---
# Global Secure Access certifications
Global Secure Access supports compliance across different regulated industries and global markets. This article lists the current certifications and updates the list as new certifications are completed.
## Supported certifications
Global Secure Access is included in several Azure compliance audits. The supported certifications are:
| Certification | Details | Inherited from | Status |
| --- | --- | --- | --- |
| [Canadian Privacy Laws](https://global.azure.com/auditmanager/certificates/views/cert/217) | Canadian privacy laws—such as the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA)—aim to protect the privacy of individuals and give them the right to access information gathered about them. For more information, see [Canadian Privacy Laws](/azure/compliance/offerings/offering-canada-privacy-laws) | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [CDSA](https://global.azure.com/auditmanager/certificates/views/cert/94) | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) Standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard specifies a set of controls designed to ensure the integrity of intellectual property and the confidentiality and security of media assets at every stage of the digital media supply chain. For more information, see [Content Delivery & Security Association (CDSA) - Azure Compliance](/azure/compliance/offerings/offering-cdsa) | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | Certification available |
| [CSA STAR](https://global.azure.com/auditmanager/certificates/views/cert/132) | The CSA STAR Certification is based on achieving ISO 27001 certification and meeting criteria specified in the Cloud Controls Matrix (CCM). It demonstrates that a cloud service provider conforms to the applicable requirements of ISO 27001, has addressed issues critical to cloud security as outlined in the CCM, and has been assessed against the STAR Capability Maturity Model for the management of activities in CCM control areas. For more information, see [CSA STAR Certification](/azure/compliance/offerings/offering-csa-star-certification) | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [DoD DISA SRG Level 2](https://global.azure.com/auditmanager/certificates/views/cert/122) | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [DoD DISA SRG Level 2](/azure/compliance/offerings/offering-dod-il2) | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [EAR](https://global.azure.com/auditmanager/certificates/views/cert/191) | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [EAR](/azure/compliance/offerings/offering-ear) | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [FedRAMP High](/azure/compliance/offerings/offering-fedramp) | NA | |
| [FIPS 140-2](https://global.azure.com/auditmanager/certificates/views/cert/147) | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [FIPS 140-2](/azure/compliance/offerings/offering-fips-140-2) | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [GDPR](https://global.azure.com/auditmanager/certificates/views/cert/218) | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers (such as organizations using Azure) only use data processors (such as Microsoft) that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [GDPR](/compliance/regulatory/gdpr) | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [GxP (FDA 21 CFR Part 11)](https://global.azure.com/auditmanager/certificates/views/cert/156) | Azure can help customers meet their requirements under Good Clinical, Laboratory, and Manufacturing Practices (GxP), as well as regulations enforced by the US Food and Drug Administration (FDA) under 21 CFR Part 11. For more information, see [GxP (FDA 21 CFR Part 11)](/azure/compliance/offerings/offering-gxp) | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [HDS (France)](https://global.azure.com/auditmanager/certificates/views/cert/209) | Microsoft Azure has been granted the Health Data Hosting (Hébergeurs de Données de Santé, HDS) certification, which is required for all entities hosting personal health data governed by French law. This made Microsoft the first major cloud service provider to meet the strict French standards for storing and processing health data. For more information, see [HDS (France)](/compliance/regulatory/offering-hds-france) | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
---
# Global Secure Access certifications
Global Secure Access supports compliance across different regulated industries and global markets. This article lists the current certifications and updates as Global Secure Access acquires new certifications.
## Supported certifications
Global Secure Access is included in several Azure compliance audits. The supported certifications are:
| Certification | Details | Inherited from | Status |
| --- | --- | --- | --- |
| [Canadian Privacy Laws](https://global.azure.com/auditmanager/certificates/views/cert/217) | Canadian privacy laws aim to protect the privacy of individuals and give them the right to access information gathered about them. These privacy laws include the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA). For more information, see [Canadian Privacy Laws](/azure/compliance/offerings/offering-canada-privacy-laws). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [CDSA](https://global.azure.com/auditmanager/certificates/views/cert/94) | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard includes controls to protect intellectual property and keep media assets secure and confidential throughout the digital media supply chain. For more information, see [Content Delivery & Security Association (CDSA) - Azure Compliance](/azure/compliance/offerings/offering-cdsa). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | Certification available |
| [CSA STAR](https://global.azure.com/auditmanager/certificates/views/cert/132) | Cloud Security Alliance (CSA) STAR certification is based on achieving ISO 27001 certification and meeting criteria in the Cloud Controls Matrix (CCM). It shows that a cloud service provider meets ISO 27001 requirements, addresses key cloud security issues in the CCM, and is assessed against the STAR Capability Maturity Model for managing activities in CCM control areas. For more information, see [CSA STAR certification](/azure/compliance/offerings/offering-csa-star-certification). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [DoD DISA SRG Level 2](https://global.azure.com/auditmanager/certificates/views/cert/122) | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [DoD DISA SRG Level 2](/azure/compliance/offerings/offering-dod-il2). | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [EAR](https://global.azure.com/auditmanager/certificates/views/cert/191) | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [EAR](/azure/compliance/offerings/offering-ear) | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [FedRAMP High](/azure/compliance/offerings/offering-fedramp). | NA | |
| [FIPS 140-2](https://global.azure.com/auditmanager/certificates/views/cert/147) | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [FIPS 140-2](/azure/compliance/offerings/offering-fips-140-2). | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [GDPR](https://global.azure.com/auditmanager/certificates/views/cert/218) | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers, such as organizations using Azure, only use data processors, such as Microsoft, that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [GDPR](/compliance/regulatory/gdpr). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [GxP (FDA 21 CFR Part 11)](https://global.azure.com/auditmanager/certificates/views/cert/156) | Azure can help customers meet their requirements under Good Clinical, Laboratory, and Manufacturing Practices (GxP), as well as regulations enforced by the US Food and Drug Administration (FDA) under 21 CFR Part 11. For more information, see [GxP (FDA 21 CFR Part 11)](/azure/compliance/offerings/offering-gxp). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [HDS (France)](https://global.azure.com/auditmanager/certificates/views/cert/209) | Microsoft Azure has the Health Data Hosting (Hébergeurs de Données de Santé, HDS) certification, which is required for all entities that host personal health data governed by French law. Microsoft is the first major cloud service provider to meet the strict French standards for storing and processing health data. For more information, see [HDS (France)](/compliance/regulatory/offering-hds-france). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |