NetApp compliance offerings

magnify glass

January 2023

No single standard or set of controls apply to all possible scenarios. Compliance programs vary in accordance with the type and nature of the solution that is managed under specific controls related to a given compliance program. NetApp organizes its compliance offerings by services, hardware, and software.

FIPS 140
NetApp offers cryptographic modules that have achieved FIPS 140-2 validation, which can vary across hardware and software. NetApp is also pursuing FIPS 140-3 going forward.

∇ For details about NetApp compliance, see FIPS 140.

General Data Protection Regulation (GDPR)
NetApp maintains a comprehensive GDPR strategy. Whether you are a data controller or data processor, NetApp products and services offer the tools necessary to implement programs that support your compliance with the GDPR, and we back our commitments in a number of customer contracts.

∇ For details about NetApp compliance, see NetApp and the GDPR.

California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
We are committed to respecting consumers’ rights and operating in ways designed to comply with the CCPA and its expansion, the CPRA. Our contractual commitments to CCPA compliance are based on whether we are collecting your personal information or acting as a service provider to customers who are collecting personal information. NetApp does not sell or share personal information for the purposes of cross-content behavioral marketing.

∇ For details about NetApp compliance, see NetApp and the CCPA.


These NetApp information services have been evaluated and verified against the industry standards listed below. For more information about each NetApp compliance offering, click the standard name.

FedRAMP ISO/IEC 27001 NIST 800-171 SOC 2 Type I SOC 2 Type II
Amazon FSx for NetApp ONTAP1

Astra Service

Azure NetApp Files2
Cloud Insights
Cloud Manager Platform3
Cloud Volumes Service for AWS

Cloud Volumes Service for GCP
Corporate IT Systems 4

Managed Services in India
NetApp Managed Services in the Americas
SaaS Backup5
Spot PC

Virtual Desktop Service and Virtual Desktop Managed Service

1 Amazon Web Services (AWS) manages compliance for Amazon FSx for NetApp ONTAP. For information, refer to AWS Services in Scope by Compliance Program.
2 Microsoft manages compliance for Azure NetApp Files. For information, refer to Microsoft Azure Compliance Offerings (pages 66 and 76).
3 Cloud Manager, Cloud Sync, Cloud Tiering, Cloud Backup, Cloud Data Sense, Backup for Kubernetes, and App Template.
4 Applicable only to those systems storing controlled unclassified information (CUI).
5 SaaS Backup is no longer available to new customers as of March 16, 2022. While the service continues to operate under the controls outlined in the last available ISO/IEC 27001 certifications and SOC 2 reports, NetApp is no longer supporting ongoing certification of this service and new certifications and reports will not be available.


These NetApp hardware products have been evaluated against the standard listed below. For more information about NetApp’s compliance, click the standard name.

AFF A-Series A200, A220, A250, A300, A320, A400, A700, A700s, A800
AFF C-Series C190
AFF8000 AFF8020, AFF8040, AFF8080EX
FAS 500 FAS 500f
FAS2500 2520, 2552, and 2554
FAS2600 2620, 2650
FAS2700 2720, 2750
FAS8000 8020, 8040, 8060, 8080
FAS8200 8200
FAS8300 8300
FAS 8700 8700


These NetApp software products and platforms have been evaluated against the standards listed below. For more information about each NetApp compliance offering, click the standard name.

Common Criteria/ ISO 15408 DoDIN APL Commercial Solutions for Classified (CSfC) Program
Element Software Element 12.2 and 10.3 running on SolidFire scale-out storage system
NetApp ONTAP ONTAP 9.7P13 and 9.5 ONTAP 9.8, 9.7, 9.6, 9.3,1 and 9.11 ONTAP 9.7P13
NetApp ONTAP Select ONTAP Select 9.5 ONTAP Select 9.8, 9.7, and 9.6
SANtricity Software SANtricity OS 11.70 and 11.50 running on E-Series and EF Series systems
NetApp StorageGRID StorageGRID 11.5
1 NetApp is no longer supporting this product or continuing its certification for DoDIN APL. Customers who require this certification should contact their account representative to ensure this product meets their compliance requirements.
Back To Top
Drift chat loading