Google Cloud’s industry-leading certifications, documentation, and third-party audits to help support your compliance.
As part of your migration to the cloud, you may need to validate our compliance documentation, certifications, and controls. Google Cloud creates and shares mappings of our industry-leading security, privacy, and compliance controls to standards from around the world. We also regularly undergo independent verification—achieving certifications, attestations, and audit reports to help demonstrate compliance.
Customers interested in Google Cloud’s approach to AI can reference Google Cloud’s Approach to Trust in Artificial Intelligence for a view into our security, privacy, governance, and responsible AI posture.
Expert insights into an industry with a significant history and diverse regulatory landscape. Explore our regional compliance papers on the telecommunications industry.
United States: Regulatory themes in the telecommunications industry
Europe: Insights into telecom regulations
Middle East: Insights into telecom regulations
Latin America: Telecoms regulatory themes
India: Regulatory themes in the telecommunications industry
An independent third-party auditor has granted a formal certification, attestation, or audit report based on an assessment that affirms our compliance with these offerings.
Global?
Cloud Computing Compliance Controls Catalog (C5) | CSA | GSMA SAS-SM | Higher Education Cloud Vendor Assessment Tool (HECVAT) | ISO 9001:2015 | ISO 22301:2019 & BS EN ISO 22301:2019 | ISO 50001:2018 | ISO/IEC 27001 | ISO/IEC 27017 | ISO/IEC 27018 | ISO/IEC 27701 | ISO/IEC 42001 | PCI 3DS Core Security Standard | PCI DSS | PCI PIN Security | SOC 1 | SOC 2 | SOC 3 | SWIFT on Google Cloud | Uptime Institute's Tier Standards | VPAT (WCAG, U.S. Section 508, EN 301 549)
The Americas
FedRAMP?|?FIPS 140-2 Validated | HITRUST CSF?| Independent Security Evaluators (ISE) Audit | Minimum Acceptable Risk Standards for Exchanges (MARS-E) | Protected B (Canada) | StateRAMP | TruSight?| U.S. Cybersecurity Maturity Model Certification (CMMC) |?U.S. Defense Information Systems Agency Provisional Authorization
EMEA
Spain Esquema Nacional de Seguridad (ENS)?|?EU Cloud Code of Conduct | HDS | ISAE 3000 Type 2 Report (FINMA) | ISO 14001 | Microfin | NCSC - Cyber Essentials Plus (UK) | Police Assured Secure Facilities (PASF) | Qatar National Information Assurance (NIA)?| SWIPO Data Portability Code of Conduct |?TISAX
Asia Pacific
Australia Hosting Certification Framework (HCF) | Cloud Security Assurance Program (CSAP) "Low Level" for Group C | Information System Security Management and Assessment Program (ISMAP) | IRAP (Information Security Registered Assessors Program) | JIIMA |?K-ISMS (Korea)?| MTCS (Singapore) Tier 3?| OSPAR?|?SNI 27001 | ETDA (Thailand)
Cloud service providers can’t provide formal certification of our customers compliance with these laws and regulations. To help support our customers, we review these laws and regulations and where possible provide guidance documents, mappings, and papers that outline our technical capabilities and legal commitments.?
Global and North America
GxP |?California Consumer Privacy Act (CCPA) | COPPA (U.S.)?| Export Administration Regulations (EAR) | FERPA (U.S.) | FINRA (US) | Google Cloud Data Processing Addendum Mapping - U.S. State Privacy Laws | HIPAA | IRS 1075 |?International Traffic in Arms Regulations (ITAR) | GLBA | OSFI (Canada) | FG16/5 - FCA | NERC CIP | PHIPA (Canada) | StateRAMP | PIPEDA (Canada)?| Québec (Canada) Law 25 / la Loi 25 | US Federal Banking Agencies | U.S. Defense Federal Acquisition Regulation Supplement (DFARS)
EMEA
ACPR (France) | BaFin Cloud Outsourcing Guidance | Banco de Espa?a?|?Banco de Portugal | Bank of Italy?|?BRSA (Turkey) |?BSI Critical Infrastructure (KRITIS) |BWG (Austria)?| Central Bank of Ireland (Ireland) | CSSF (Luxembourg)?|?De Nederlandsche Bank (the Netherlands) | EU AI Act | EU DORA | European Union’s Digital Markets Act | EU Solvency II | EU Standard Contractual Clauses | FINMA (Switzerland) |?FSA (Denmark) | GDPR | Google Cloud & the EU Network and Information Systems Directive (NIS2) | ISO 14001 | Israel’s Privacy Protection Authority |?KNF (Poland) |?MaRisk AT 9 Outsourcing | PRA (UK) | revFADP (Switzerland) | South Africa POPI | SFSA (Sweden) | Telecoms Security Act (UK) | VAG (Austria)| SYSC 8 Outsourcing - FCA Handbook | UK CHECK
Latin America?
