White Paper | Align with Compliance Requirements with SASE
See our certifications and how Check Point SASE supports your compliance work — ISO, SOC 2, GDPR, HIPAA, NIS 2, CIS, and more.

How Check Point SASE Helps You Align with Key Compliance Requirements Certifications and attestations, and the frameworks
Check Point SASE helps you address
How Check Point SASE Helps You Align
with Key Compliance Requirements
Certifications and attestations, and the frameworks Check Point SASE helps you address
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 02
Executive Summary
Check Point SASE is designed with security and compliance support capabilities at its core. We maintain rigorous certifications that demonstrate the security of our platform, and we deliver capabilities that help organizations align with a wide range of compliance frameworks.
From global privacy regulations to healthcare mandates and industry best practices, Check Point SASE helps organizations strengthen their compliance efforts through advanced security controls, deep visibility, and secure access.
This overview is organized in two parts. First, the standards Check Point is independently certified or attested against. Second, the frameworks where Check Point SASE provides technical capabilities that support your own compliance work. A capability summary and a reference diagram tie the two together.
Where Check Point SASE helps most
Identity and access
Zero Trust access, identity provider integration, role-based access control (RBAC), and multi-factor authentication (MFA)
Encryption in transit
Traffic secured with modern protocols, including TLS, IPSec, and WireGuard
Logging and auditability
Centralized event logging and continuous access audits for investigation and reporting
Segmentation
Application-level access control that limits lateral movement and shrinks the attack surface
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 02
Executive Summary
Check Point SASE is designed with security and compliance support capabilities at its core. We maintain rigorous certifications that demonstrate the security of our platform, and we deliver
capabilities that help organizations align with a wide range of compliance frameworks. From global privacy regulations to healthcare mandates and industry best practices, Check Point
SASE helps organizations
strengthen their compliance efforts through advanced security controls, deep visibility, and secure access.
This overview is organized in two parts. First, the standards Check Point is independently certified or attested against. Second, the frameworks
where Check Point SASE provides technical capabilities that support your own compliance work. A capability summary and a reference diagram tie the
two together.
Where Check Point SASE helps most
Identity and access
Zero Trust access, identity provider
integration, role-based access control (RBAC), and multi-factor authentication
(MFA)
Encryption in transit
Traffic secured with modern protocols, including TLS, IPSec, and WireGuard
Logging and auditability
Centralized event logging and continuous
access audits for investigation and
reporting
Segmentation
Application-level access control that limits lateral movement and shrinks the
attack surface
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 03
Our Certifications
Check Point SASE, as part of Check Point, is certified or attested against the following standards, validating the security and reliability of our platform.
ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032
ISO/IEC 27036 ISO/IEC 27701 SOC 2 Type II
CISA Secure by Design Pledge (signatory commitment)
C5 — Cloud Computing Compliance Controls Catalogue (BSI, Germany)
IRAP — Infosec Registered Assessors Program (Australia)
These certifications provide assurance that our systems, processes, and controls meet stringent industry requirements, including information security management, cloud security, privacy protection, and cyber resilience.
Supporting Your Compliance Efforts
In addition to our own certifications, Check Point SASE provides capabilities that may assist organizations in supporting alignment with key compliance frameworks by delivering essential security capabilities. Support depends on configuration and use, but the essential security building blocks are the same across frameworks.
Frameworks where Check Point SASE supports customer compliance
HIPAA Security Rule HIPAA Security Rule
Technical safeguards that support the protection of electronic protected health information
Access control, data protection, and activity logging for personal data
CIS Critical Security Controls HIPAA Security Rule
Capabilities that help address more than 35 CIS Safeguards across multiple controls
Risk management, incident detection and reporting, and operational resilience
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 03
Our Certifications
Check Point SASE, as part of Check Point, is certified or attested against the following
standards, validating the security and reliability of our platform.
ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032
ISO/IEC 27036 ISO/IEC 27701 SOC 2 Type II
CISA Secure by Design Pledge (signatory commitment)
C5 — Cloud Computing Compliance Controls Catalogue (BSI, Germany)
IRAP — Infosec Registered Assessors Program (Australia)
These certifications provide assurance that our systems, processes, and controls meet stringent
industry requirements, including information security management, cloud security, privacy protection, and cyber resilience.
Supporting Your Compliance Efforts
In addition to our own certifications, Check Point SASE provides capabilities that may assist organizations in supporting alignment with key compliance frameworks by delivering essential security capabilities. Support depends on configuration and use, but the essential security building blocks are the same across frameworks.
