Compliance Certificates

Compliance Certifications

International

  • ISO 27001

    Widely accepted standard that specifies requirements for information security system management

  • ISO 27017

    International certification for cloud computing information security

  • ISO 27018

    International code of conduct that focuses on personal data protection on cloud

  • ISO 29151

    Standards identified by privacy risk and impact assessment

  • BS 10012

    Best practice framework aligned to the principles of the EU GDPR

  • ISO 27701

    Guidance for privacy information management

  • ISO 27799

    Healthcare industry standard on personal health information protection

  • ISO 27034

    Standard that focuses on establishing processes and frameworks for secure software programs.

  • ISO/IEC 20000 -1

    International standard for information technology service management system

  • ISO 22301

    International standard for business continuity management systems

  • CSA STAR gold certification

    International certification for different levels of cloud security

  • PCI DSS

    Global security standard of the payment card industry

  • SOC 1 Type II Report

    Independent audit reports on service providers' security controls

  • SOC 2 Type II Report

    Internal security controls of Huawei Cloud service system

  • SOC 3 Report

    Part of the SOC 2 report available to the public upon application

Other

  • [Germany] C5

    Highly recognized high-level security standard for cloud service providers

  • [US] NIST Cybersecurity Framework

    Cyber security framework based on the classic IPDRR capability model

  • ENS (Esquema Nacional de Seguridad)

    Mandatory law for companies in the public sector and their technology suppliers

  • EU Cloud CoC

    The EU Cloud Code of Conduct (CoC) is an EDPB endorsed and legally operational transnational code of conduct that provides explicit guidance for cloud service providers to effectively incorporate the obligations specified in GDPR Article 28-Processor.

Industry-specific Guidance

Financial Industry

Industry-specific regulatory requirements in each country/region, Huawei Cloud compliance status, and compliance resources