            <pubDate>Tue, 07 Jul 2026 13:00:00 GMT</pubDate>
            <description><![CDATA[ The pledge is a voluntary framework inviting organizations to commit to foundational cyber security governance, board-level accountability, and supply chain rigor. For over a decade, Cloudflare has pioneered the core pillars of this framework: democratizing security, leadership accountability, and radical transparency. ]]></description>
            <content:encoded><![CDATA[ <p>Today, the UK government launched the <a href="https://www.gov.uk/government/news/businesses-across-britain-sign-up-to-cyber-resilience-pledge-as-ministers-urge-firms-to-strengthen-cyber-defences"><u>Cyber Resilience Pledge</u></a>: a voluntary framework inviting organizations to commit to foundational cybersecurity governance, board-level accountability, and comprehensive cybersecurity coverage across supply chains. <b>Cloudflare is </b><a href="https://assets.ctfassets.net/slt3lc6tev37/1WKiJC2ISsPozmIWk30ao5/99ff2bec7c1d9c927d221bf3f4aea218/DSIT_Cyber_Resilience_Pledge___Cloudflare__Letterhead.pdf"><b><u>proud to join</u></b></a><b> the pledge’s founding cohort of signatories </b>and continue our long-standing work with the Department of Science, Innovation and Technology (DSIT), National Cyber Security Centre, and others to shape a more secure, future-ready digital economy for the UK<b>.</b></p><p><a href="https://www.gov.uk/government/publications/cyber-resilience-pledge/cyber-resilience-pledge-declaration"><u>The pledge's</u></a> core pillars — democratizing security, leadership accountability, and radical transparency — have been at the heart of Cloudflare since day one. Instead of approaching this framework as a new set of commitments to meet, we see it as a welcome validation from the UK government of the security philosophy and principles Cloudflare has championed for over a decade. We are glad to see the rest of the industry moving in this direction.</p><p>This pledge is an important step, and it comes at a time of significant cyber risk. In the first quarter of 2026, Cloudflare's global network blocked an average of <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-2026-threat-intelligence-report-nation-state-actors-and/"><u>234 billion cyber threats every day</u></a>. Recently, we mitigated a hyper-volumetric DDoS attack that peaked at <a href="https://blog.cloudflare.com/ddos-threat-report-2025-q4/"><u>31.4 Tbps</u></a>. At the end of 2025, Cloudflare data showed that the UK had risen to be the <a href="https://blog.cloudflare.com/ddos-threat-report-2025-q4/"><u>sixth-most targeted</u></a> location across the globe for DDoS attacks, with threat actors increasingly targeting application-layer services in financial services, aviation, and regional government infrastructure. This trend is consistent with broader data from the <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026#:~:text=Just%20over%20four%20in%20ten,UK%20charities%20%5Bfootnote%201%5D."><u>UK Cyber Security Breaches Survey</u></a>, which revealed that 43% of surveyed British businesses and 28% of charities reported suffering from a cyber incident this past year.</p><p>At the same time, frontier AI models are rapidly changing the security landscape, lowering the barrier to entry for attackers, and enabling more automated vulnerability scanning and more convincing phishing campaigns. Cloudflare has long been preparing for this shift. The defensive architecture we recently <a href="https://blog.cloudflare.com/frontier-model-defense/"><u>published</u></a> for frontier cyber models reflects the same principle: security has to evolve as quickly as the threats companies face. Every layer of that harness architecture, from ML-based attack scoring to Zero Trust access controls, is available to Cloudflare customers today.</p><p>Against that backdrop, the pledge does something essential: it recognizes that collective defense is critical. It asks organizations to make cyber resilience a leadership-level priority, to implement appropriate controls to boost threat awareness, and to help ensure supply chains meet a meaningful security baseline. Most breaches still exploit well-understood gaps, like unpatched systems, weak access controls, or poor vendor oversight. Encouraging more organizations to close those gaps through enhanced governance, monitoring, and implementation is a necessary starting point. </p><p>Cloudflare is fully aligned with the UK government's mission to elevate cybersecurity governance within companies and organizations of all sizes. Every organization that raises its baseline makes the Internet safer for everyone else. Our mission at Cloudflare is to help build a better Internet, and we have always believed that cybersecurity and resilience work best when they are universal. A more resilient Internet is a better Internet. </p>
    <div>
      <h2>Why resilience matters</h2>
      <a href="#why-resilience-matters">
        