Frameworks where Check Point SASE supports customer compliance
HIPAA Security Rule
Technical safeguards that support
the protection of electronic protected health information
HIPAA Security Rule
Access control, data protection,
and activity logging for personal data
CIS Critical Security Controls
Capabilities that help address
more than 35 CIS Safeguards
across multiple controls
HIPAA Security Rule
Risk management, incident
detection and reporting, and
operational resilience
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 04
Compliance at a Glance
Check Point SASE helps organizations address common security requirements found across major compliance and industry frameworks — including identity and access management, encryption, logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.
Customer
requirement
What it means for
you
How Check Point
SASE helps
Frameworks
commonly
addressed
Identity and
access
management
Control who can
reach apps and data;
enforce least privilege
ZTNA, identity provider
integration, RBAC,
MFA
ISO 27001, NIS 2,
SOC 2, CIS, HIPAA
Encryption in
transit
Protect sensitive data
as it moves across
networks
TLS, IPSec, and
WireGuard encrypted
tunnels
GDPR, HIPAA, ISO
27001, NIS 2
Network
segmentation
Limit lateral
movement and reduce
attack surface
ZTNA and application-
level access control
ISO 27001, CIS, C5
Logging and
auditability
Enable audits,
investigations, and
compliance reporting
Centralized logging
and SIEM integration
SOC 2, ISO 27001,
HIPAA, GDPR, NIS 2
Device trust and
session control
Ensure only compliant
devices keep access
Device posture checks
and session
termination
CIS, ISO 27001
(indirect)
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 04
Compliance at a Glance
Check Point SASE helps organizations address common security requirements found across major
compliance and industry frameworks — including identity and access management, encryption,
logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.
Customer
requirement What it means for
you
How Check Point
SASE helps Frameworks
commonly addressed
Identity and access
management
Control who can
reach apps and data; enforce least privilege
ZTNA, identity provider integration, RBAC, MFA
ISO 27001, NIS 2,
SOC 2, CIS, HIPAA
Encryption in transit
Protect sensitive data
as it moves across
networks
TLS, IPSec, and
WireGuard encrypted tunnels
GDPR, HIPAA, ISO
27001, NIS 2
Network
segmentation
Limit lateral
movement and reduce
attack surface
ZTNA and application- level access control
ISO 27001, CIS, C5
Logging and auditability
Enable audits,
investigations, and compliance reporting
Centralized logging and SIEM integration
SOC 2, ISO 27001,
HIPAA, GDPR, NIS 2
Device trust and
session control Ensure only compliant devices keep access
Device posture checks and session
termination
CIS, ISO 27001 (indirect)
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 05
Certifications and Attestations
ISO/IEC 27001 and Related Certifications
Check Point SASE helps organizations address common security requirements found across major compliance and industry frameworks — including identity and access management, encryption, logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.
Our certifications
Check Point, including Check Point SASE, is certified for ISO/IEC 27001, along with related standards ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27032, and ISO/IEC 27701. Together they cover information security, privacy management, cloud security, and cyber resilience.
ISO/IEC 27001 — Information Security Management System (ISMS)
ISO/IEC 27017 — cloud security best practices
ISO/IEC 27018 — protection of personally identifiable information (PII) in public clouds
ISO/IEC 27032 — guidelines for internet security
ISO/IEC 27701 — Privacy Information Management System (PIMS)
Customer support
Organizations pursuing ISO/IEC 27001 compliance can leverage Check Point SASE capabilities that deliver essential controls related to:
Network security, access management, threat protection, and data encryption
Protection of personal data in cloud environments (ISO 27018, ISO 27701)
Cyber resilience measures for detecting, responding, and recovering from cyber incidents (ISO 27032)
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 05
Certifications and Attestations
ISO/IEC 27001 and Related Certifications
Check Point SASE helps organizations address common security requirements found across major
compliance and industry frameworks — including identity and access management, encryption,
logging, and Zero Trust access. The following examples illustrate how certain Check Point SASE security capabilities may support customer compliance initiatives.
Our certifications
Check Point, including Check Point SASE, is certified for ISO/IEC 27001, along with related standards ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27032, and ISO/IEC 27701. Together they cover information
security, privacy management, cloud security, and cyber resilience.
