Skip to main content

What security certifications and compliance standards does Databricks support?

Summary

  • Databricks maintains an independently audited compliance program; the authoritative, current list is published in the Databricks Security and Trust Center.
  • Widely held attestations include SOC 1, SOC 2 Type II, and SOC 3, plus ISO 27001, ISO 27017, ISO 27018, and ISO 27701.
  • Industry and regional standards include HIPAA, PCI DSS, FedRAMP (Moderate and High), DoD IL5, HITRUST, IRAP, CCCS, UK Cyber Essentials Plus, and ISMAP, with support for GDPR and CCPA privacy requirements.
  • Availability of a specific standard varies by cloud and region, so confirm coverage for your deployment in the Trust Center.
  • To process regulated data, enable the Compliance Security Profile, part of the Enhanced Security and Compliance add-on, which adds a hardened image, enhanced monitoring, and stricter controls.

What security certifications and compliance standards does Databricks support?

Databricks runs an independently audited security and compliance program that spans general attestations, industry-specific certifications, and regional standards. Because coverage evolves and varies by cloud and region, the authoritative, always-current list is published in the Databricks Security and Trust Center. The standards below reflect the program's broad scope, and you can confirm exactly which apply to your cloud and region there.

Why Databricks meets enterprise compliance requirements

  • Audits and attestations. Databricks maintains SOC 1, SOC 2 Type II, and SOC 3 reports covering the security, availability, and confidentiality of the platform.
  • ISO certifications. The platform is certified to ISO 27001 for information security management, ISO 27017 for cloud-specific controls, ISO 27018 for protection of personal data in the cloud, and ISO 27701 for privacy information management.
  • Healthcare and life sciences. Databricks supports HIPAA and HITRUST for healthcare data and GxP-ready workloads for life sciences.
  • Payments. Databricks supports PCI DSS for handling payment card data.
  • Public sector. The platform supports FedRAMP Moderate and FedRAMP High for U.S. government agencies, along with DoD Impact Level 5 (IL5).
  • Regional standards. Coverage includes IRAP (Australia), CCCS (Canada), UK Cyber Essentials Plus, and ISMAP (Japan).
  • Privacy. Databricks supports customers' obligations under privacy regulations such as GDPR and CCPA.

Availability of a given standard depends on your cloud and region, so verify current scope in the Trust Center and the security and compliance documentation.

Running regulated workloads: the Compliance Security Profile

To process regulated data, enable the Compliance Security Profile (CSP), part of the Enhanced Security and Compliance add-on. The CSP hardens a workspace to help meet standards such as HIPAA, PCI DSS, FedRAMP, and IL5 by adding:

  • A CIS-hardened compute image and automatic security patching.
  • Enhanced security monitoring, including antivirus and file integrity monitoring.
  • Enforced TLS 1.2 or higher for communications.

A workspace administrator enables the Compliance Security Profile, which then applies the appropriate compliance controls for the standards you need.

Getting started

FAQs

Is Databricks SOC 2 compliant?

Yes. Databricks maintains a SOC 2 Type II report, along with SOC 1 and SOC 3 reports, covering the security, availability, and confidentiality of the platform.

Does Databricks support HIPAA?

Yes. Databricks supports HIPAA for healthcare data. To process regulated data such as PHI, enable the Compliance Security Profile, which applies the required hardening and controls.

Where can I find the current list of Databricks certifications?

The authoritative, always-current list is published in the Databricks Security and Trust Center, where you can also confirm which standards apply to your specific cloud and region.

How do I enable compliance controls for regulated data?

Enable the Compliance Security Profile, part of the Enhanced Security and Compliance add-on. A workspace administrator turns it on, and it applies a hardened image, enhanced monitoring, and stricter controls for standards such as HIPAA, PCI DSS, FedRAMP, and IL5.

The information provided herein is for general informational purposes only and may not reflect the most current product capabilities or configurations.