      </a>
    </div>
    <p><a href="https://www.cloudflare.com/learning/security/what-is-cyber-resilience/#:~:text=Unlike%20organizations%20that%20focus%20on,can%20cause%20when%20they%20happen."><u>Cyber resilience</u></a> is increasingly recognized as a core business requirement. Customers expect services to be available at all times, responsive, and trustworthy. And that’s true even when the environment gets more challenging to operate in, whether from increased attacks, outages, abuse, or complexity. </p><p>Resilience ultimately is not just about recovering after something goes wrong. It is about designing security systems and operating models that can proactively track threat signals, seamlessly absorb disruptions, and adapt to be better. In this way, security and resilience are inseparable. Security controls are what make resilience real. </p>
    <div>
      <h2>How Cloudflare helps strengthen resilience through security</h2>
      <a href="#how-cloudflare-helps-strengthen-resilience-through-security">
        
      </a>
    </div>
    <p>Thanks to the scale of our network, we can help organizations build resilience by shifting protection closer to the edge, before threats reach core systems. We think about cyber resilience through a few core architectural principles:</p>
    <div>
      <h3>Security as a default, not a product tier</h3>
      <a href="#security-as-a-default-not-a-product-tier">
        
      </a>
    </div>
    <p>Cloudflare believes baseline security protections should be available to all and has been living that principle since our founding. We were the <a href="https://blog.cloudflare.com/introducing-universal-ssl/"><u>first</u></a> to offer SSL certificates, required for traffic encryption, to all users. We protect vulnerable voices through our Impact programs like <a href="https://www.cloudflare.com/galileo/"><u>Project Galileo</u></a> and the <a href="https://www.cloudflare.com/athenian/"><u>Athenian Project</u></a>. We continuously push the boundaries of Internet cryptography, including the <a href="https://blog.cloudflare.com/post-quantum-crypto-should-be-free/"><u>deployment of post-quantum cryptography</u></a> across our network. Our <a href="https://www.cloudflare.com/en-gb/plans/free/"><u>free plan</u></a> includes unmetered DDoS protection regardless of the size, duration, or volume of attacks, and also provides access to a global content delivery network (CDN) and DNSSEC. These capabilities have historically required expensive hardware and specialist security teams. But the pledge’s aim of elevating organizational resilience and raising the cyber resilience floor across the UK economy only works if small businesses, local authorities, public services, and startups can afford to participate. Our model directly supports that goal.</p>
    <div>
      <h3>The network is the sensor</h3>
      <a href="#the-network-is-the-sensor">
        
      </a>
    </div>
    <p>Because Cloudflare directly peers with more than 13,000 networks globally, we see attack patterns as they emerge. Threat intelligence collected in one part of the network can be turned into protection everywhere else in a matter of seconds. A threat detected while mitigating an attack on a customer in Singapore can become a rule that helps protect a customer in Sheffield moments later. That same visibility also helps improve how we detect, score, and respond to attacks across Cloudflare’s network and security services. Visibility at scale leads to resilience at scale for Cloudflare’s customers and network.</p>
    <div>
      <h3>Cloudflare is customer zero</h3>
      <a href="#cloudflare-is-customer-zero">
        
      </a>
    </div>
    <p>Our customers benefit from the exact same industry-leading security products and infrastructure that safeguard our own systems. Cloudflare employees use Cloudflare Access and Gateway to reach internal applications, and every request to an internal system requires hard key-based multi-factor authentication, posture checks, and cryptographically verified identity tokens. We test every security layer on ourselves first, and use our own internal learnings to build better security solutions for ourselves and our network. By integrating security into every level of the business, Cloudflare demonstrates a ground-up commitment that sits at the very heart of the pledge.</p>
    <div>
      <h3>Transparency and response</h3>
      <a href="#transparency-and-response">
        