ISO/IEC 27001 — Information Security Management System (ISMS)
ISO/IEC 27017— cloud security best practices
ISO/IEC 27018— protection of personally identifiable information (PII) in public clouds
ISO/IEC 27032— guidelines for internet security
ISO/IEC 27701 — Privacy Information Management System (PIMS)
Customer support
Organizations pursuing ISO/IEC 27001 compliance can leverage Check Point SASE capabilities that deliver essential controls related to:
Network security, access
management, threat protection, and data encryption
Protection of personal data in cloud environments (ISO 27018,
ISO 27701)
Cyber resilience measures for detecting, responding, and recovering from cyber incidents (ISO 27032)
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 06
Our platform contributes to ISO compliance by:
Controlling access to applications and data via Zero Trust principles
Enforcing encryption for data in transit through secure tunnels (IPSec, WireGuard)
Logging access and policy changes for auditing
Segmenting networks and restricting access based on user roles
Supporting privacy management best practices for protecting PII in cloud services
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 06
Our platform contributes to ISO compliance by:
Controlling access to
applications and data via Zero
Trust principles
Enforcing encryption for data in
transit through secure tunnels (IPSec, WireGuard)
Logging access and policy
changes for auditing
Segmenting networks and
restricting access based on user roles
Supporting privacy management best practices for protecting PII in cloud services
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 07
SOC 2 Type II
Our certifications
Check Point is certified for SOC 2 Type II, meaning our systems and processes have been independently audited for how effectively they secure customer data over time. The certification covers the Security, Availability, and Confidentiality trust services criteria, based on the AICPA Trust Services Criteria.
How we support your SOC 2 obligations
Prevent unauthorized access Monitor network activity
Ensure high availability and resilience
Protect sensitive customer data throughout the service lifecycle
How the audit scope works
Check Point SASE uses cloud infrastructure providers whose controls are covered by their own independent compliance certifications (for example, SOC 2 and ISO 27001). These providers were treated as subservice organizations during our audit. Our SOC 2 certification focuses solely on the controls directly managed by Check Point.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 07
SOC 2 Type II
Our certifications
Check Point is certified for SOC 2 Type II, meaning our systems and processes have been
independently audited for how effectively they secure customer data over time. The certification
covers the Security, Availability, and Confidentiality trust services criteria, based on the AICPA Trust Services Criteria.
How we support your SOC 2 obligations
Prevent unauthorized access Monitor network activity
Ensure high availability and resilience
Protect sensitive customer data
throughout the service lifecycle
How the audit scope works
Check Point SASE uses cloud infrastructure providers whose controls are covered by their own
independent compliance certifications (for example, SOC 2 and ISO 27001). These providers
were treated as subservice organizations during our audit. Our SOC 2 certification focuses
solely on the controls directly managed by Check Point.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 08
C5 — Cloud Computing Compliance Controls Catalogue (BSI, Germany)
Our attestation
Check Point, including the Check Point SASE management environment via the Check Point Portal, is attested by an independent auditor against the Cloud Computing Compliance Criteria Catalogue (C5:2020) issued by the German Federal Office for Information Security (BSI).
C5 defines comprehensive baseline security criteria for cloud service providers and is widely recognized in Germany and across the EU. Check Point SASE supports customer compliance with key C5 requirements through controls in these core areas:
Identity and access management Zero Trust access, role-based access control, and robust authentication
Data transport security Traffic between users, gateways, and systems encrypted with TLS, IPSec, and WireGuard
Logging Centralized event logging and continuous access audits for traceability
Separation of environments Strict isolation of production from development and testing systems
Business continuity Cloud-native resiliency measures and geographic redundancy
These controls position Check Point SASE well for regulated entities that need trusted, compliant cloud solutions across Germany and the broader EU.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 08
C5 — Cloud Computing Compliance Controls Catalogue
(BSI, Germany)
Our attestation
Check Point, including the Check Point SASE management environment via the Check Point Portal, is
attested by an independent auditor against the Cloud Computing Compliance Criteria Catalogue
(C5:2020) issued by the German Federal Office for Information Security (BSI).
C5 defines comprehensive baseline security criteria for cloud service providers and is widely recognized in Germany and across the EU. Check Point SASE supports customer compliance with
key C5 requirements through controls in these core areas:
Identity and access management
Zero Trust access, role-based access control, and robust authentication
Data transport security
Traffic between users, gateways,
and systems encrypted with TLS, IPSec, and WireGuard
Logging
Centralized event logging and continuous access audits for
traceability
Separation of environments
Strict isolation of production from development
and testing systems
Business continuity
Cloud-native resiliency measures and geographic redundancy
These controls position Check Point SASE well for regulated entities that need trusted, compliant cloud solutions across Germany and the broader EU.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 09
CISA Secure by Design Pledge
Our commitment
Check Point is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Secure by Design pledge. The initiative calls on technology providers to design and deliver products that are secure by default and resilient against modern threats.
