White Paper | Align with Compliance Requirements with SASE

White Paper | Align with Compliance Requirements with SASE

See our certifications and how Check Point SASE supports your compliance work — ISO, SOC 2, GDPR, HIPAA, NIS 2, CIS, and more.

White Paper | Align with Compliance Requirements with SASE

How Check Point SASE Helps You Align with Key Compliance Requirements  Certifications and attestations, and the frameworks

Check Point SASE helps you address

How Check Point SASE Helps You Align

with Key Compliance Requirements

Certifications and attestations, and the frameworks Check Point SASE helps you address

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 02

Executive Summary

Check Point SASE is designed with security and compliance support capabilities at its core. We maintain rigorous certifications that demonstrate the security of our platform, and we deliver capabilities that help organizations align with a wide range of compliance frameworks.

From global privacy regulations to healthcare mandates and industry best practices, Check Point SASE helps organizations strengthen their compliance efforts through advanced security controls, deep visibility, and secure access.

This overview is organized in two parts. First, the standards Check Point is independently certified or attested against. Second, the frameworks where Check Point SASE provides technical capabilities that support your own compliance work. A capability summary and a reference diagram tie the two together.

Where Check Point SASE helps most

Identity and access

Zero Trust access, identity provider integration, role-based access control (RBAC), and multi-factor authentication (MFA)

Encryption in transit

Traffic secured with modern protocols, including TLS, IPSec, and WireGuard

Logging and auditability

Centralized event logging and continuous access audits for investigation and reporting

Segmentation

Application-level access control that limits lateral movement and shrinks the attack surface

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 02

Executive Summary

Check Point SASE is designed with security and compliance support capabilities at its core. We maintain rigorous certifications that demonstrate the security of our platform, and we deliver

capabilities that help organizations align with a wide range of compliance frameworks. From global privacy regulations to healthcare mandates and industry best practices, Check Point

SASE helps organizations

strengthen their compliance efforts through advanced security controls, deep visibility, and secure access.

This overview is organized in two parts. First, the standards Check Point is independently certified or attested against. Second, the frameworks

where Check Point SASE provides technical capabilities that support your own compliance work. A capability summary and a reference diagram tie the

two together.

Where Check Point SASE helps most

Identity and access

Zero Trust access, identity provider

integration, role-based access control (RBAC), and multi-factor authentication

(MFA)

Encryption in transit

Traffic secured with modern protocols, including TLS, IPSec, and WireGuard

Logging and auditability

Centralized event logging and continuous

access audits for investigation and

reporting

Segmentation

Application-level access control that limits lateral movement and shrinks the

attack surface

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 03

Our Certifications

Check Point SASE, as part of Check Point, is certified or attested against the following standards, validating the security and reliability of our platform.

ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032

ISO/IEC 27036 ISO/IEC 27701 SOC 2 Type II

CISA Secure by Design Pledge (signatory commitment)

C5 — Cloud Computing Compliance Controls Catalogue (BSI, Germany)

IRAP — Infosec Registered Assessors Program (Australia)

These certifications provide assurance that our systems, processes, and controls meet stringent industry requirements, including information security management, cloud security, privacy protection, and cyber resilience.

Supporting Your Compliance Efforts

In addition to our own certifications, Check Point SASE provides capabilities that may assist organizations in supporting alignment with key compliance frameworks by delivering essential security capabilities. Support depends on configuration and use, but the essential security building blocks are the same across frameworks.

Frameworks where Check Point SASE supports customer compliance

HIPAA Security Rule HIPAA Security Rule

Technical safeguards that support the protection of electronic protected health information

Access control, data protection, and activity logging for personal data

CIS Critical Security Controls  HIPAA Security Rule

Capabilities that help address more than 35 CIS Safeguards across multiple controls

Risk management, incident detection and reporting, and operational resilience

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 03

Our Certifications

Check Point SASE, as part of Check Point, is certified or attested against the following

standards, validating the security and reliability of our platform.

ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032

ISO/IEC 27036 ISO/IEC 27701 SOC 2 Type II

CISA Secure by Design Pledge (signatory commitment)

C5 — Cloud Computing Compliance Controls Catalogue (BSI, Germany)

IRAP — Infosec Registered Assessors Program (Australia)

These certifications provide assurance that our systems, processes, and controls meet stringent

industry requirements, including information security management, cloud security, privacy protection, and cyber resilience.

Supporting Your Compliance Efforts

In addition to our own certifications, Check Point SASE provides capabilities that may assist organizations in supporting alignment with key compliance frameworks by delivering essential security capabilities. Support depends on configuration and use, but the essential security building blocks are the same across frameworks.

Frameworks where Check Point SASE supports customer compliance

HIPAA Security Rule

Technical safeguards that support

the protection of electronic protected health information

HIPAA Security Rule

Access control, data protection,

and activity logging for personal data

CIS Critical Security Controls

Capabilities that help address

more than 35 CIS Safeguards

across multiple controls

HIPAA Security Rule

Risk management, incident

detection and reporting, and

operational resilience

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 04

Compliance at a Glance

Check Point SASE helps organizations address common security requirements found across major compliance and industry frameworks — including identity and access management, encryption, logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.

Customer

requirement

What it means for

you

How Check Point

SASE helps

Frameworks

commonly

addressed

Identity and

access

management

Control who can

reach apps and data;

enforce least privilege

ZTNA, identity provider

integration, RBAC,

MFA

ISO 27001, NIS 2,

SOC 2, CIS, HIPAA

Encryption in

transit

Protect sensitive data

as it moves across

networks

TLS, IPSec, and

WireGuard encrypted

tunnels

GDPR, HIPAA, ISO

27001, NIS 2

Network

segmentation

Limit lateral

movement and reduce

attack surface

ZTNA and application-

level access control

ISO 27001, CIS, C5

Logging and

auditability

Enable audits,

investigations, and

compliance reporting

Centralized logging

and SIEM integration

SOC 2, ISO 27001,

HIPAA, GDPR, NIS 2

Device trust and

session control

Ensure only compliant

devices keep access

Device posture checks

and session

termination

CIS, ISO 27001

(indirect)

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 04

Compliance at a Glance

Check Point SASE helps organizations address common security requirements found across major

compliance and industry frameworks — including identity and access management, encryption,

logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.

Customer

requirement What it means for

you

How Check Point

SASE helps Frameworks

commonly addressed

Identity and access

management

Control who can

reach apps and data; enforce least privilege

ZTNA, identity provider integration, RBAC, MFA

ISO 27001, NIS 2,

SOC 2, CIS, HIPAA

Encryption in transit

Protect sensitive data

as it moves across

networks

TLS, IPSec, and

WireGuard encrypted tunnels

GDPR, HIPAA, ISO

27001, NIS 2

Network

segmentation

Limit lateral

movement and reduce

attack surface

ZTNA and application- level access control

ISO 27001, CIS, C5

Logging and auditability

Enable audits,

investigations, and compliance reporting

Centralized logging and SIEM integration

SOC 2, ISO 27001,

HIPAA, GDPR, NIS 2

Device trust and

session control Ensure only compliant devices keep access

Device posture checks and session

termination

CIS, ISO 27001 (indirect)

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 05

Certifications and Attestations

ISO/IEC 27001 and Related Certifications

Check Point SASE helps organizations address common security requirements found across major compliance and industry frameworks — including identity and access management, encryption, logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.

Our certifications

Check Point, including Check Point SASE, is certified for ISO/IEC 27001, along with related standards ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27032, and ISO/IEC 27701. Together they cover information security, privacy management, cloud security, and cyber resilience.

ISO/IEC 27001 — Information Security Management System (ISMS)

ISO/IEC 27017 — cloud security best practices

ISO/IEC 27018 — protection of personally identifiable information (PII) in public clouds

ISO/IEC 27032 — guidelines for internet security

ISO/IEC 27701 — Privacy Information Management System (PIMS)

Customer support

Organizations pursuing ISO/IEC 27001 compliance can leverage Check Point SASE capabilities that deliver essential controls related to:

Network security, access management, threat protection, and data encryption

Protection of personal data in cloud environments (ISO 27018, ISO 27701)

Cyber resilience measures for detecting, responding, and recovering from cyber incidents (ISO 27032)

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 05

Certifications and Attestations

ISO/IEC 27001 and Related Certifications

Check Point SASE helps organizations address common security requirements found across major

compliance and industry frameworks — including identity and access management, encryption,

logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.

