Is this your company?Buyers are checking Commvault here. Claim commvault.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Commvault is a global leader in data protection and management, helping organizations securely manage and recover data across on-premises, cloud, and hybrid environments. Trusted by businesses worldwide, Commvault's platform simplifies data backup, recovery, and compliance. Founded in 1988, Commvault supports thousands of customers in efficiently safeguarding their critical data.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Commvault SOC 2 compliant?
Commvault is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Commvault ISO 27001 certified?
According to Commvault's public trust center, Commvault is ISO 27001 certified. On SOC2C this listing is Listed.
Is Commvault FedRAMP compliant?
According to Commvault's public trust center, Commvault is FedRAMP compliant. On SOC2C this listing is Listed.
Is Commvault NIST CSF compliant?
According to Commvault's public trust center, Commvault is NIST CSF compliant. On SOC2C this listing is Listed.
Is Commvault PCI DSS compliant?
According to Commvault's public trust center, Commvault is PCI DSS compliant. On SOC2C this listing is Listed.
Is Commvault HIPAA compliant?
According to Commvault's public trust center, Commvault is HIPAA compliant. On SOC2C this listing is Listed.
Is Commvault CSA STAR certified?
According to Commvault's public trust center, Commvault is CSA STAR certified. On SOC2C this listing is Listed.
Is Commvault SOC 2 Type I or Type II?
Commvault is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Commvault's SOC 2 for a vendor risk assessment?
Yes. Commvault's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Commvault penetration tested?
Commvault hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Commvault secure?
Security isn't a single yes/no, but Commvault is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001, FedRAMP, NIST CSF, PCI DSS, HIPAA, CSA STAR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Commvault have a bug bounty or vulnerability disclosure program?
Commvault hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@commvault.com or via a /security page (Commvault lists a security contact).
Who are Commvault's subprocessors?
Commvault lists 13 subprocessors on its trust center, including Commvault Systems Limited (UK), Commvault Systems (India) Pty. Ltd, Commvault Systems (Egypt) LLC, Commvault Systems (Australia) Pty. Ltd, Microsoft Corporation. Buyers use this for fourth-party risk review.
Where does Commvault host or store data?
Commvault hosts on AWS, GCP, Azure, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information. Data residency details are on its trust center.
Where is Commvault's trust center or security page?
Commvault's trust center is at https://trust.commvault.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How does Commvault comply with the GDPR and other privacy laws?
Commvault operates a global data privacy program designed around the principles of the GDPR, serving as a foundation to address privacy requirements across different regions. This program is tailored to meet the specific requirements of local regulations, such as the CCPA/CPRA in California, PIPEDA in Canada, and India’s DPDP Act. Our approach emphasizes strong data governance, transparency, and accountability, incorporating measures such as encryption, access controls, and tools to support data subject rights management. We actively monitor and adapt to changes in privacy laws worldwide, aligning our practices with evolving standards. In addition, our dedicated compliance team works closely with customers to provide guidance and solutions that support their compliance efforts, helping them navigate complex regulatory landscapes while maintaining robust data protection practices. For further information about Commvault's compliance with the GDPR and/or privacy laws, please contact [privacy@commvault.com](mailto:privacy@commvault.com).
How does Commvault comply with the EU AI Act and other AI laws?
Commvault adheres to emerging AI regulatory frameworks, such as the EU AI Act, by prioritizing ethical AI practices and governance. We have established internal policies to assess and mitigate risks associated with AI deployment, including evaluating our systems against high-risk AI criteria outlined in the EU AI Act. Our approach integrates principles from the U.S. Executive Order on AI, which emphasizes transparency, privacy protections, and security, as well as the NIST AI Risk Management Framework (RMF), which guides organizations in managing AI risks through fairness, robustness, and accountability. These frameworks complement our global governance efforts and help ensure our AI solutions remain effective, responsible, and compliant. We also monitor developments in other jurisdictions, such as the UK's principles-based approach to AI regulation and similar initiatives in Canada, aligning our practices with emerging standards worldwide. These measures are integrated into our broader compliance and risk management programs, enabling us to provide AI services that are not only innovative but also aligned with customer expectations and regulatory requirements. For further information about Commvault's compliance with the EU AI Act and how our solutions can assist with your obligations, please contact [compliance@commvault.com](mailto:compliance@commvault.com).
How does Commvault comply with NIS2?
As an essential entity under the EU Network and Information Systems Directive (NIS2), Commvault is committed to aligning with all applicable requirements of the directive while supporting our customers in meeting their cybersecurity obligations. Our global compliance team has proactively reviewed and adapted our existing frameworks to align with NIS2 requirements, including measures for cybersecurity risk management, corporate governance, incident reporting, and business continuity planning. These efforts are supported by our adherence to recognized security standards, such as ISO/IEC 27001:2022, SOC 2 Type 2, and FIPS 140-2 certifications, which provide a robust foundation for compliance. Additionally, our preparations are designed to anticipate and align with related EU regulations, such as the Digital Operational Resilience Act (DORA). We actively monitor guidance from EU member states to ensure our compliance approach remains comprehensive and adaptable as national implementation progresses. As a trusted provider of data protection solutions, we leverage our expertise and tools to protect critical systems from evolving cyber threats while empowering our customers to fulfill their own NIS2 obligations. For further information about Commvault's compliance with NIS2 and how our solutions can assist with your obligations, please contact compliance@commvault.com.
How does Commvault comply with DORA?
Commvault is committed to meeting the requirements of the Digital Operational Resilience Act (DORA) by maintaining a strong operational resilience framework. This includes implementing advanced monitoring and incident response mechanisms, ensuring continuous availability of critical services, and regularly testing the integrity and reliability of our systems. We adhere to industry standards, such as ISO 27001 and SOC 2, which provide a foundation for resilience against cyber threats. Customers and partners subject to The Digital Operational Resilience Act (DORA) may request to sign the financial sector addendum by emailing [corporatetrustops@commvault.com](mailto:corporatetrustops@commvault.com "mailto:corporatetrustops@commvault.com"). Commvault's Legal Entity Identifier (LEI) code is 65T5VRP62VXG39YFML83. For further information about Commvault's compliance with DORA and how our solutions can assist with your obligations, please contact [compliance@commvault.com](mailto:compliance@commvault.com "mailto:compliance@commvault.com").
How does Commvault Cloud comply with FedRamp?
Commvault Cloud complies with FedRAMP standards to ensure the highest levels of security and regulatory compliance for our federal customers. To verify the current status of Commvault Cloud’s FedRAMP authorization, you can visit the official FedRAMP Marketplace here: https://marketplace.fedramp.gov/products/FR2115384377.
Where can I find information about Commvault’s ownership and investor structure?
Please use the following link to view Commvault’s ownership details, including major shareholders, on our Ownership Summary page : "https://ir.commvault.com/financial-information/ownership-summary"
How does Commvault Cloud comply with CMMC?
We have completed a CMMC Level 2 self‑assessment aligned to NIST SP 800‑171 and are proceeding with an independent third‑party assessment to be completed by the November effective date. We will share validated results and documentation upon completion. In the interim, we can provide high‑level security information (e.g., encryption, access controls, vulnerability management, incident response) to support your risk review.
How does Commvault comply with the EU Data Act
Commvault is committed to meeting the requirements of the EU Data Act by supporting cloud provider switching and data portability. We will work collaboratively with our customers to enable a smooth, transparent, and compliant data transition process. While the specific approach depends on the Commvault Solutions and/or Services in use, we facilitate prompt transfer of storage environment ownership and provide the technology and guidance necessary to convert customer data into a vendor-neutral format. For additional details, refer to our documentation on Tenant Portability and Migration. Customers and partners subject to the EU Data Act may request to sign Commvault’s EU Data Act Addendum by contacting [corporatetrustops@commvault.com](mailto:corporatetrustops@commvault.com). Please refer to our Technical & Organizational Measures.pdf), Description of Personal Data Processing, and our Government Access Policy for additional details on the safeguards Commvault has in place to protect our Customer’s data. For further information about Commvault’s compliance with the EU Data Act or how our solutions can assist with your obligations, please contact [compliance@commvault.com](mailto:compliance@commvault.com).
How does Commvault comply with export controls and sanctions?
Commvault operates a global export controls and sanctions compliance program designed to meet applicable legal requirements where we do business. Our program includes restricted party and end user screening, destination controls, contractual safeguards, governance, and employee training, and we continuously monitor regulatory developments. For general guidance and questions, please contact compliance@commvault.com.
What is Commvault’s ECCN under the U.S. EAR?
Commvault software is classified under ECCN 5D992.c (self-classification) as set out in our U.S. Export Compliance Notice.
Is Commvault registered with Canada’s Controlled Goods Program (CGP)?
Yes. Commvault Systems (Canada) Inc. is listed in the Government of Canada’s CGP directory [](https://iss-ssi.pwgsc-tpsgc.gc.ca/dmc-cgd/rchrch-srch/w4/new-re-qu-fra.asp?id=4054 "https://iss-ssi.pwgsc-tpsgc.gc.ca/dmc-cgd/rchrch-srch/w4/new-re-qu-fra.asp?id=4054")with an expiry date of 2029-06-03.
Is there an SLA for resolving identified security issues?
Commvault maintains vulnerability management procedures in alignment with industry standards and guided by the Information Security Policy. We do not disclose full Vulnerability reports because this contains proprietary information. Vulnerabilities are remediated in accordance with the Company’s policy. The current SLA for remediation is Critical-30 days, High-60, Medium-90, Low-180 days.