What Check Point SASE commits to
Embed security features in the core design of the platform
Enable multi-factor authentication by default
Reduce default attack surfaces across our infrastructure
Offer transparency and accountability around secure development practices
This commitment reflects our broader mission: helping customers not only achieve compliance, but maintain a strong security posture by design.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 09
CISA Secure by Design Pledge
Our commitment
Check Point is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Secure
by Design pledge. The initiative calls on technology providers to design and deliver products that are
secure by default and resilient against modern threats.
What Check Point SASE commits to
Embed security features in the
core design of the platform
Enable multi-factor
authentication by default
Reduce default attack surfaces
across our infrastructure
Offer transparency and
accountability around secure
development practices
This commitment reflects our broader mission: helping customers not only achieve compliance, but maintain a strong security posture by design.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 10
IRAP — Australia
Our assessment
The Australian Signals Directorate’s Infosec Registered Assessors Program (IRAP) provides a framework for independent assessment of ICT and cloud services against the Australian Government Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF). Check Point has completed an IRAP assessment of selected cloud services that underpin Check Point SASE, with particular emphasis on the core cloud infrastructure and Check Point SASE Private Access capabilities.
The resulting IRAP report provides independent assurance about the implementation and effectiveness of security controls within the defined scope at the time of the assessment.
Customer support
For Australian Government agencies and regulated organizations handling Australian Government information, Check Point SASE and its IRAP-assessed cloud environment can be used as part of the evidence base when customers independently demonstrate alignment with the ISM and PSPF for outsourced ICT and cloud services (including OFFICIAL, OFFICIAL: Sensitive and PROTECTED information). In particular, Check Point SASE helps support:
Network and infrastructure security controls - Zero Trust access to applications, network segmentation, and secure remote connectivity
Encryption of data in transit - Use of secure tunnels and modern cryptographic protocols
Identity and access management Integration with enterprise identity providers, strong authentication (including MFA), and role-based access controls
Logging, monitoring, and auditability - Centralized logging of administrative and access activity, SIEM integration, and security event visibility
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 10
IRAP — Australia
Our assessment
The Australian Signals Directorate’s Infosec Registered Assessors Program (IRAP) provides a
framework for independent assessment of ICT and cloud services against the Australian Government
Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF). Check Point
has completed an IRAP assessment of selected cloud services that underpin Check Point SASE, with
particular emphasis on the core cloud infrastructure and Check Point SASE Private Access capabilities.
The resulting IRAP report provides independent assurance about the implementation and
effectiveness of security controls within the defined scope at the time of the assessment.
Customer support
For Australian Government agencies and regulated organizations handling Australian Government
information, Check Point SASE and its IRAP-assessed cloud environment can be used as part of the evidence base when customers independently demonstrate alignment with the ISM and PSPF
for outsourced ICT and cloud services (including OFFICIAL, OFFICIAL: Sensitive and PROTECTED information).
In particular, Check Point SASE helps support:
Network and infrastructure
security controls - Zero Trust
access to applications, network
segmentation, and secure
remote connectivity
Encryption of data in transit - Use of secure tunnels
and modern cryptographic protocols
Identity and access management
Integration with enterprise
identity providers, strong authentication (including MFA), and role-based access controls
Logging, monitoring, and
auditability - Centralized logging of administrative and access
activity, SIEM integration, and
security event visibility
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 11
Frameworks We Help You Address
HIPAA Security Rule
Customer support only
Check Point SASE itself is not audited for HIPAA compliance but provides technical capabilities that may support U.S. healthcare organizations in addressing certain HIPAA Security Rule technical safeguards, which govern the protection of electronic protected health information (ePHI).
