generated: '2026-06-20' method: searched probe: true source: >- https://access.redhat.com/security/rh-compliance-certifications-attestations, https://www.redhat.com/en/solutions/compliance-approach, https://www.redhat.com/en/trust, https://access.redhat.com/compliance/soc-2-type-2 url: https://www.redhat.com/en/trust description: >- Red Hat publishes its compliance posture through the Red Hat Trust portal (redhat.com/en/trust) and the Customer Portal compliance certifications and attestations page. Managed-services and product certifications are tracked separately; the certifications below are named in Red Hat's public compliance materials. certifications: - SOC 2 Type 2 - SOC 3 - ISO 27001 - ISO 27017 - ISO 27018 - PCI DSS 4.0 - FIPS 140-2 - FIPS 140-3 - Common Criteria - FedRAMP High evidence: - source: https://access.redhat.com/security/rh-compliance-certifications-attestations keywords: [soc 2 type 2, iso 27001, iso 27017, iso 27018, pci dss, compliance, attestations] - source: https://access.redhat.com/compliance/soc-2-type-2 keywords: [soc 2 type 2] - source: https://www.redhat.com/en/blog/red-hat-enterprise-linux-common-criteria-and-fips-certificates keywords: [common criteria, fips 140-2, fips 140-3] notes: >- FedRAMP High applies to Red Hat OpenShift Service on AWS (ROSA). FIPS 140-3 cryptographic module validation was completed on RHEL 9.0/9.2 (OpenSSL, GnuTLS, Kernel Crypto API). Scope of each certification varies by product / managed service — see the Customer Portal compliance pages for the authoritative per-offering matrix.