PDPL (Argentina) | BCRA (Argentina) | Central Bank of Brazil (Brazil) |?CNBV (Mexico)?|?CNSF (Mexico) |?CMF (Chile) | Superintendencia de Banca (Peru) | Financial Superintendence of Colombia | Lei Geral de Prote??o de Dados (LGPD) |?ASFI (Bolivia)?
Asia Pacific
Act on the Protection of Personal Information (Japan) | APRA Prudential Standard CPS 234?| APPs (Australia) | APRA (Australia) | Bank Negara (Malaysia)?|?Bank of Thailand (BOT) | BSP (Philippines) | DSA (Bangladesh) | FSC Insurance Outsourcing Directions?|?FSC Banking Outsourcing Regulations | GR 95/2018 guidelines | IA (Hong Kong)?|?HKMA (Hong Kong)?|?MAMPU (Malaysia)?|?PDPO (Hong Kong)?|?Indonesia Government Regulation No. 71 (GR 71)?|?IRDAI (India) | FSC (Korea) | Korean Financial Supervisory Service (FSS) | MAS TRM Guidelines |?OIC (Thailand) | OJK Circular 21 of 2017 (SEOJK 21)?|?OJK Regulation No. 38 of 2016 (POJK 38) |?PDP Law (Indonesia)?| PDPA (Malaysia)?|?PDPA (Philippines)?|?PDPA (Taiwan)?|?PDPA (Thailand) | PDPD (Vietnam) | PIPA (Korea) |?RBI (India)?|?Reserve Bank of New Zealand (New Zealand) | Securities and Exchange Board of India (SEBI) | PDPA (Singapore)?| State Bank of Vietnam | The Privacy Act (New Zealand)
Our products, technical capabilities, guidance documents, and legal commitments help our customers map to these frameworks and alignments. These offerings may not require formal certification or attestation, though we may rely on our certifications, attestations, and reports to help our customers map to these frameworks and alignments.
Global
Bitsight | Center for Internet Security (CIS) Benchmarks | CyberGRX | ISO/IEC 27110 | Know Your Third Party (KY3P) Report | MVSP | ProcessUnity Global Risk Exchange | Standardized Information Gathering (SIG) Questionnaire | USDM Life Sciences?| Whistic
EMEA
EBA (EU) | European Cloud User Coalition (ECUC) | EIOPA (EU) | NCSC - Cloud Security (UK) | NEN (Netherlands) | NHS (UK) | PiTuKri |?Qualifying license (Kingdom of Saudi Arabia)
North America
Criminal Justice Information Services (CJIS) | FFIEC (US) | MPA | NIST 800-53 | NIST 800-171 | NIST 800-34 - Contingency Planning | StateRAMP |?US Federal Banking Agencies
Asia Pacific
ABS (Singapore) |?PMDA (Japan) | FISC (Japan) | MeitY (India) | Monetary Authority of Singapore (MAS) Guidelines | NISC (Japan) | 2G3M (Japan)
Tell us what you’re solving for. A Google Cloud expert will help you find the best solution.
跑马了是什么意思hcv9jop1ns7r.cn | 梦见爸爸去世预兆什么hcv7jop6ns0r.cn | ca什么意思xjhesheng.com | 耳鸣用什么滴耳液hcv8jop2ns6r.cn | 4.11是什么星座hcv9jop0ns9r.cn |
吃什么能增加免疫力hcv9jop5ns1r.cn | 靶向药是什么hcv8jop2ns1r.cn | 裘是什么意思hcv9jop1ns0r.cn | 有因必有果什么意思hcv8jop2ns9r.cn | 来月经喝红糖水有什么好处hcv8jop2ns1r.cn |
foreplay是什么意思hcv9jop1ns7r.cn | 糖筛和糖耐有什么区别hcv8jop9ns5r.cn | 无伤大雅是什么意思hcv8jop3ns7r.cn | 四月是什么星座hcv7jop9ns0r.cn | 一什么方法imcecn.com |
什么是疣体hcv9jop5ns9r.cn | 吹空调喉咙痛什么原因hcv7jop4ns5r.cn | 家五行属什么hcv8jop3ns0r.cn | 周瑜是什么生肖hcv8jop1ns1r.cn | amass是什么牌子hcv9jop5ns5r.cn |