      </a>
    </div>
    <p>Finally, resilience requires honesty and transparency when things go wrong and a commitment to strengthen systems for the future. When <a href="https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/"><u>security incidents</u></a> or zero-day vulnerabilities emerge, we publish deep-dive technical postmortems on the Cloudflare Blog. We share indicators of compromise and architectural retrospectives, so the broader security community can learn from our telemetry. But transparency is only the first step. We treat every incident as a mandate to make our network more resilient. After a significant outage last fall, our <a href="https://blog.cloudflare.com/code-orange-fail-small-complete/"><u>Code Orange</u></a> effort mobilized engineering teams to rebuild for resilience. They designed systems to "fail small," and built new tooling to enforce safer configuration changes and automate best practices, so the same failure can't happen twice.</p>
    <div>
      <h2>How Cloudflare implements the Cyber Resilience Pledge commitments</h2>
      <a href="#how-cloudflare-implements-the-cyber-resilience-pledge-commitments">
        
      </a>
    </div>
    <p>As noted above, today’s voluntary pledge asks companies and organizations to commit to certain standards in board responsibility and governance, supply chain security, and the technical requirements under the UK’s <a href="https://www.cloudflare.com/trust-hub/compliance-resources/cyber-essentials/"><u>Cyber Essentials</u></a> certification scheme. As a global cybersecurity and network resilience provider, we operate an advanced internal cybersecurity governance model. </p>
    <div>
      <h3>Board responsibility and governance</h3>
      <a href="#board-responsibility-and-governance">
        
      </a>
    </div>
    <p>With cybersecurity and resilience at the core of Cloudflare's global business, we are proud to be a leader in <a href="https://www.cloudflare.com/the-net/top-of-mind-technology/security-boardroom/"><u>developing and advocating for</u></a> practices that strengthen cybersecurity at the board level.</p><p>Our Board of Directors treats cyber risk oversight as a core responsibility. Cloudflare’s Board receives cybersecurity briefings from our Chief Security Officer on at least a quarterly basis, including direct threat briefings. In addition, the Audit Committee of the Board receives quarterly briefings on enterprise risk management that include a specific focus on cyber risks and the company's process for regularly reviewing and mitigating cyber threats and risks.</p><p>We are grateful that DSIT's toolkit and resources are available to benchmark, reinforce, and support boards' ongoing governance efforts across the entire UK economy.</p>
    <div>
      <h3>Supply chain security and Cyber Essentials (CE)</h3>
      <a href="#supply-chain-security-and-cyber-essentials-ce">
        
      </a>
    </div>
    <p>Cloudflare adheres to rigorous international security compliance certifications. We require our supply chain to meet comprehensive international standards that incorporate and build upon the core requirements of Cyber Essentials. Cloudflare manages vendor risk globally, prioritizing comprehensive international security frameworks that encompass and exceed the fundamental technical controls of the Cyber Essentials program.</p><p>More specifically, Cloudflare requires critical suppliers to adhere to rigorous, internationally recognized security compliance certifications and reports — primarily ISO 27001 and SOC 2 Type II. These frameworks explicitly require the implementation of firewalls, secure configurations, user access controls, malware protection, and patch management (the five core pillars of Cyber Essentials).</p><p>Cloudflare will continue to use a risk-based methodology to evaluate suppliers. We commend DSIT for expanding access to the Cyber Essentials Supplier Check Tool, which Cloudflare can adopt for localized supply chain validation within the UK. And for global suppliers where UK Cyber Essentials is not a native or practical certification, Cloudflare will accept equivalent international certifications (like ISO 27001) as sufficient verification of a robust security posture. These practices help ensure that Cloudflare's critical supply chain undergoes stringent security vetting, meeting the risk-reduction outcomes intended by Cyber Essentials.</p>
    <div>
      <h2>Onward</h2>
      <a href="#onward">
        
