Google Cloud Platform Services in Scope by Compliance Program

Last modified: April 4, 2025 | Previous Versions

Capitalized terms have the meaning stated in the applicable agreement between Customer or Partner and Google.

The following Services fall within the scope of one or more of: Google's ISO 27001 Certification, ISO 27017 Certification, ISO 27018 Certification, PCI DSS Certification, SOC 1 Report, SOC 2 Report and SOC 3 Report and Penetration Testing Report. A done in the table below indicates that the Service (row) is in scope for the specified certification or report (column).

Service ISO 27001, 27017, 27018 Certifications SOC 1, 2, 3 Reports PCI DSS Certification Penetration Testing
Access Approval done done done done
Access Context Manager done done done done
Access Transparency done done done done
Agent Assist done done done
AI Platform Data Labeling done done done done
AI Platform Neural Architecture Search (NAS) done done done
AI Platform Training and Prediction done done done done
AlloyDB done done done
Anthos Identity Service (AIS) done done done
Anthos on AWS done (ISO 27001 only)
Anthos on Azure done (ISO 27001 only)
Anti-Money Laundering AI done (ISO 27001 only) done
API Gateway done done done done
Apigee done done done done
App Engine done done done done
Artifact Registry done done done done
Assured Workloads for Government done done done done
AutoML Natural Language done done done done
AutoML Tables done done done done
AutoML Translation done done done done
AutoML Video done done done done
AutoML Vision done done done done
Backup for GKE done done done
Bare Metal Solution done done done done
Batch done done done done
BeyondCorp Enterprise done done done done
BigQuery done done done done
BigQuery Data Transfer Service done done done done
Bigtable done done done done
Binary Authorization done done done done
Certificate Authority Service done done done done
Cloud Asset Inventory done done done done
Cloud Billing done done done done
Cloud Build done done done done
Cloud CDN done done done done
Cloud Composer done done done done
Cloud Console done done done done
Cloud Console App done done done done
Cloud Data Fusion done done done done
Cloud Deployment Manager done done done done
Cloud DNS done done done done
Cloud Endpoints done done done done
Cloud External Key Manager (Cloud EKM) done done done done
Cloud Filestore done done done done
Cloud Firewall done (ISO 27001 only) done done
Cloud Functions done done done done
Cloud Functions for Firebase done done done done
Cloud Healthcare done done done done
Cloud HSM done done done done
Cloud IDS done done done done
Cloud Interconnect done done done done
Cloud Key Management Service done done done done
Cloud Life Sciences done done done done
Cloud Load Balancing done done done done
Cloud Logging done done done done
Cloud Monitoring done done done done
Cloud NAT (Network Address Translation) done done done done
Cloud Natural Language API done done done done
Cloud Profiler done done done done
Cloud Router done done done done
Cloud Run done done done done
Cloud Run for Anthos done done done done
Cloud Scheduler done done done done
Cloud SDK done done done done
Cloud Shell done done done done
Cloud Source Repositories done done done done
Cloud Speaker ID done done done done
Cloud SQL done done done done
Cloud Storage done done done done
Cloud Storage for Firebase done done done done
Cloud Tasks done done done done
Cloud Trace done done done done
Cloud Translation done done done done
Cloud Vision done done done done
Cloud VPN done done done done
Cloud Workstations done (ISO 27001 only) done done done
Compute Engine done done done done
Config Management done done done done
Connect done done done done
Contact Center AI done done done done
Container Registry done done done done
Cyber Insurance Hub done done done done
Data Catalog done done done done
Database Migration Service done done done done
Dataflow done done done done
Dataform done (ISO 27001 only) done done done
Dataplex done done done done
Dataproc done done done done
Dataproc Metastore done done done
Datastore done done done done
DataStream done done done done
Dialogflow done done done done
Discovery Solutions done done
Document AI done done done done
Document AI Warehouse done done done done
Earth Engine done (ISO 27001 only) done done
Eventarc done done done done
Firebase App Check done (ISO 27001 only) done done
Firebase Authentication done done done done
Firebase Test Lab done done done
Firestore done done done done
GCVE done done done
Gemini for Google Cloud done done
Generative AI on Vertex AI (formerly Generative AI support on Vertex AI) done done
Google Cloud Armor done done done done
Google Cloud Deploy done done done done
Google Cloud Identity-Aware Proxy done done done done
Google Cloud Marketplace done done done done
Google Distributed Cloud Edge done (ISO 27001 only) done (SOC 2 only) done
Google Kubernetes Engine done done done done
Healthcare Data Engine (HDE) done done done
Hub done done done done
Identity & Access Management (IAM) done done done done
Identity Platform done done done done
Insights done done done done
IoT Core done done done done
Key Access Justification (Access Sovereignty) done done done done
Looker (Google Cloud core) done done done done
Looker Studio done done done done
Managed Service for Microsoft Active Directory (AD) done done done done
Memorystore done done done done
Migrate to Virtual Machines done done
Migration Center done done done
Network Connectivity Center done done done
Network Intelligence Center done done done done
Network Service Tiers done done done done
Persistent Disk done done done done
Pub/Sub done done done done
reCAPTCHA Enterprise done done done done
Recommendations AI done done
Recommenders done done done done
Resource Manager API done done done done
Retail Search done done
Secret Manager done done done done
Security Command Center done done done done
Sensitive Data Protection done done done done
Service Directory done done done done
Service Infrastructure done done done done
Spanner done done done done
Spectrum Access System done done done
Speech-to-Text done done done done
Storage Transfer Service done done done done
Tables done(ISO 27001 only) done
Talent Solution done done done done
Text-to-Speech done done done done
Traffic Director done done done done
Transcoder API done done
Transfer Appliance done(ISO 27001 only) done done
Vertex AI Conversation (formerly Generative AI App Builder) done done
Vertex AI Platform (formerly Vertex AI) done done done done
Vertex AI Search (formerly Gen App Builder – Enterprise Search) done done done
Video Intelligence API done done done done
Virtual Private Cloud done done done done
VirusTotal done(ISO 27001 only) done done
VPC Service Controls done done done done
Web Risk API done done done done
Workflows done done done done
Workload Manager done done done
BigQuery Omni done done done done
Media CDN done (ISO 27001 only) done
Anthos Clusters on Bare Metal done
Anthos Clusters on VMware done
Anthos Identity Service – Software done(ISO 27001 only)
Binary Authorization – Software done(ISO 27001 only)
Cloud Logging – Software done(ISO 27001 only)
Cloud Monitoring – Software done(ISO 27001 only)
Cloud Run for Anthos – Software done(ISO 27001 only)
Config Management – Software done(ISO 27001 only)
Connect – Software done(ISO 27001 only)
Migrate to Containers done
Service Mesh – Software done(ISO 27001 only)