Our certifications

Check Point, including Check Point SASE, is certified for ISO/IEC 27001, along with related standards ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27032, and ISO/IEC 27701. Together they cover information

security, privacy management, cloud security, and cyber resilience.

ISO/IEC 27001 — Information Security Management System (ISMS)

ISO/IEC 27017— cloud security best practices

ISO/IEC 27018— protection of personally identifiable information (PII) in public clouds

ISO/IEC 27032— guidelines for internet security

ISO/IEC 27701 — Privacy Information Management System (PIMS)

Customer support

Organizations pursuing ISO/IEC 27001 compliance can leverage Check Point SASE capabilities that deliver essential controls related to:

Network security, access

management, threat protection, and data encryption

Protection of personal data in cloud environments (ISO 27018,

ISO 27701)

Cyber resilience measures for detecting, responding, and recovering from cyber incidents (ISO 27032)

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 06

Our platform contributes to ISO compliance by:

Controlling access to applications and data via Zero Trust principles

Enforcing encryption for data in transit through secure tunnels (IPSec, WireGuard)

Logging access and policy changes for auditing

Segmenting networks and restricting access based on user roles

Supporting privacy management best practices for protecting PII in cloud services

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 06

Our platform contributes to ISO compliance by:

Controlling access to

applications and data via Zero

Trust principles

Enforcing encryption for data in

transit through secure tunnels (IPSec, WireGuard)

Logging access and policy

changes for auditing

Segmenting networks and

restricting access based on user roles

Supporting privacy management best practices for protecting PII in cloud services

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 07

SOC 2 Type II

Our certifications

Check Point is certified for SOC 2 Type II, meaning our systems and processes have been independently audited for how effectively they secure customer data over time. The certification covers the Security, Availability, and Confidentiality trust services criteria, based on the AICPA Trust Services Criteria.

How we support your SOC 2 obligations

Prevent unauthorized access  Monitor network activity

Ensure high availability and resilience

Protect sensitive customer data throughout the service lifecycle

How the audit scope works

Check Point SASE uses cloud infrastructure providers whose controls are covered by their own independent compliance certifications (for example, SOC 2 and ISO 27001). These providers were treated as subservice organizations during our audit. Our SOC 2 certification focuses solely on the controls directly managed by Check Point.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 07

SOC 2 Type II

Our certifications

Check Point is certified for SOC 2 Type II, meaning our systems and processes have been

independently audited for how effectively they secure customer data over time. The certification

covers the Security, Availability, and Confidentiality trust services criteria, based on the AICPA Trust Services Criteria.

How we support your SOC 2 obligations

Prevent unauthorized access Monitor network activity

Ensure high availability and resilience

Protect sensitive customer data

throughout the service lifecycle

How the audit scope works

Check Point SASE uses cloud infrastructure providers whose controls are covered by their own

independent compliance certifications (for example, SOC 2 and ISO 27001). These providers

were treated as subservice organizations during our audit. Our SOC 2 certification focuses

solely on the controls directly managed by Check Point.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 08

C5 — Cloud Computing Compliance Controls Catalogue 
 (BSI, Germany)

Our attestation

Check Point, including the Check Point SASE management environment via the Check Point Portal, is attested by an independent auditor against the Cloud Computing Compliance Criteria Catalogue (C5:2020) issued by the German Federal Office for Information Security (BSI).