      </a>
    </div>
    <p>Cyber resilience is not a one-time pledge — it is a continuous practice of building systems that fail safely, recover quickly, and learn to be better. For organizations across the UK, it means making cybersecurity a business-critical priority, with leadership buy-in, teams that understand the threats they face, and supply chains managed for risk. The pledge sets a baseline that every organization should strive to meet.</p><p>Cloudflare built its platform on the belief that security and resilience should be universal and available to both the smallest developer and the largest enterprise. We are proud to stand with DSIT and the other signatories of this pledge, and look forward to continued partnership and innovation to elevate cyber resilience across the UK and around the globe.</p> ]]></content:encoded>
            <category><![CDATA[United Kingdom]]></category>
            <category><![CDATA[Cybersecurity]]></category>
            <category><![CDATA[Policy & Legal]]></category>
            <category><![CDATA[Security]]></category>
            <guid isPermaLink="false">3xHevpKOOM76zUSrlPcQno</guid>
            <dc:creator>Katie Visser</dc:creator>
            <dc:creator>Ling Wu</dc:creator>
        </item>
        <item>
            <title><![CDATA[Commitment to Customer Security]]></title>
            <link>https://blog.cloudflare.com/our-commitment-to-customer-security/</link>
            <pubDate>Fri, 18 Mar 2022 18:58:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare has been hooked on securing customers globally since its inception. Our services protect customer traffic and data as well as our own, and we are continuously improving and expanding those services to respond to the changing threat landscape of the Internet ]]></description>
            <content:encoded><![CDATA[ <p></p><p>Cloudflare has been hooked on securing customers globally since its inception. Our services protect customer traffic and data as well as our own, and we are continuously improving and expanding those services to respond to the changing threat landscape of the Internet. Proving that commitment is a multi-faceted venture, the Security Team focuses on people, proof, and transparency to ensure every touchpoint with our products and company feels dependable.</p>
    <div>
      <h3>People</h3>
      <a href="#people">
        
      </a>
    </div>
    <p>The breadth of knowledge of the Security Team is wide and bleeding edge. Working as a security team at a security company means being highly technical, <a href="https://cloudflare.tv/event/3tghdguhftXYpoWDqilFFC">diverse</a>, <a href="/dogfooding-from-home/">willing to test any and all products on ourselves</a>, and sharing our knowledge with our local and global communities through industry groups and <a href="https://bsides.berlin/">presenting at conferences worldwide</a>. Connecting with our customers and counterparts through meetups and conferences lets us share problems, learn about upcoming industry trends, and share feedback to make improvements to the customer experience. In addition to running a formally documented, risk-based security program for Cloudflare, team members drive continuous improvement efforts across our Product and Infrastructure teams by reviewing and advising on changes, identifying and treating vulnerabilities, controlling authorization and access to systems and data, encrypting data in transit and at rest, and by detecting and responding to threats and incidents.</p>
    <div>
      <h3>Proof</h3>
      <a href="#proof">
        
      </a>
    </div>
    <p>Security claims are all well and good, but how can a customer be sure we are doing what we say we do? We do it by undergoing several audits a year, proving that our security practices meet industry standards. To date, Cloudflare has regularly assessed and maintained compliance with PCI DSS (as a merchant and a service provider), SOC 2 Type II, ISO 27001 and ISO 27701 standards. No matter where our customers are in the world, they will likely need to rely on at least one of these standards to protect their customers’ information. We honor the responsibility of being the backbone of that <a href="https://www.cloudflare.com/trust-hub/compliance-resources/">trust</a>.</p><p>As Cloudflare’s customer base continues to grow into more regulated industries with complex and rigorous requirements, we've decided to assess our global network against three additional standards this year:</p><ul><li><p><a href="https://www.cloudflare.com/learning/privacy/what-is-fedramp/">FedRAMP</a>, the US Federal Risk and Authorization Management Program, which evaluates our systems and practices against the standard for protection of US agency data in cloud computing environments. Cloudflare is listed on the <a href="https://marketplace.fedramp.gov/#!/product/cloudflare-federal?sort=productName&amp;productNameSearch=cloudflare">FedRAMP Marketplace</a> as “In Process” for an agency authorization at a Moderate impact level. We’re in the final steps of concluding our security assessment report from our auditors and on target to receive an authorization to operate in 2022.</p></li><li><p>ISO 27018, which examines our practices to protect personally identifiable information (PII) as a cloud provider. This extension to the ISO 27001 standard ensures that our information security management system (ISMS) manages the risks associated with processing PII. We’ve completed the third-party assessment, and we’re waiting for our certification in the upcoming month.</p></li><li><p>C5, Cloud Computing Compliance Criteria Catalog, introduced by <a href="https://www.bsi.bund.de/DE/Home/home_node.html">the Federal Office for Information Security</a> (The BSI) in Germany, is a validation against a defined baseline security level for cloud computing. Cloudflare is currently in the process of being assessed against the catalog by third-party auditors. Learn about our journey <a href="/bsig-audit-and-beyond/">here</a>.</p></li></ul>
    <div>
      <h3>Transparency</h3>
      <a href="#transparency">
        
