What Security and Compliance Certifications Does Passbolt Have?
Passbolt publicly lists four verifiable security and compliance credentials: a SOC 2 Type II audit report, GDPR compliance, European manufacturing, and membership in the FIDO Alliance. It is also in the ANSSI CSPN certification process, which means that certification is pending rather than completed. These claims matter most to IT and security teams evaluating a credential platform for regulated or sovereignty-sensitive environments.
The Credentials Passbolt States
| Credential | Status | What it signals |
|---|---|---|
| SOC 2 Type II | Audited, report available | Independent verification that controls operated effectively over an audit period |
| GDPR | Compliant | Alignment with EU data protection requirements |
| Made in Europe | Stated | European development and hosting posture |
| FIDO Alliance | Member | Participation in the standards body behind phishing-resistant authentication |
| ANSSI CSPN | In certification process | French national security certification is being pursued, not yet granted |
Why Each One Matters
SOC 2 Type II
A Type II report goes beyond a point-in-time snapshot: an independent auditor tests whether security controls actually functioned across a defined period. For buyers, this is often the single most useful document because it can be requested and reviewed directly rather than taken on trust. If your procurement or security review requires third-party assurance, this is the artifact to ask for.
GDPR Compliance
GDPR matters when personal data of EU residents is involved. For teams handling employee or customer credentials, a GDPR-compliant vendor simplifies the data protection assessment. Note that "compliant" is a vendor statement; the specifics of data processing, hosting location, and subprocessors should be confirmed in the vendor's documentation during your own review.
Made in Europe
European origin is relevant for organisations with data sovereignty requirements — particularly public sector, defence, and regulated industries that prefer infrastructure and development outside non-EU jurisdictions. Passbolt's customer list includes European government bodies and universities, which is consistent with this positioning.
FIDO Alliance Membership
FIDO Alliance membership indicates engagement with the standards community behind modern, phishing-resistant authentication. For teams planning to move beyond passwords toward hardware security keys or passkeys, this is a signal of direction rather than a guarantee of specific features — verify the exact authentication methods supported before committing.
ANSSI CSPN — In Progress
The ANSSI CSPN (Centre de Sécurité des Produits et Systèmes) certification is issued by the French national cybersecurity agency. Passbolt states it has entered the certification process. Treat this as pending: it is not yet a completed certification, and you should not represent it as one in your own compliance documentation. If French or EU government certification is a hard requirement, confirm the current status directly with the vendor before relying on it.
How to Verify These Claims Yourself
- Request the SOC 2 Type II report. Vendors typically provide it under NDA. Review the audit period, the trust services criteria covered, and any exceptions noted.
- Check the certification status directly. For ANSSI CSPN, ask for the current stage and expected timeline rather than assuming completion.
- Confirm GDPR specifics. Ask where data is hosted, who the subprocessors are, and whether a Data Processing Agreement is available.
- Match credentials to your own requirements. A SOC 2 Type II report satisfies many enterprise reviews; a government or defence buyer may additionally need ANSSI CSPN or equivalent national certification.
Choosing Based on Your Compliance Needs
- If you need independent third-party assurance: SOC 2 Type II is the credential to prioritise, and the report is reviewable.
- If you handle EU personal data: GDPR compliance plus European hosting reduces assessment friction.
- If you have sovereignty or public-sector requirements: "Made in Europe" and the European customer references are relevant, but confirm hosting and jurisdiction details.
- If French national certification is mandatory: ANSSI CSPN is still in process — verify status before treating it as satisfied.
- If you are standardising on phishing-resistant authentication: FIDO Alliance membership signals alignment, but validate the specific supported methods.
The practical takeaway: Passbolt's compliance story rests on one completed independent audit (SOC 2 Type II), a GDPR compliance statement, a European origin claim, and FIDO Alliance membership — with ANSSI CSPN explicitly in progress. For most enterprise security reviews, the SOC 2 Type II report is the document that does the heavy lifting; the remaining credentials support sovereignty and standards-alignment arguments. Confirm anything your own compliance framework treats as mandatory directly with the vendor.