Supported security standards
Genesys Cloud supports various industry standard security practices and operational controls. It is certified to meet the requirements of several industry-specific standards listed below.
Industry Standards / Certifications | Genesys Cloud Support | Region | Description |
---|---|---|---|
AgID | Yes | EMEA | The Agency for Digital Italy (Agenzia per l’italia Digitale or AgID) is the “technical agency of the Presidency of the Council of Ministers.” AgID’s cloud strategy is intended to provide “a qualification path for public and private entities to provide Cloud infrastructures and services to the Public Administration (PA) with high standards of security, efficiency and reliability.” |
C5 | Yes | EMEA | The cloud computing compliance criteria catalogue (C5) defines a baseline security level for cloud computing. It’s used by professional cloud service providers, auditors, and cloud customers. |
CCPA | Yes | Americas ** | The California Consumers Protection Act (CCPA) is a state statute intended to enhance privacy rights and consumer protection for residents of California in the United States. |
CSA CAIQ | Yes | Global * | CAIQ is an industry-accepted way to document what security controls exist in our SaaS solutions, providing security control transparency through compliance with the Cloud Controls Matrix. |
Cyber Essentials | Yes | EMEA | Backed by the UK government and overseen by the National Cyber Security Centre (NCSC), Cyber Essentials is a certification scheme designed to show an organization has a minimum level of protection in cyber security through annual assessments to maintain certification. |
Cyber Essentials Plus | Yes | EMEA | Cyber Essentials Plus is a technical audit of the Genesys Cloud CX™ platform against the controls of the Cyber Essentials standard. The Cyber Essentials Scheme is “an effective, (UK) Government backed scheme that will help you to protect your organisation, whatever its size, against a whole range of the most common cyber attacks.” |
DoD Impact Level 2 (IL2) | Yes | Americas (US-East-2 only) |
The U.S. Department of Defense (DoD) Cloud Computing Security Requirements Guide (SRG) provides the baseline security requirements used to assess the security posture of a cloud service offering. Cloud Service Providers (CSPs) supporting U.S. DoD customers are required to comply with these requirements. Genesys Cloud CX has been granted a Provisional Authorization (PA) for DoD Impact Level 2 (IL2) from the Defense Information Systems Agency (DISA) leveraging Genesys’ FedRAMP Moderate Authorization. IL2 is for non-Controlled Unclassified Information (non-CUI), which includes all data cleared for public release, as well as some DoD private unclassified information not designated as CUI or critical mission data that requires some minimal level of access control. |
ENS | Yes | EMEA |
The National Security Scheme (Esquema Nacional de Seguridad or ENS) was first developed in 2010 with its last update in 2022 (Royal Decree 311/2022). The ENS accreditation scheme has been developed by La Entidad Nacional de Acreditación (ENAC) in close collaboration with the Ministry of Finance and Public Administration and the CCN (National Cryptologic Centre). This certification is applicable to the entire Spanish Public Sector and collaborating suppliers. It ensures the adequate protection of information and services, aligning with the ENS framework’s basic principles, requirements, and security measures. |
EU-U.S. Data Privacy Framework (DPF) | Yes | US and EMEA |
The EU-United States Data Privacy Framework, developed by the United States Department of Commerce and the European Commission, enables United States organizations to establish reliable mechanisms for transferring personal data from the European Union to the United States. This certification ensures data protection that is consistent with EU, UK, and Swiss law. |
FedRAMP | Americas (US-East-2 only) |
The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security authorizations for Cloud Service Offerings. Genesys Cloud is FedRAMP authorized at the Moderate Impact Level. |
- * Roadmap for US-East-2 (FedRAMP region)
- ** Not available in US-East-2 (FedRAMP region)