      </a>
    </div>
    <p>Our commitment to security for our customers and business means we have to be super transparent. When a security incident is being contained, we have in our response plan to not only bring in our legal, compliance and communications teams to determine notification strategy, but we also start outlining a detailed overview of how we are responding, even if we are still in the process of remediating.</p><p>We know firsthand how frustrating it can be when your critical vendors stay silent during a security incident and provide nothing more than a one sentence legal response which fails to reveal how they were impacted by the security vulnerability or incident. Here at Cloudflare, it is in our DNA to be transparent. You can see it with the blogs (<a href="/about-the-march-8-9-2021-verkada-camera-hack/">Verkada Incident</a>, <a href="/how-cloudflare-security-responded-to-log4j2-vulnerability/">Log4j</a>) we write and how quickly we show our customers how we’ve responded and what we’re doing to fix the issue.</p><p>One of the most frequent questions we get from our customers regarding incidents is if our third-parties were impacted. Supply chain vulnerabilities, like Solarwinds and Log4j, have driven us to create efficiencies, such as automated inquiries, to all of our critical vendors at once. During the Containment phase of our security incident response process, our third-party risk team is quickly able to identify the impacted vendors and prioritize our production and security vendors. Our tooling allows us to trigger inquiries to third parties immediately, and our team is integrated into the incident response process to ensure effective communication. Any information that we receive from our vendors, we share with our Security Compliance forums to ensure that other companies who are also inquiring with their vendors don’t have to duplicate their work.</p>
    <div>
      <h3>Value</h3>
      <a href="#value">
        
      </a>
    </div>
    <p>These recurring audits and assessments are not simple website badges. Our Security team doesn’t produce evidence only to pass audits; our process includes identifying risks, forming controls and processes to address those risks, continuous operation of those processes, evaluation of the effectiveness of (in the form of internal and external audits and tests) those processes, and making improvements to the ISMS based on those evaluations. Some things on our process that set us apart include the following:</p><ul><li><p>Many companies do not contact vendors or have this process baked into their incident response procedures. For log4j, our Vendor Security Team was on calls with the response team and providing regular updates on vendor responses as soon as the incident was identified.</p></li><li><p>Many companies do not proactively communicate to customers like we do. We communicate even when we are not legally required to do so because we feel it’s the right thing to do regardless of the requirement.</p></li><li><p>The tools in this space also are not usually flexible enough to send custom questionnaires quickly out to vendors. We have automation in place to get these out in bulk right away and tailor questions to the vulnerabilities at hand.</p></li></ul><p>The final step is communicating the resulting picture of our security posture to our customers. Our security certifications and assessment results are available to our customers via download from their Cloudflare Dashboards, or by request to their account team. For the latest information about our certifications and reports, please visit <a href="https://www.cloudflare.com/trust-hub">our</a> <a href="https://www.cloudflare.com/trust-hub/compliance-resources/">Trust Hub</a>.</p> ]]></content:encoded>
            <category><![CDATA[Security Week]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Compliance]]></category>
            <guid isPermaLink="false">2JMe5N3c4arpvGb4eNcd3l</guid>
            <dc:creator>Ling Wu</dc:creator>
            <dc:creator>Matt Gallagher</dc:creator>
        </item>
        <item>
            <title><![CDATA[Updates to Cloudflare Security and Privacy Certifications and Reports]]></title>
            <link>https://blog.cloudflare.com/updates-to-cloudflare-security-and-privacy-certifications-and-reports/</link>
            <pubDate>Sat, 11 Dec 2021 13:59:14 GMT</pubDate>
            <description><![CDATA[ Customer confidence in our ability to handle their sensitive information in an ever-changing regulatory landscape has to be as solid as our offerings, so we have expanded the scope of our previously-existing compliance validations; not only that, we’ve also managed to obtain a couple of new ones. ]]></description>
            <content:encoded><![CDATA[ <p></p><p>Cloudflare’s products and services are protecting more customers than ever with significant expansion over the past year. Earlier this week, we launched Cloudflare Security Center so customers can map their attack surface, review potential security risks and threats to their organization, and have generally fast tracked many offerings to meet the needs of customers.</p><p>This rapid expansion has meant ensuring our security, privacy, and risk posture grew accordingly. Customer confidence in our ability to handle their sensitive information in an ever-changing regulatory landscape has to be as solid as our offerings, so we have expanded the scope of our previously-existing compliance validations; not only that, we’ve also managed to obtain a couple of new ones.</p>
    <div>
      <h3>What’s New</h3>
      <a href="#whats-new">
        