C5 defines comprehensive baseline security criteria for cloud service providers and is widely recognized in Germany and across the EU. Check Point SASE supports customer compliance with key C5 requirements through controls in these core areas:

Identity and access management
 Zero Trust access, role-based access control, and robust authentication

Data transport security 
 Traffic between users, gateways, and systems encrypted with TLS, IPSec, and WireGuard

Logging
 Centralized event logging and continuous access audits for traceability

Separation of environments 
 Strict isolation of production from development and testing systems

Business continuity 
 Cloud-native resiliency measures and geographic redundancy

These controls position Check Point SASE well for regulated entities that need trusted, compliant cloud solutions across Germany and the broader EU.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 08

C5 — Cloud Computing Compliance Controls Catalogue

(BSI, Germany)

Our attestation

Check Point, including the Check Point SASE management environment via the Check Point Portal, is

attested by an independent auditor against the Cloud Computing Compliance Criteria Catalogue

(C5:2020) issued by the German Federal Office for Information Security (BSI).

C5 defines comprehensive baseline security criteria for cloud service providers and is widely recognized in Germany and across the EU. Check Point SASE supports customer compliance with

key C5 requirements through controls in these core areas:

Identity and access management

Zero Trust access, role-based access control, and robust authentication

Data transport security

Traffic between users, gateways,

and systems encrypted with TLS, IPSec, and WireGuard

Logging

Centralized event logging and continuous access audits for

traceability

Separation of environments

Strict isolation of production from development

and testing systems

Business continuity

Cloud-native resiliency measures and geographic redundancy

These controls position Check Point SASE well for regulated entities that need trusted, compliant cloud solutions across Germany and the broader EU.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 09

CISA Secure by Design Pledge

Our commitment

Check Point is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Secure by Design pledge. The initiative calls on technology providers to design and deliver products that are secure by default and resilient against modern threats.

What Check Point SASE commits to

Embed security features in the core design of the platform

Enable multi-factor authentication by default

Reduce default attack surfaces across our infrastructure

Offer transparency and accountability around secure development practices

This commitment reflects our broader mission: helping customers not only achieve compliance, but maintain a strong security posture by design.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 09

CISA Secure by Design Pledge

Our commitment

Check Point is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Secure

by Design pledge. The initiative calls on technology providers to design and deliver products that are

secure by default and resilient against modern threats.

What Check Point SASE commits to

Embed security features in the

core design of the platform

Enable multi-factor

authentication by default

Reduce default attack surfaces

across our infrastructure

Offer transparency and

accountability around secure

development practices

This commitment reflects our broader mission: helping customers not only achieve compliance, but maintain a strong security posture by design.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 10

IRAP — Australia

Our assessment

The Australian Signals Directorate’s Infosec Registered Assessors Program (IRAP) provides a framework for independent assessment of ICT and cloud services against the Australian Government Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF). Check Point has completed an IRAP assessment of selected cloud services that underpin Check Point SASE, with particular emphasis on the core cloud infrastructure and Check Point SASE Private Access capabilities.

The resulting IRAP report provides independent assurance about the implementation and effectiveness of security controls within the defined scope at the time of the assessment.

Customer support

For Australian Government agencies and regulated organizations handling Australian Government information, Check Point SASE and its IRAP-assessed cloud environment can be used as part of the evidence base when customers independently demonstrate alignment with the ISM and PSPF for outsourced ICT and cloud services (including OFFICIAL, OFFICIAL: Sensitive and PROTECTED information). 
 In particular, Check Point SASE helps support:

Network and infrastructure security controls  - Zero Trust access to applications, network segmentation, and secure remote connectivity

Encryption of data in transit - Use of secure tunnels and modern cryptographic protocols

Identity and access management Integration with enterprise identity providers, strong authentication (including MFA), and role-based access controls

Logging, monitoring, and auditability - Centralized logging of administrative and access activity, SIEM integration, and security event visibility

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 10

IRAP — Australia

Our assessment

The Australian Signals Directorate’s Infosec Registered Assessors Program (IRAP) provides a

framework for independent assessment of ICT and cloud services against the Australian Government

Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF). Check Point

has completed an IRAP assessment of selected cloud services that underpin Check Point SASE, with

particular emphasis on the core cloud infrastructure and Check Point SASE Private Access capabilities.

The resulting IRAP report provides independent assurance about the implementation and

effectiveness of security controls within the defined scope at the time of the assessment.

Customer support

For Australian Government agencies and regulated organizations handling Australian Government

information, Check Point SASE and its IRAP-assessed cloud environment can be used as part of the evidence base when customers independently demonstrate alignment with the ISM and PSPF

for outsourced ICT and cloud services (including OFFICIAL, OFFICIAL: Sensitive and PROTECTED information).

In particular, Check Point SASE helps support:

Network and infrastructure

security controls - Zero Trust

access to applications, network

segmentation, and secure

remote connectivity

Encryption of data in transit - Use of secure tunnels

and modern cryptographic protocols

Identity and access management

Integration with enterprise

identity providers, strong authentication (including MFA), and role-based access controls

Logging, monitoring, and

auditability - Centralized logging of administrative and access

activity, SIEM integration, and

security event visibility

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 11

Frameworks We Help You Address

HIPAA Security Rule

Customer support only

Check Point SASE itself is not audited for HIPAA compliance but provides technical capabilities that may support U.S. healthcare organizations in addressing certain HIPAA Security Rule technical safeguards, which govern the protection of electronic protected health information (ePHI).

According to the U.S. Department of Health and Human Services, covered entities must:

Ensure the confidentiality, integrity, and availability of ePHI

Protect against reasonably anticipated threats to ePHI

Guard against impermissible uses or disclosures

Ensure workforce compliance

Check Point SASE provides capabilities that may be used to support these requirements by:

Enabling least-privilege access to sensitive applications and data

Encrypting ePHI in transit across secure tunnels

Logging access and changes for audit and investigation

Providing centralized management and policy enforcement

As noted in our HIPAA checklist white paper, Check Point SASE supports core technical safeguards, including access control, integrity controls, audit controls, and transmission security, making it a solution that may support organizations working toward HIPAA compliance.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 11

Frameworks We Help You Address

HIPAA Security Rule

Customer support only

Check Point SASE itself is not audited for HIPAA compliance but provides technical capabilities that

may support U.S. healthcare organizations in addressing certain HIPAA Security Rule technical

safeguards, which govern the protection of electronic protected health information (ePHI).

According to the U.S. Department of Health and Human Services, covered entities must:

Ensure the confidentiality,

integrity, and availability of ePHI

Protect against reasonably

anticipated threats to ePHI

Guard against impermissible uses or disclosures Ensure workforce compliance

Check Point SASE provides capabilities that may be used to support these requirements by:

Enabling least-privilege access to

sensitive applications and data

Encrypting ePHI in transit across secure tunnels

Logging access and changes for

audit and investigation

Providing centralized management

and policy enforcement

As noted in our HIPAA checklist white paper, Check Point SASE supports core technical safeguards,

including access control, integrity controls, audit controls, and transmission security, making it a solution that may support organizations working toward HIPAA compliance.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 12

GDPR

Customer support only

Check Point SASE provides capabilities that can support organizations in meeting certain GDPR obligations — depending on configuration and use — through strong access controls, data protection mechanisms, and activity logging.

Among other things, GDPR requires organizations to:

Ensure secure data transfer and storage

Enable auditability of data access and processing

Protect personal data against unauthorized processing and accidental loss, destruction, or damage

How Check Point SASE addresses these needs:

Encrypt traffic between users and resources

Log network and administrative activity

Apply Zero Trust policies that restrict user and application access to predefined rules

Check Point SASE supports GDPR compliance efforts with technical security capabilities that provide visibility, control, and secure access across the network. Learn more about Check Point’s commitment to GDPR at checkpoint.com/trust-point.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 12

GDPR

Customer support only

Check Point SASE provides capabilities that can support organizations in meeting certain GDPR

obligations — depending on configuration and use — through strong access controls, data protection

mechanisms, and activity logging.

Among other things, GDPR requires organizations to:

Ensure secure data transfer and

storage

Enable auditability of data access and processing

Protect personal data against unauthorized processing and accidental loss, destruction, or damage

How Check Point SASE addresses these needs:

Encrypt traffic between users and resources

Log network and administrative

activity

Apply Zero Trust policies that restrict user and application access to predefined rules

Check Point SASE supports GDPR compliance efforts with technical security capabilities that provide

visibility, control, and secure access across the network. Learn more about Check Point’s commitment to GDPR at checkpoint.com/trust-point.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 13

NIS 2 Directive

Customer support only

Check Point SASE supports organizations in addressing technical cyber security measures related to the EU’s NIS 2 Directive, which sets mandatory cyber security risk-management and reporting obligations for essential and important entities.

