generated: '2026-07-25' method: searched probe: true source: >- https://www.nokia.com/we-are-nokia/security/ and https://www.nokia.com/we-are-nokia/security/compliance/ (both HTTP 200). summary: >- There is no Network as Code trust centre - no trust.networkascode.nokia.io, no product compliance page, no SOC 2 report request flow, and nothing about subprocessors or data residency for the platform beyond the supplemental privacy notice. What exists is Nokia's corporate security section, which is substantive and organised into named areas (trusted performance, product security, service security, cybersecurity, supply chain security, security compliance) and does name a real certification and a real regulatory programme. Read it as parent-company assurance, not product attestation. url: https://www.nokia.com/we-are-nokia/security/ sections: - {name: Security home, url: 'https://www.nokia.com/we-are-nokia/security/'} - {name: Product security, url: 'https://www.nokia.com/we-are-nokia/security/products/'} - {name: Security compliance, url: 'https://www.nokia.com/we-are-nokia/security/compliance/'} - {name: Coordinated Vulnerability Disclosure, url: 'https://www.nokia.com/we-are-nokia/security/products/cvd/'} - {name: Product security advisories, url: 'https://www.nokia.com/we-are-nokia/security/product-security-advisory/'} - {name: Vulnerability management, url: 'https://www.nokia.com/we-are-nokia/security/vulnerability-management/'} certifications: - ISO/IEC 27001:2022 regulatory_programs: - {name: EU Cyber Resilience Act, note: 'Dedicated CRA compliance programme launched 2024 covering product design, testing, documentation and supply chain; Nokia is active in CRA standardisation.'} - {name: NIS 2 Directive, note: 'Expanded cybersecurity obligations across managed services and manufacturing.'} - {name: Radio Equipment Directive 2014/53/EU, note: 'Product safety, EMC and spectrum efficiency.'} - {name: U.S. National Security Agreement, note: 'Specialised agreement with the U.S. Government applying controls to network access and product integrity.'} process: DFSEC (Design for Security) - country-specific product regulation requirements are embedded in this process. not_found: - {claim: 'SOC 2', note: 'Not named on any Nokia security page found.'} - {claim: 'PCI DSS', note: 'Not named.'} - {claim: 'HIPAA', note: 'Not named.'} - {claim: 'FedRAMP', note: 'Not named.'} - {claim: 'Product-scoped trust centre for Network as Code', note: 'trust.networkascode.nokia.io does not exist; networkascode.nokia.io publishes terms of service and a supplemental privacy notice only.'} product_legal: terms_of_service: https://networkascode.nokia.io/legal/terms-of-service privacy: https://networkascode.nokia.io/legal/supplemental-privacy-notice corporate_privacy: https://www.nokia.com/notices/privacy/ evidence: - {source: 'https://www.nokia.com/we-are-nokia/security/compliance/', keywords: ['ISO/IEC 27001:2022', 'EU Cyber Resilience Act', 'NIS 2', 'Radio Equipment Directive', 'regulatory compliance management framework'], status: 200} - {source: 'https://www.nokia.com/we-are-nokia/security/', status: 200}