      </a>
    </div>
    <p>We’ve had a busy year and focused on our commitment to privacy as well as complying to one of the most rigorous security standards in the industry. We are excited about the following achievements in 2021:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5NxVjOBGH7kQLFkBvZZjgn/0494dbca8a01269ebcbeaa0d9d46810a/image2-48.png" />
            
            </figure><p>FedRAMP In Process - Cloudflare hit a major milestone by being listed on the <a href="https://marketplace.fedramp.gov/#!/product/cloudflare-federal?sort=productName">FedRAMP Marketplace</a> as ‘In Process’ for receiving an agency authorization at a moderate baseline. Once an Authorization to Operate (ATO) is granted, it will allow agencies and other cloud service providers to leverage our product and services in a public sector capacity.</p><p>ISO 27701:2019 (International Organization for Standardization) - Cloudflare is one of the first companies in the industry to achieve ISO 27701 certification as both a data processor and controller. The certification provides assurance to our customers that we have a formal privacy program that is aligned to GDPR.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5pfaggrDT8lAaVR9jxfQA/b4e708c46d6cd50798c5e2957c82de5b/image3-32.png" />
            
            </figure><p>Self-Serve Compliance Documentation - Pro, Business, and Enterprise customers now have the ability to obtain a copy of Cloudflare’s certifications, reports, and overview through the <a href="https://support.cloudflare.com/hc/en-us/articles/4412661740941-Access-Compliance-Documentation">Cloudflare Dashboard</a>.</p>
    <div>
      <h3>Security Certifications &amp; Reports</h3>
      <a href="#security-certifications-reports">
        
      </a>
    </div>
    <p>Cloudflare understands the importance of maintaining compliance to industry standards, certifications, and reports. Our customers rely on the certifications we have to ensure secure and private handling of their data. Each year, the security team expands the scope of these validations to ensure that all of our applicable products and services are included.  Cloudflare has met the requirements of the following standards:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3hZRL6jSUQU6Py4fQNTi0l/dd6738aa9a5b4f2a2da3068666caaaea/image7-10.png" />
            
            </figure><p>SOC-2 Type II / SOC 3 (Service Organizations Controls) - Cloudflare maintains SOC reports that include the security, confidentiality, and availability trust principles. The SOC-2 report provides assurance that our products and underlying infrastructure are secure and highly available while protecting the confidentiality of our customer’s data. We engage with our third-party assessors on an annual basis, and the report provided to our customers covers a period of one full year.</p><p>ISO 27001:2013 (International Organization for Standardization) - Cloudflare has been ISO 27001 certified since 2019. Customers can be assured that Cloudflare has a formal information security management program that adheres to a globally recognized standard.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4z2ZT9Wi6nbGNINBgL7iJo/ca8fde6aeea4ee1f9dbe7978cbe0970b/image9-4.png" />
            
