Lansweeper’s security compliance program aligns with globally recognized standards and undergoes regular independent assessments. As regulations evolve, Lansweeper expands our compliance coverage to ensure our platform meets the expectations of regulated industries and public-sector organizationsworldwide.
| What It Is | How Lansweeper Meets It | |
|---|---|---|
|
SOC 2 Type 2 |
Independent audit validating the design and operating effectiveness of security, availability, confidentiality, and privacy controls (AICPA TSC). |
Lansweeper undergoes recurring audits by accredited CPA firms. Controls such as access management, change management, secure development, monitoring, and incident response are assessed annually to confirm they operate effectively over time. |
|
ISO/IEC 27001:2022 |
International standard for establishing, operating, and continuously improving an |
Lansweeper undergoes recurring audits by accredited CPA firms. Lansweeper maintains a formal ISMS with risk assessments, security policies, governance processes, and internal audits. Security controls from ISO Annex A are implemented and reviewed regularly to ensure ongoing compliance. |
|
TX-RAMP |
Texas statewide security authorization for cloud solutions used by public-sector organizations. |
Lansweeper’s security controls, documentation, and risk management processes have been reviewed against TX-RAMP requirements to ensure compliance with state-level expectations for protecting sensitive data. |
|
CSA STAR Level 1 |
Cloud Security Alliance program requiring transparent documentation of cloud security practices via the CAIQ and Cloud Controls Matrix. |
Lansweeper publishes detailed responses to the CAIQ, demonstrating how our cloud security controls align with CSA best practices across data protection, IAM, incident response, and infrastructure security. |
|
CMMC |
U.S. DoD Cybersecurity Maturity Model Certification for contractors and supply-chain participants. |
Lansweeper current policies, processes and technical implementation already cover all requirements of CMMC level 1. Lansweeper evaluates additional measures that must be taken to fully comply with CMMC level 2. |
|
NIS2 |
EU directive requiring stronger cybersecurity, incident reporting, and operational resilience for essential/important entities. |
Lansweeper doesn’t need to adhere to NIS2, yet our Lansweeper governance, security controls, incident response, and supply-chain safeguards, aligns with NIS2 principles to support customers subject to NIS2 obligations. |
|
GDPR |
EU regulation governing personal |
Lansweeper implements dataminimization, access controls, encryption, audit logging, DPA commitments, user rights processes, and privacy-by-design practices to support GDPR compliance across our services. |
|
VPAT |
Accessibility evaluation aligned to Section 508, WCAG, and EN 301 549. |
Lansweeper completes a VPAT to disclose accessibility capabilities and gaps, supporting customers with procurement and accessibility compliance requirements. |
"*" indicates required fields