NIST CSF-Compliant Security Vendors
Security vendors that hold NIST CSF certification
Okta
21/32Identity and access management platform providing secure authentication, authorization, and single sign-on for enterprises.
NIST 800-53 Rev. 5
Zscaler
14/32Cloud-native zero trust security platform (ZIA/ZPA) for secure internet and application access.
NIST 800-53 Rev.5 mapping published
Lacework
5/32Cloud security and CNAPP platform for workload protection and compliance monitoring, now part of Fortinet.
Referenced as an alignment standard
Checkmarx
3/32Application security testing (SAST/SCA) platform.
Partial per the vendor's trust center; the specific condition is not detailed there.
These security vendors do not currently hold NIST CSF certification:
- 1Password (not documented)
- CrowdStrike (not documented)
- Snyk (not documented)
- Palo Alto Networks (not documented)
- Cisco Duo (not documented)
- Splunk (not documented)
- SentinelOne (not documented)
- Fortinet (not documented)
- Check Point (not documented)
- Rapid7 (not documented)
- Tenable (not documented)
- Qualys (not documented)
- Proofpoint (not documented)
- Mimecast (not documented)
- KnowBe4 (not documented)
- Auth0 (not documented)
- OneLogin (not documented)
- Ping Identity (not documented)
- JumpCloud (not documented)
- LastPass (not documented)
- Dashlane (not documented)
- Bitwarden (not documented)
- Wiz (not documented)
- Orca Security (not documented)
- Netskope (not documented)
- Darktrace (not documented)
- Varonis (not documented)
- Cybereason (not documented)
- VMware Carbon Black (not documented)
- Trend Micro (not documented)
- McAfee (not documented)
- Symantec (not documented)
- Sophos (not documented)
- Bitdefender (not documented)
- ESET (not documented)
- Malwarebytes (not documented)
- Keeper Security (not documented)
- Ivanti (not documented)
- Keeper (not documented)
- Tailscale (not documented)
- Veracode (not documented)
- GitGuardian (not documented)
- Semgrep (not documented)
- Clerk (not documented)
- WorkOS (not documented)
Know a vendor we're missing?