SOC2C

Is this your company? Buyers are checking dotCMS Services LLC here. Claim dotcms.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
dotCMS Services LLC logo

dotCMS Services LLC

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

dotCMS Services LLC is SOC 2 Type II compliant. dotCMS Services LLC also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

dotCMS is the most agile, scalable and secure content management system for enterprise. Built on leading Java technology, dotCMS is an open-source, hybrid multi-tenant headless content management system that gives developers the flexibility of a headless CMS while equipping marketers with no-code visual content authoring. Whether you're building a network of global websites, an employee intranet, customer portal, or single page web application, dotCMS helps you manage content, images, and assets in one centralized location and deliver them to any channel.

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Subprocessors

5
  • A
    AWS · aws
  • G
    Google Cloud Platform · Cloud provider
  • S
    Strong DM
  • K
    Keeper
  • G
    GitHub · github

Compliance leadership

The person who leads dotCMS Services LLC's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. dotCMS Services LLC's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Security fixesMar 2026

dotCMS has fixed 3 critical and high severity vulnerabilities and disclosing them as part of the responsible disclosure program. SI-72 (CVE-2024-4447) permitted users with access to the System Maintenance pane to extract session ID data via the DWR APIs. This could allow high permission users to obfuscate attribution. SI-73 (CVE-2025-8311) resolved a blind SQLi vulnerability in the "/api/v1/contenttype" endpoint that could allow an authenticated, low-privileged user to extract sensitive data or escalate privileges. SI-74 (CVE-2025-11165) addressed a sandbox escape vulnerability in the Velocity scripting engine (VTools) that could enable bypassing class/package restrictions and potential command execution under application privileges. All 3 issues are fixed and merged into dotEvergreen as it always receives the fixes automatically. For customers without dotEvergreen or a supported LTS release, we strongly recommend to use backported versions 25.07.10 LTS or 24.12.27 LTS.

dotCMS Achieves 2025 SOC 2 Type II CertificationSep 2025

We are pleased to announce that dotCMS has successfully completed its 2025 SOC 2 Type II audit, covering the period from September 1, 2024 to August 31, 2025. Conducted by an independent third-party auditor, the examination validated that our controls operated effectively across 4 Trust Services Criteria for Security, Availability, Confidentiality, and Privacy, with no exceptions noted. This milestone underscores our continued commitment to delivering a secure, reliable, and privacy-first CMS platform for our customers worldwide. At dotCMS is a secure brand that safeguards your data and ensures operational resilience remain top priorities. For reference, the new SOC2 II report is available from the left banner under Resources in our Trust Center at https://security.dotcms.com/

Security Advisory SI-73 and CVE-2025-8311 Now PublishedSep 2025

dotCMS security team have completed a fix to security Issue SI-73, which discloses a recently addressed SQLi vulnerability affecting the /api/v1/contenttype endpoint API. The corresponding CVE-2025-8311 (https://www.cve.org/CVERecord?id=CVE-2025-8311), is now live as well. You can find full technical details and mitigation guidance here: 🔗 SI-73 Advisory on dotCMS Please review the advisory and ensure your systems are updated to a patched release if applicable. Let us know if you have any questions or require assistance by contacting security@dotcms.com or your CSM. Thank you dotCMS Security Team

ISO/IEC 27001:2022 re-Certification AchievedMay 2025

dotCMS is proud to announce that we have achieved ISO/IEC 27001:2022 certification for our Information Security Management System (ISMS). This globally recognized standard affirms our commitment to maintaining the highest level of security, privacy, and risk management across our content management platform. The certification scope includes our Cloud Engineering, Software Development, and Product Support functions, and reflects our ongoing dedication to protecting customer data and maintaining operational excellence. 🔐 Certificate Number: 122254 📅 Valid Until: June 19, 2026 📄 Issued by: Prescient Security LLC

Next.js and the corrupt middleware: the authorizing artifactMar 2025

A critical vulnerability (CVE-2025-29927) in Next.js middleware that allows attackers to bypass authorization mechanisms across all versions of the framework. https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware Remediation: Upgrade to Next.js v14.1.4 or later Vercel patched the vulnerability in Next.js v14.1.4, so updating your application to at least this version is the primary mitigation.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is dotCMS Services LLC SOC 2 compliant?
dotCMS Services LLC is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is dotCMS Services LLC ISO 27001 certified?
According to dotCMS Services LLC's public trust center, dotCMS Services LLC is ISO 27001 certified. On SOC2C this listing is Listed.
Is dotCMS Services LLC SOC 2 Type I or Type II?
dotCMS Services LLC is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use dotCMS Services LLC's SOC 2 for a vendor risk assessment?
Yes. dotCMS Services LLC's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is dotCMS Services LLC penetration tested?
dotCMS Services LLC hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.