Organizations must ensure they have appropriate measures to manage cyber risks, protect networks and information systems, and report significant incidents.

What Check Point SASE commits to

Enable Zero Trust access to critical systems and data

Secure data in transit through encrypted tunnels

Support business continuity through resilient cloud infrastructure and secure remote access

Log security events and system activity for incident detection and reporting

These capabilities may assist organizations in addressing certain NIS 2 requirements related to risk management, incident reporting, and operational resilience.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 13

NIS 2 Directive

Customer support only

Check Point SASE supports organizations in addressing technical cyber security measures related to

the EU’s NIS 2 Directive, which sets mandatory cyber security risk-management and reporting

obligations for essential and important entities.

Organizations must ensure they have appropriate measures to manage cyber risks, protect networks

and information systems, and report significant incidents.

What Check Point SASE commits to

Enable Zero Trust access to

critical systems and data

Secure data in transit through

encrypted tunnels

Log security events and system

activity for incident detection and reporting

Support business continuity

through resilient cloud infrastructure and secure

remote access

These capabilities may assist organizations in addressing certain NIS 2 requirements related to risk

management, incident reporting, and operational resilience.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 14

CIS Critical Security Controls

Customer support only

The Center for Internet Security (CIS) Critical Security Controls (v8) represent a prioritized set of actions that collectively form a strong cyber security foundation. Check Point SASE provides capabilities that may assist organizations to address over 35 CIS Safeguards across various controls.

Key examples

Monitor managed devices and enforce posture requirements

Enforce encryption and enable least-privilege access

Support MFA, and manage and report on role-based access

Provide detailed logging and retention

Secure access through identity-based rules, with traffic limited to secure protocols

These mappings are documented in our CIS Controls matrix and summary overview, so customers can see exactly how Check Point SASE contributes to securing their environments.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 14

CIS Critical Security Controls

Customer support only

The Center for Internet Security (CIS) Critical Security Controls (v8) represent a prioritized set of actions that collectively form a strong cyber security foundation. Check Point SASE provides capabilities that may assist organizations to address over 35 CIS Safeguards across various controls.

Key examples

Monitor managed devices and

enforce posture requirements

Enforce encryption and

enable least-privilege access

Support MFA, and manage and

report on role-based access

Provide detailed logging and retention

Secure access through identity-based rules, with traffic limited to secure protocols

These mappings are documented in our CIS Controls matrix and summary overview, so customers

can see exactly how Check Point SASE contributes to securing their environments.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 15

Check Point Portal Compliance

Check Point SASE is managed through the Check Point Portal, a unified, cloud-delivered management experience for Check Point products and services.

The certifications below also apply to the Check Point Portal management environment, reinforcing the security of administrative operations and data within the management interface.

ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032

ISO/IEC 27701 SOC 2 Type II C5 (BSI, Germany) IRAP (Australia)

Together, these certifications help ensure secure administrative access, policy management, and account management.

Take the Complexity Out of Compliance

Compliance is never one-size-fits-all. Check Point SASE offers a flexible foundation for meeting regulatory and best-practice standards across sectors. By unifying secure networking and advanced threat prevention in one platform, we help streamline compliance and reduce the load on IT and security teams.

See how Check Point SASE can streamline your compliance efforts.

Talk to an Expert

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 15

Check Point Portal Compliance

Check Point SASE is managed through the Check Point Portal, a unified, cloud-delivered management experience for Check Point products and services.

The certifications below also apply to the Check Point Portal management environment, reinforcing

the security of administrative operations and data within the management interface.

ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032

ISO/IEC 27701 SOC 2 Type II C5 (BSI, Germany) IRAP (Australia)

Together, these certifications help ensure secure administrative access, policy management, and account management.