            </figure><p><a href="https://www.cloudflare.com/learning/privacy/what-is-pci-dss-compliance/">PCI Data Security Standard (DSS)</a> - Cloudflare engages with a QSA (Qualified Security Assessor) on an annual basis to evaluate us as a Level 1 Merchant and a Service Provider. This way, we can assure our customers that we meet the requirements to transmit their payment data securely. As a service provider, our customers can trust Cloudflare’s products to meet requirements of the DSS and transmit cardholder data securely through our services.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5haYZ6uc2P1mSDmWEMr7mZ/49ff33fcd4530fe2f6611cafbeeb5e74/image1-65.png" />
            
            </figure><p>HIPAA/HITECH Act (Health Insurance Portability and Accountability Act/Health Information Technology for Economic and Clinical Health - Covered healthcare entities that are leveraging our enterprise version of our security products to protect their application layer can be assured that Cloudflare can sign Business Associates Agreements (BAA).</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1C7lxBKgzUPhzhCbztgtHu/20b1910b7c52fc2417ffb8860fd8ddfd/image5-16.png" />
            
            </figure><p>1.1.1.1 Public DNS Resolver Privacy Examination - Cloudflare conducted a first-of-its-kind privacy examination by a leading accounting firm to determine whether the 1.1.1.1 resolver was effectively configured to meet Cloudflare’s privacy commitments. A public summary of the assessment can be found <a href="https://www.cloudflare.com/resources/assets/slt3lc6tev37/5xlHCvvNBrvrIoWbuk1vTy/e1058b0d366adf4e983aef99a6ed2a1f/Cloudflare_1.1.1.1_Public_Resolver_Report_-_03302020__2_.pdf">here</a>.</p>
    <div>
      <h3>What’s on our Roadmap?</h3>
      <a href="#whats-on-our-roadmap">
        
      </a>
    </div>
    <p>As a global company, Cloudflare partners with industry experts and regional leaders around the world to determine the best ways to build customer trust. Our infoshare events with existing customers and participation in standards organizations guide our methods to continuously improve the security and privacy posture of our products and services. Part of that improvement is obtaining additional third party validations. At this time, we are evaluating ISO 27018 to give customers additional assurance that we meet industry standards for handling personal data in our cloud platform. We will continue to move forward in our <a href="https://www.cloudflare.com/learning/privacy/what-is-fedramp/">FedRAMP</a> journey. And of course, we are continuously evaluating a range of other region-specific certifications. For the latest information about our certifications and reports, please visit <a href="https://www.cloudflare.com/trust-hub">our trust hub</a>.</p><p>If you are an existing customer and want to give us feedback about a validation, please contact your Account Executive and let them know! We will continue to pursue validations that support our customers’ needs and make the internet safer and more secure.</p> ]]></content:encoded>
            <category><![CDATA[CIO Week]]></category>
            <category><![CDATA[Certification]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Privacy]]></category>
            <guid isPermaLink="false">2DqMzQMGe1mJSn32JKikv7</guid>
            <dc:creator>Ling Wu</dc:creator>
        </item>
        <item>
            <title><![CDATA[Cloudflare Certifications]]></title>
            <link>https://blog.cloudflare.com/cloudflare-certifications/</link>
            <pubDate>Thu, 10 Dec 2020 12:00:00 GMT</pubDate>
            <description><![CDATA[ We think trust is fundamental to building a better Internet. Cloudflare adheres to industry-standard security compliance certifications and regulations to help our customers earn their users’ trust. ]]></description>
            <content:encoded><![CDATA[ <p></p><p>At Cloudflare, we prioritize initiatives that improve the security and privacy of our products and services. The security organization believes trust and transparency are foundational principles that are ingrained in what we build, the policies we set, and the data we protect. Many of our enterprise customers have stringent regulatory compliance obligations and require their cloud service providers like ourselves to provide assurance that we meet and exceed industry security standards. In the last couple of years, we’ve decided to invest in ways to make the evaluation of our security posture easier. We did so not only by obtaining recognized security certifications and reports in an aggressive timeline, but we also built a team that partners with our customers to provide transparency into our security and privacy practices.</p>
    <div>
      <h3>Security Certifications &amp; Reports</h3>
      <a href="#security-certifications-reports">
        
      </a>
    </div>
    <p>We understand the importance of providing transparency into our security processes, controls, and how our customers can continuously rely on them to operate effectively. Cloudflare complies with and supports the following standards:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/58wbHF8JPYMoGYoQ6HZHQV/dfcca75f7fdcabce9888445d2a6b4cbf/image4-3.jpg" />
            