Google Workspace and Cloud Identity Services in Scope by Compliance Program

Capitalized terms have the meaning stated in the applicable agreement between Customer and Google.

The following Services fall within the scope of one or more of: Google's ISO 27001 Certification, ISO 27017 Certification, ISO 27018 Certification, SOC 1 Report, SOC 2 Report and SOC 3 Report and Penetration Testing Report. A done in the table below indicates that the Service (row) is in scope for the specified certification or report (column).

Service ISO 27001, 27017, 27018 Certifications SOC 1, 2, 3 Reports Penetration Testing
Admin Console done done done
Alert Center API done(ISO 27001 only) done done
Apps Email Audit API done(ISO 27001 only) done done
Apps Script done(ISO 27001 only) done done
AppSheet done done (SOC 2/3 only) done
Assignments done done done
Calendar done done done
Calendar API done(ISO 27001 only) done done
Classroom done done done
Cloud Identity done done done
Cloud Search done done done
Contacts done done done
Data Transfer API done(ISO 27001 only) done done
Directory API done(ISO 27001 only) done done
Docs done done done
Domain Shared Contacts API done(ISO 27001 only) done done
Drive done done done
Drive Activity API done(ISO 27001 only) done done
Drive Rest API done(ISO 27001 only) done
Enterprise License Manager done(ISO 27001 only) done
Forms done done done
Gmail done done done
Gmail Rest API done(ISO 27001 only) done
Google Chat done done done
Google Meet done done done
Google Workspace Migrate done done done
Groups done done done
Groups Migration API done(ISO 27001 only) done done
Groups Settings API done(ISO 27001 only) done done
Keep done done done
Mobile Device Management done done done
People API done(ISO 27001 only) done
Reports API done(ISO 27001 only) done done
Reseller API done(ISO 27001 only) done done
SAML-based SSO API done(ISO 27001 only) done done
Service Mesh done done done
Sheets done done done
Sheets API done(ISO 27001 only) done
Sites done done done
Slides done done done
Tasks done done done
Tasks API done(ISO 27001 only) done
Vault done done done
Voice done done done


Other Services in Scope by Compliance Program

Capitalized terms have the meaning stated in the applicable agreement between Customer or Partner and Google.

These Services fall within the scope of one or more of: Google's ISO 27001 Certification, ISO 27017 Certification, ISO 27018 Certification, SOC 1 Report, SOC 2 Report and SOC 3 Report and Penetration Testing Report. A done in the table below indicates that the Service (row) is in scope for the specified certification or report (column).

Service ISO 27001, 27017, 27018 Certifications SOC 1, 2, 3 Reports Penetration Testing
Looker (original) done done done

Previous Versions

Morty Proxy This is a proxified and sanitized view of the page, visit original site.