Take the Complexity Out of Compliance

Compliance is never one-size-fits-all. Check Point SASE offers a flexible foundation for meeting regulatory and best-practice standards across sectors. By unifying secure networking and advanced threat prevention in one platform, we help streamline compliance and reduce the load on IT and security teams.

See how Check Point SASE can streamline your compliance efforts.

Talk to an Expert

https://sase.checkpoint.com/demo https://sase.checkpoint.com/demo

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 16

References and Resources

Check Point product certifications — https://www.checkpoint.com/about-us/product- certifications/

HIPAA: Securing healthcare organizations with Zero Trust — https://www.checkpoint.com/ resources/items/hipaa-securing-healthcare-organizations-with-zero-trust

Check Point SASE coverage of the CIS Critical Security Controls — https://www.checkpoint.com/ resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls

Addressing CIS Controls with Check Point SASE — https://www.checkpoint.com/resources/items/ addressing-cis-controls-with-harmony-sase

EU NIS 2 Directive (Directive (EU) 2022/2555) — https://eur-lex.europa.eu/legal-content/EN/TXT/? uri=CELEX:32022L2555

Check Point Trust Point — https://www.checkpoint.com/trust-point/

Strengthening authentication in the AI era: Check Point SASE and the CISA Secure by Design pledge — https://blog.checkpoint.com/

Legal Notice

Information contained in this compliance overview is provided for general informational purposes only, may be modified at any time, and does not constitute legal or professional advice, nor does it constitute a warranty or guarantee of compliance, fitness for a particular purpose, or suitability for any specific regulatory framework.

Check Point is a cyber security technology provider and does not provide compliance assessment or compliance certification services. References to laws, regulations, standards, frameworks, or industry requirements describe security capabilities that may support customer compliance initiatives, but do not mean that use of Check Point products or services alone will ensure compliance with any legal or regulatory obligation.

Customers are responsible for assessing their own compliance obligations and for configuring, implementing, and using the service in accordance with applicable laws and regulations, including data protection requirements. Compliance outcomes depend on numerous factors outside Check Point’s control, including customer configurations, internal policies and procedures, third-party systems, and operational practices.

www.checkpoint.com  © 2026 Check Point Software Technologies Ltd. All rights reserved.

COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 16

References and Resources

Check Point product certifications — https://www.checkpoint.com/about-us/product-certifications/

HIPAA: Securing healthcare organizations with Zero Trust — https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust

Check Point SASE coverage of the CIS Critical Security Controls —

https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls

Addressing CIS Controls with Check Point

SASE — https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase EU NIS 2 Directive (Directive

(EU) 2022/2555) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555

Check Point Trust Point — https://www.checkpoint.com/trust-point/ Strengthening authentication in the AI era: Check Point SASE and the CISA Secure by Design pledge — https://blog.checkpoint.com/

Legal Notice

Information contained in this compliance overview is provided for general informational purposes

only, may be modified at any time, and does not constitute legal or professional advice, nor does it

constitute a warranty or guarantee of compliance, fitness for a particular purpose, or suitability for any specific regulatory framework.

Check Point is a cyber security technology provider and does not provide compliance assessment or

compliance certification services. References to laws, regulations, standards, frameworks, or industry requirements describe security capabilities that may support customer compliance initiatives, but do not mean that use of Check Point products or services alone will ensure compliance with any legal or

regulatory obligation.

Customers are responsible for assessing their own compliance obligations and for configuring,

implementing, and using the service in accordance with applicable laws and regulations, including

data protection requirements. Compliance outcomes depend on numerous factors outside Check

Point’s control, including customer configurations, internal policies and procedures, third-party systems, and operational practices.

www.checkpoint.com © 2026 Check Point Software Technologies Ltd. All rights reserved.

https://www.checkpoint.com/about-us/product-certifications/ https://www.checkpoint.com/about-us/product-certifications/ https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555 https://www.checkpoint.com/trust-point/ https://blog.checkpoint.com/ https://www.checkpoint.com https://www.checkpoint.com/about-us/product-certifications/ https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555 https://www.checkpoint.com/trust-point/ https://blog.checkpoint.com/ https://www.checkpoint.com


Item Type: pdf