            </figure><p>SOC-2 Type II / SOC 3 (Service Organizations Controls) - Cloudflare maintains SOC reports that include the security, confidentiality, and availability trust principles. The SOC-2 report provides assurance that our products and underlying infrastructure are secure and highly available while protecting the confidentiality of our customer’s data.  We engage with our third-party assessors on an annual basis, and the report provided to our customers covers a period of one full year.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4giruqaFOEZOQJzISJWVnx/a36041eb60295a843298bf98542c8a1f/image5-18.png" />
            
            </figure><p>ISO 27001:2013 (International Standards Organization) - Cloudflare’s ISO certification covers our entire platform including our edge network and core data centers. Customers can be assured that Cloudflare has a formal information security management program that adheres to a globally recognized standard.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7btv7cHDpbSrYwMz99F8sQ/a245d79d49592d3a3b1abc98e68765eb/image2-23.png" />
            
            </figure><p>PCI Data Security Standard (DSS) - Cloudflare engages with a QSA (qualified security assessor) on an annual basis to evaluate us as a Level 1 Merchant and a Service Provider. This way, we can assure our customers that we meet the requirements to transmit their payment data securely. As a service provider, our customers can trust Cloudflare’s products to meet requirements of the DSS and transmit cardholder data securely through our services.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7ABqJpPo9p1KSwzG5n3i83/afc55cd6dc362e6d172bfb059a5ebb11/image1-40.png" />
            
            </figure><p>HIPAA/HITECH Act (Health Insurance Portability and Accountability Act/Health Information Technology for Economic and Clinical Health - Covered healthcare entities that are leveraging our enterprise version of our security products to protect their application layer can be assured that Cloudflare can sign Business Associates Agreements (BAA).</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4TFsDK6aJozSWpBDy05KQK/503e35b44856d519295d0c043235b9da/image3-30.png" />
            
            </figure><p>1.1.1.1 Public DNS Resolver Privacy Examination -  Cloudflare conducted a first-of-its-kind privacy examination by a leading accounting firm to determine whether the 1.1.1.1 resolver was effectively configured to meet Cloudflare’s privacy commitments. A public summary of the assessment can be found <a href="https://www.cloudflare.com/resources/assets/slt3lc6tev37/5xlHCvvNBrvrIoWbuk1vTy/e1058b0d366adf4e983aef99a6ed2a1f/Cloudflare_1.1.1.1_Public_Resolver_Report_-_03302020__2_.pdf">here</a>.</p>
    <div>
      <h3>Security Engagement Team</h3>
      <a href="#security-engagement-team">
        
      </a>
    </div>
    <p>We understood that having security compliance certifications and reports would provide ease of mind when using our products, but we knew it may not be enough for those who are sending their most sensitive information through our services. We decided that it was paramount to build out a Security Engagement Team within our Security Organization. Our Security Engagement Team can work with our customer’s security and compliance functions to understand their regulatory and compliance landscape. They are here to understand our customer’s use cases, address concerns, and communicate asks and requests to our Validations, Risk, and Security Engineering Teams so we know what’s top of mind from our customers.</p><p>We strive to put trust first. The certifications and reports we obtain, the security features we build, the white papers, faqs, and documents that we create — we build all of these resources based on the needs of our customers.  In the future, we will continue to listen closely to our customers, with the goal of continuously improving the security and privacy of our products and services.</p><p>For more information about our certifications and reports please visit our compliance page - <a href="https://www.cloudflare.com/privacy-and-compliance/certifications/">cloudflare.com/compliance</a>. You can also reach us at <a href="#">compliance@cloudflare.com</a> for any questions.</p> ]]></content:encoded>
            <category><![CDATA[Privacy Week]]></category>
            <category><![CDATA[Certification]]></category>
            <category><![CDATA[PCI Certified]]></category>
            <guid isPermaLink="false">14iaMZCrprZMBXkUg2CMkW</guid>
            <dc:creator>Ling Wu</dc:creator>
        </item>
    </channel>
</rss>