Cresta

SafeBaseVerified May 2026

Cresta Compliance & Certifications

SOC 2 Type IISOC 3ISO 27001ISO 27701ISO 42001HIPAAPCI DSSGDPRCCPACPRANIST

Frequently Asked Questions

Does Cresta have SOC 2 Type II?

Yes. Cresta holds SOC 2 Type II, SOC 3, ISO 27001, ISO 27701, ISO 42001, HIPAA, PCI DSS, GDPR, CCPA, CPRA, NIST certifications. You can view their trust center at trust.cresta.com for full security and compliance documentation.

Where can I find Cresta's security documentation?

Cresta publishes their trust center on SafeBase at trust.cresta.com. It includes security policies, compliance certifications (SOC 2 Type II, SOC 3, ISO 27001, ISO 27701, ISO 42001, HIPAA, PCI DSS, GDPR, CCPA, CPRA, NIST), and other documentation.

Does Cresta have ISO 27001 certification?

Yes, Cresta is ISO 27001 certified. This international standard confirms they have implemented a comprehensive information security management system (ISMS).

Is Cresta HIPAA compliant?

Yes, Cresta is HIPAA compliant and can support healthcare organizations that handle protected health information (PHI).