September 2020: Compliance Certification Roundup - ZenGRC
In September 2020, ZenGRC reported that multiple companies worldwide achieved significant compliance certifications, including PCI-DSS level 1 certifications by SmartStream and iQIYI, SOC 2 Type II by eBizDocs, and various ISO certifications such as ISO 27001 by Tangoe, Folio, Remind, and Comply365, ISO 9001 by Innomar Strategies, PACSHealth, and Silicon Creations, as well as ISO 27701 by Glassbox, highlighting a broad commitment to information security and quality management standards across diverse industries and regions.
Each month, ZenGRC highlights companies that have earned compliance certifications for information security frameworks. Here’s the September 2020 roundup of recent compliance news from around the United States and around the world.
PCI Certification
PCI certification and compliance are two different, but related, designations.
- PCI certification is a more rigorous process involving an intensive audit performed by a Qualified Security Assessor (QSA).
- PCI compliance means a company follows best practices to help protect Cardholder Data (CHD) following the guidelines set by the PCI Council.
Recent PCI Certifications:
- SmartStream (New York City, NY): PCI-DSS version 3.2.1, level 1 certification.
- eBizDocs (Albany, NY): SOC 2 Type II attestation with zero defects.
- iQIYI, Inc. (Beijing, China): PCI DSS certification.
- Payment International Enterprise (Jidhafs, Bahrain): PCI DSS Compliance Certification.
ISO Certification
ISO standards concern many industries. The three primary ISO standards that help organize compliance for companies looking to create IT programs: IT, ISO 27001, ISO 31000, and ISO 9001.
Recent ISO Certifications:
- Tangoe (Parsippany, NJ): ISO 27001 certification.
- Securities and Exchange Commission of Pakistan (Islamabad, Pakistan): Phase 2 of ISO certification for its Information Security Management System (ISMS).
- Folio (Mclean, VA): ISO/IEC 27001 certification.
- Innomar Strategies (Oakville, Ontario, Canada): ISO 9001:2015 certification for clinics and home care nursing services.
- Remind (San Francisco, CA): ISO 27001:2013 certification.
- Glassbox (London, UK): ISO 27701 standard certification.
- Comply365 (Beloit, WI): ISO 27001:2013 certification.
- PACSHealth, LLC (Scottsdale, AZ): ISO 9001:2015 certification for its quality management system.
- Silicon Creations (Lawrenceville, GA): ISO 9001 Quality Management System certification.
- The New Science Degree and PG College (Telangana, India): ISO 9001:2015 accreditation.
- IoT.nxt (Centurion, South Africa): Triple ISO certification and finalized compliance with EU GDPR requirements.
- Peak Performance Compounding (Leominster, MA): ISO 13485:2016 and 9001:2015 certifications.
- Corporate Prime Solutions Inc. (Vancouver, BC): ISO 9001:2015 QMS Re-Certification and ISO/IEC 27001:2013 ISMS Certification.
- WasteServ (Marsa, Malta): ISO 9001:2015 and ISO 14001:2015 certification.
- Axion Polymers (Manchester, UK): Recertified for ISO 9001.
- Aerofloat Australia (Taren Point, Australia): ISO certified in multiple international standards.
- Metropolitan Atlanta Rapid Transit Authority Department of Safety and Quality Assurance (Atlanta, GA): ISO 9001:2015 certification for its Quality Management System.
SOC 2 Certification
SOC 2 concerns all organizations and enterprises providing services that process and store customer data. SOC 2 reports are based on five Trust Services Criteria: security, availability, confidentiality, processing integrity, and privacy.
Recent SOC 2 Certifications:
- True Influence (Princeton, NJ): SOC 2 Type 2 audit.
- EmployStream (Cleveland, OH): SOC 2 Type 1 audit.
- Foko Retail (Gatineau, Quebec, Canada): SOC 2 Type 2 certification.
- Panorays (New York City, NY): SOC 2 Type II audit.
- Criterion Networks (Santa Clara, CA): SOC 2 Type 1 certification for its Criterion SDCloud® platform.
- Meperia (Santa Fe, NM): SOC 2 Type 2 examination.
- Driven Technologies (Norcross, GA): SOC 2 Type 1 examination, HIPAA security compliance assessment, PCI DSS assessment, and penetration tests.
- Tower MSA Partners (Delray Beach, FL): SOC 2 Type I audit.
- Solvvy (San Mateo, CA): SOC 2 Type 1 examination with zero exceptions.
- Contract Room (San Mateo, CA): SOC 2 Type 1 certification.
- Fireminds (Hamilton, Bermuda): SOC2 accreditation renewal.
- Accio Data (Dripping Springs, TX): SOC 2 Type 2 audit for Accio Enterprise platform.
- Employment Screening Resources (Novato, CA): SOC 2 Type 2 accreditation.
- AQuity Solutions (Cary, NC): SOC 2 Type I Audit examination.
- Aithent (New York City, NY): SOC 2 Type 2 audit.
- SWORD Health (New York City, NY): SOC 2 Type 2 examination with zero exceptions.
- Randstad RiseSmart (San Jose, CA): SOC 2 Type I examination.
FedRAMP Certification
The Federal Risk and Authorization Management Program (FedRAMP) is a government program that determines if the cloud products and services offered by cloud service providers are secure enough to be used by federal agencies.
Recent FedRAMP Certifications:
- Zscaler, Inc. (San Jose, CA): FedRAMP “In Process” status at the High Impact level.
- Slack (San Francisco, CA): FedRAMP Moderate certification.
- IronNet Cybersecurity (Mclean, VA): Approved as FedRAMP Ready.
- Geotab: Full FedRAMP authorization for its cloud-based telematics platform.
HIPAA Compliance
Compliance with the Federal Health Insurance Portability and Accountability Act (HIPAA) ensures that health care organizations protect the privacy, security, and integrity of protected health information.
Recent HIPAA Compliance Achievements:
- SOCi (San Diego, CA): Met HIPAA compliance standards.
- Catalytic (Chicago, IL): Completed HIPAA Type 1 compliance examinations.
- C2 Computer Services (Coral Springs, FL): Achieved HIPAA compliance.
- Medallia (San Francisco, CA): Achieved HIPAA compliance.
- CoreSite Realty Corporation (Denver, CO): Achieved HIPAA compliance.