SOC2C

Is this your company? Buyers are checking Commvault here. Claim commvault.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Commvault logo

Commvault

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Commvault is SOC 2 Type II compliant. Commvault also holds ISO 27001, FedRAMP, NIST CSF, PCI DSS, HIPAA, and CSA STAR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Commvault is a global leader in data protection and management, helping organizations securely manage and recover data across on-premises, cloud, and hybrid environments. Trusted by businesses worldwide, Commvault's platform simplifies data backup, recovery, and compliance. Founded in 1988, Commvault supports thousands of customers in efficiently safeguarding their critical data.

Compliance & infrastructure

SOC 2 Type IIISO 27001FedRAMPNIST CSFPCI DSSHIPAACSA STAR
Hosting
AWSGCPAzure
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card information

Subprocessors

13
  • C
    Commvault Systems Limited (UK)
    UK
  • C
    Commvault Systems (India) Pty. Ltd
    India
  • C
    Commvault Systems (Egypt) LLC
    Egypt
  • C
    Commvault Systems (Australia) Pty. Ltd
  • M
    Microsoft Corporation
    US/Other
  • A
    Amazon Web Services (AWS) · Applicable for SaaS workloads only
    US/Other
  • O
    Oracle Corporation · Applicable for SaaS workloads only
    US/Other
  • G
    Google Cloud Platform · Cloud infrastructure and storage for Commvault SaaS workloads (e.g., Google Work
    US/Other
  • E
    Egnyte · Applicable for Threatwise only
    US
  • T
    Triple C Cloud Computing Ltd. · Applicable for Threatwise only
    Israel
  • P
    Persistent Systems Malaysia Sdn Bhd
    Malaysia
  • C
    Clumio · Integration with Commvault Cloud
    US
Show all 13 subprocessors
  • S
    Satori · Integration with Commvault Cloud
    US

Compliance leadership

The person who leads Commvault's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Commvault's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Commvault SOC 2 compliant?
Commvault is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Commvault ISO 27001 certified?
According to Commvault's public trust center, Commvault is ISO 27001 certified. On SOC2C this listing is Listed.
Is Commvault FedRAMP compliant?
According to Commvault's public trust center, Commvault is FedRAMP compliant. On SOC2C this listing is Listed.
Is Commvault NIST CSF compliant?
According to Commvault's public trust center, Commvault is NIST CSF compliant. On SOC2C this listing is Listed.
Is Commvault PCI DSS compliant?
According to Commvault's public trust center, Commvault is PCI DSS compliant. On SOC2C this listing is Listed.

Answers published by Commvault

Reproduced from Commvault's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How does Commvault comply with the GDPR and other privacy laws?
Commvault operates a global data privacy program designed around the principles of the GDPR, serving as a foundation to address privacy requirements across different regions. This program is tailored to meet the specific requirements of local regulations, such as the CCPA/CPRA in California, PIPEDA in Canada, and India’s DPDP Act. Our approach emphasizes strong data governance, transparency, and accountability, incorporating measures such as encryption, access controls, and tools to support data subject rights management. We actively monitor and adapt to changes in privacy laws worldwide, aligning our practices with evolving standards. In addition, our dedicated compliance team works closely with customers to provide guidance and solutions that support their compliance efforts, helping them navigate complex regulatory landscapes while maintaining robust data protection practices. For further information about Commvault's compliance with the GDPR and/or privacy laws, please contact [privacy@commvault.com](mailto:privacy@commvault.com).
How does Commvault comply with the EU AI Act and other AI laws?
Commvault adheres to emerging AI regulatory frameworks, such as the EU AI Act, by prioritizing ethical AI practices and governance. We have established internal policies to assess and mitigate risks associated with AI deployment, including evaluating our systems against high-risk AI criteria outlined in the EU AI Act. Our approach integrates principles from the U.S. Executive Order on AI, which emphasizes transparency, privacy protections, and security, as well as the NIST AI Risk Management Framework (RMF), which guides organizations in managing AI risks through fairness, robustness, and accountability. These frameworks complement our global governance efforts and help ensure our AI solutions remain effective, responsible, and compliant. We also monitor developments in other jurisdictions, such as the UK's principles-based approach to AI regulation and similar initiatives in Canada, aligning our practices with emerging standards worldwide. These measures are integrated into our broader compliance and risk management programs, enabling us to provide AI services that are not only innovative but also aligned with customer expectations and regulatory requirements. For further information about Commvault's compliance with the EU AI Act and how our solutions can assist with your obligations, please contact [compliance@commvault.com](mailto:compliance@commvault.com).
How does Commvault comply with NIS2?
As an essential entity under the EU Network and Information Systems Directive (NIS2), Commvault is committed to aligning with all applicable requirements of the directive while supporting our customers in meeting their cybersecurity obligations. Our global compliance team has proactively reviewed and adapted our existing frameworks to align with NIS2 requirements, including measures for cybersecurity risk management, corporate governance, incident reporting, and business continuity planning. These efforts are supported by our adherence to recognized security standards, such as ISO/IEC 27001:2022, SOC 2 Type 2, and FIPS 140-2 certifications, which provide a robust foundation for compliance. Additionally, our preparations are designed to anticipate and align with related EU regulations, such as the Digital Operational Resilience Act (DORA). We actively monitor guidance from EU member states to ensure our compliance approach remains comprehensive and adaptable as national implementation progresses. As a trusted provider of data protection solutions, we leverage our expertise and tools to protect critical systems from evolving cyber threats while empowering our customers to fulfill their own NIS2 obligations. For further information about Commvault's compliance with NIS2 and how our solutions can assist with your obligations, please contact compliance@commvault.com.
How does Commvault comply with DORA?
Commvault is committed to meeting the requirements of the Digital Operational Resilience Act (DORA) by maintaining a strong operational resilience framework. This includes implementing advanced monitoring and incident response mechanisms, ensuring continuous availability of critical services, and regularly testing the integrity and reliability of our systems. We adhere to industry standards, such as ISO 27001 and SOC 2, which provide a foundation for resilience against cyber threats. Customers and partners subject to The Digital Operational Resilience Act (DORA) may request to sign the financial sector addendum by emailing [corporatetrustops@commvault.com](mailto:corporatetrustops@commvault.com "mailto:corporatetrustops@commvault.com"). Commvault's Legal Entity Identifier (LEI) code is 65T5VRP62VXG39YFML83. For further information about Commvault's compliance with DORA and how our solutions can assist with your obligations, please contact [compliance@commvault.com](mailto:compliance@commvault.com "mailto:compliance@commvault.com").
How does Commvault Cloud comply with FedRamp?
Commvault Cloud complies with FedRAMP standards to ensure the highest levels of security and regulatory compliance for our federal customers. To verify the current status of Commvault Cloud’s FedRAMP authorization, you can visit the official FedRAMP Marketplace here: https://marketplace.fedramp.gov/products/FR2115384377.

Business & Industrial peers that completed SOC 2