PCI DSS-Compliant Security Vendors
Security vendors that hold PCI DSS certification
Okta
21/32Identity and access management platform providing secure authentication, authorization, and single sign-on for enterprises.
PCI DSS v4.0.0
CrowdStrike
17/32Cloud-native endpoint protection platform providing threat intelligence, incident response, and cybersecurity solutions.
PCI DSS v4.0.1
Zscaler
14/32Cloud-native zero trust security platform (ZIA/ZPA) for secure internet and application access.
Wiz
13/32Cloud-native application protection platform (CNAPP) for cloud security.
v4.0.1
Splunk
11/32Data platform for security, observability, and IT operations (SIEM, log analytics), owned by Cisco.
Level 1 PCI service provider
Palo Alto Networks
10/32Cybersecurity platform spanning network security, cloud security, and SOC automation.
Proofpoint
10/32Email security, threat protection, and data loss prevention platform.
Proofpoint Archive product
Orca Security
10/32Agentless cloud security platform (CNAPP) for cloud workload and configuration risk.
v4.0.1
1Password
9/32Password manager and secure digital wallet that stores passwords, documents, and sensitive information with end-to-end encryption.
PCI DSS materials available in trust center
Keeper
9/32Password management and privileged access security platform.
SentinelOne
8/32AI-powered endpoint, cloud, and identity security (XDR) platform.
PCI-DSS whitepaper referenced, not a formal certification listing
Auth0
8/32Identity and access management (authentication-as-a-service) platform, owned by Okta.
Compliant deployment models offered
Varonis
8/32Data security platform for data classification, access governance, and threat detection.
Snyk
7/32Developer security platform for finding and fixing vulnerabilities in code, containers, and cloud infrastructure.
PCI DSS SAQ-A
Trend Micro
6/32Cybersecurity platform for endpoint, cloud, and network security.
Trend Vision One certified PCI DSS service provider
McAfee
5/32Consumer and enterprise antivirus, identity, and online privacy protection platform.
v3.2.1
Cisco Duo
1/32Multi-factor authentication (MFA) and zero-trust access security platform from Cisco.
Supports PCI-DSS 4.0 MFA requirements (Section 8.3); not itself a PCI DSS certification
Qualys
0/32Cloud-based vulnerability management and IT security/compliance platform.
Qualys offers PCI compliance scanning as a product; own certification status unclear from this pass
These security vendors do not currently hold PCI DSS certification:
- Fortinet (not documented)
- Check Point (not documented)
- Rapid7 (not documented)
- Tenable (not documented)
- Mimecast (not documented)
- KnowBe4 (not documented)
- OneLogin (not documented)
- Ping Identity (not documented)
- JumpCloud (not documented)
- LastPass (not documented)
- Dashlane (not documented)
- Bitwarden (not documented)
- Lacework (not documented)
- Netskope (not documented)
- Darktrace (not documented)
- Cybereason (not documented)
- VMware Carbon Black (not documented)
- Symantec (not documented)
- Sophos (not documented)
- Bitdefender (not documented)
- ESET (not documented)
- Malwarebytes (not documented)
- Keeper Security (not documented)
- Ivanti (not documented)
- Tailscale (not documented)
- Checkmarx (not documented)
- Veracode (not documented)
- GitGuardian (not documented)
- Semgrep (not documented)
- Clerk (not documented)
- WorkOS (not documented)
Know a vendor we're missing?