ZenGRC

August 2020: Compliance Certification Roundup - ZenGRC

In August 2020, ZenGRC reported notable PCI certifications including SmartStream's PCI-DSS level 1 certification, Effectual's Level 1 Service Provider certification, Rectangle Health's PCI SSC P2PE and Level 2 Service Provider certifications, MYPINPAD's pioneering PCI SSC certification for Android contactless payments, and various ISO certifications such as Tangoe's and Al Meera's ISO 27001 certifications for information security management.

Each month, ZenGRC highlights companies that have earned compliance certifications for information security frameworks.

Here’s the August 2020 roundup of compliance news from around the United States and the world.

PCI Certification

PCI certification and compliance are two different, but related, designations.

  • PCI certification is a more rigorous process involving an intensive audit performed by a Qualified Security Assessor (QSA).
  • PCI compliance means a company follows best practices to help protect Cardholder Data (CHD) following the guidelines set by the PCI Council.

Notable PCI certifications in July:

  • SmartStream (New York City): PCI-DSS version 3.2.1, level 1 certification.
  • Effectual (Hoboken, NJ): PCI DSS certification as a Level 1 Service Provider, awarded by Coalfire.
  • Rectangle Health (Valhalla, NY): Certified as an official PCI SSC Point-to-Point Encryption (P2PE) Solution Provider and PCI Level 2 Service Provider, awarded by Coalfire.
  • MYPINPAD (London, England): First company to achieve PCI SSC certification for its Android software-based Contactless Payments on Commercial off-the-shelf (CPoC) solution.
  • RNL (Cedar Rapids, Iowa): PCI-DSS 3.2 compliance and certification for RNL Engage Remote Engagement with WebRTC.
  • Sum And Substance Ltd (London, UK): PCI DSS attestation of compliance as a Service Provider.
  • The Results Companies (Fort Lauderdale, FL): PCI-DSS compliance for data centers, global network, call centers, and Results Home Office™ technology.

ISO Certification

ISO standards concern many industries. The three primary ISO standards that help organize compliance for companies looking to create IT programs: IT, ISO 27001, ISO 31000, and ISO 9001.

Notable ISO certifications in July:

  • Tangoe (Parsippany, NJ): ISO 27001 certification.
  • Al Meera Consumer Goods Company (Qatar): ISO/IEC 27001:2013 certification for Information Security Management System (ISMS).
  • ORYX Gaming (Las Vegas, NV): ISO/IEC 27001 certification.
  • Delasport (Gibraltar): ISO/IEC 27001:2017 certificate accreditation.
  • PariPlay Limited (Gibraltar): ISO/IEC 27001:2017 certificate accreditation.
  • YITU Technology (Shanghai, China): ISO/IEC 27701:2019 certification for privacy information management system, first AI company in China to receive it.
  • PFU America, Inc. (Sunnyvale, CA): ISO 27001 certification, audited by Schellman & Company LLC.
  • Unicon (Gilbert, AZ): ISO 27001:2013 certification across professional services, cloud services, and operations.
  • Aprio (Atlanta, GA): Accredited as an ISO 27701 Certifying Body by ANSI-ASQ Accreditation Board (ANAB), first full-service CPA firm in the U.S. to receive ANAB’s ISO 27701 certification.
  • Qatar Chamber of Commerce (Doha, Qatar): ISO 27001:2013 certification for information security management systems.
  • Snapdeal (New Delhi, India): ISO/IEC 27001:2013 certification, audited by BSI group.
  • Cornerstone (London, UK): ISO 27701 certification for a Privacy Information Management System.

SOC 2 Certification

SOC 2 concerns all organizations and enterprises providing services that process and store customer data. SOC 2 reports are based on five Trust Services Criteria: security, availability, confidentiality, processing integrity, and privacy.

Notable SOC 2 certifications in July:

  • True Influence (Princeton, NJ): SOC 2 Type 2 audit.
  • Aithent Inc. (New York City): SSAE-18, SOC 2 Type 2 audit.
  • SOC Prime (Washington, D.C.): SOC 2 Type I audit.
  • Quixy (Hyderabad, India): SOC 2 Type 2 compliance and ISO 27001 certification.
  • BiZZdesign (Enschede, Netherlands): SOC 2 – Type 2 attestation.
  • W Energy Software (Tulsa, OK): SOC 2 Type 2 Audit for Financial and Transaction Management Software System.
  • BackChecked LLC (Phoenix, AZ): SOC 2 Type 2 audit.
  • Botkeeper (Boston, MA): SOC 2 Type 1 compliance audit.
  • Cymulate (New York City): SOC 2 Type 2 compliance and ISO 27001 certification.
  • SeamlessDocs (New York City): SOC 2 Type 1 compliance and HIPAA compliance, audited by A-Lign.
  • Even Financial (New York City): SOC 2 Type 2 examination, audited by Schneider Downs & Co.
  • RecVue Inc. (Palo Alto, CA): SOC 1 Type 2 and SOC 2 Type 2 examinations.
  • Megaphone (Reston, VA): SOC 1 Type I and SOC 2 examinations for financial and information security management.
  • Longbow Advantage (Ann Arbor, MI): SOC 2 certification for the fourth year in a row.
  • Proctortrack (New York City): SOC 2 Type 2 certification.
  • X20 Media (Montreal, Canada): SOC 2 Type 2 audit.
  • NowSecure (Chicago, IL): SOC 2 Type 2 certification.
  • Dividend Finance (San Francisco, CA): SOC 2 Type 2 accreditation.
  • Brightleaf Solutions (Brookline, MA): SOC 2 Type 1 audit.

FedRAMP Certification

The Federal Risk and Authorization Management Program (FedRAMP) is a government program that determines if the cloud products and services offered by cloud service providers are secure enough to be used by federal agencies.

Notable FedRAMP certifications in July:

  • Everlaw (Oakland, CA): FedRAMP Moderate Authority to Operate, in partnership with the Department of Justice.
  • Elastic (Mountain View, CA): FedRAMP Moderate authorization.
  • Backstop Solutions Group (Chicago, IL): SOC 2 Type II certification.
  • Ivalua (Redwood City, CA): FedRAMP Ready status for moderate impact certification.
  • Snowflake (San Mateo, CA): FedRAMP Moderate Authorization to Operate (ATO) on AWS US East and Microsoft Azure Government cloud.
  • Dynatrace (Waltham, MA): FedRAMP moderate impact level authorization, available via Dynatrace for Government.

HIPAA Compliance

Compliance with the Federal Health Insurance Portability and Accountability Act (HIPAA) ensures that health care organizations protect the privacy, security, and integrity of protected health information.

Notable HIPAA compliance achievements in July:

  • IntelePeer (San Mateo, CA): Atmosphere CPaaS is now HIPAA compliant.
  • ExtraHop (Seattle): Independent validation for HIPAA policies, procedures, and technology, conducted by CoalFire.
  • StarLeaf (Watford, UK): Achieved HIPAA compliance, allowing entry into Business Associate Agreements with US healthcare organizations.
  • The 20 (Plano, TX): Achieved HIPAA compliance using Compliancy Group’s proprietary HIPAA solution.
  • IMImobile (Boca Raton, FL): Completed HIPAA compliance assessment for IMIconnect platform.