According to the U.S. Department of Health and Human Services, covered entities must:
Ensure the confidentiality, integrity, and availability of ePHI
Protect against reasonably anticipated threats to ePHI
Guard against impermissible uses or disclosures
Ensure workforce compliance
Check Point SASE provides capabilities that may be used to support these requirements by:
Enabling least-privilege access to sensitive applications and data
Encrypting ePHI in transit across secure tunnels
Logging access and changes for audit and investigation
Providing centralized management and policy enforcement
As noted in our HIPAA checklist white paper, Check Point SASE supports core technical safeguards, including access control, integrity controls, audit controls, and transmission security, making it a solution that may support organizations working toward HIPAA compliance.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 11
Frameworks We Help You Address
HIPAA Security Rule
Customer support only
Check Point SASE itself is not audited for HIPAA compliance but provides technical capabilities that
may support U.S. healthcare organizations in addressing certain HIPAA Security Rule technical
safeguards, which govern the protection of electronic protected health information (ePHI).
According to the U.S. Department of Health and Human Services, covered entities must:
Ensure the confidentiality,
integrity, and availability of ePHI
Protect against reasonably
anticipated threats to ePHI
Guard against impermissible uses or disclosures Ensure workforce compliance
Check Point SASE provides capabilities that may be used to support these requirements by:
Enabling least-privilege access to
sensitive applications and data
Encrypting ePHI in transit across secure tunnels
Logging access and changes for
audit and investigation
Providing centralized management
and policy enforcement
As noted in our HIPAA checklist white paper, Check Point SASE supports core technical safeguards,
including access control, integrity controls, audit controls, and transmission security, making it a solution that may support organizations working toward HIPAA compliance.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 12
GDPR
Customer support only
Check Point SASE provides capabilities that can support organizations in meeting certain GDPR obligations — depending on configuration and use — through strong access controls, data protection mechanisms, and activity logging.
Among other things, GDPR requires organizations to:
Ensure secure data transfer and storage
Enable auditability of data access and processing
Protect personal data against unauthorized processing and accidental loss, destruction, or damage
How Check Point SASE addresses these needs:
Encrypt traffic between users and resources
Log network and administrative activity
Apply Zero Trust policies that restrict user and application access to predefined rules
Check Point SASE supports GDPR compliance efforts with technical security capabilities that provide visibility, control, and secure access across the network. Learn more about Check Point’s commitment to GDPR at checkpoint.com/trust-point.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 12
GDPR
Customer support only
Check Point SASE provides capabilities that can support organizations in meeting certain GDPR
obligations — depending on configuration and use — through strong access controls, data protection
mechanisms, and activity logging.
Among other things, GDPR requires organizations to:
Ensure secure data transfer and
storage
Enable auditability of data access and processing
Protect personal data against unauthorized processing and accidental loss, destruction, or damage
How Check Point SASE addresses these needs:
Encrypt traffic between users and resources
Log network and administrative
activity
Apply Zero Trust policies that restrict user and application access to predefined rules
Check Point SASE supports GDPR compliance efforts with technical security capabilities that provide
visibility, control, and secure access across the network. Learn more about Check Point’s commitment to GDPR at checkpoint.com/trust-point.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 13
NIS 2 Directive
Customer support only
Check Point SASE supports organizations in addressing technical cyber security measures related to the EU’s NIS 2 Directive, which sets mandatory cyber security risk-management and reporting obligations for essential and important entities.
Organizations must ensure they have appropriate measures to manage cyber risks, protect networks and information systems, and report significant incidents.
What Check Point SASE commits to
Enable Zero Trust access to critical systems and data
Secure data in transit through encrypted tunnels
Support business continuity through resilient cloud infrastructure and secure remote access
Log security events and system activity for incident detection and reporting
These capabilities may assist organizations in addressing certain NIS 2 requirements related to risk management, incident reporting, and operational resilience.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 13
NIS 2 Directive
Customer support only
Check Point SASE supports organizations in addressing technical cyber security measures related to
the EU’s NIS 2 Directive, which sets mandatory cyber security risk-management and reporting
obligations for essential and important entities.
Organizations must ensure they have appropriate measures to manage cyber risks, protect networks
and information systems, and report significant incidents.
What Check Point SASE commits to
Enable Zero Trust access to
critical systems and data
Secure data in transit through
encrypted tunnels
Log security events and system
activity for incident detection and reporting
Support business continuity
through resilient cloud infrastructure and secure
remote access
These capabilities may assist organizations in addressing certain NIS 2 requirements related to risk
management, incident reporting, and operational resilience.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 14
CIS Critical Security Controls
Customer support only
The Center for Internet Security (CIS) Critical Security Controls (v8) represent a prioritized set of actions that collectively form a strong cyber security foundation. Check Point SASE provides capabilities that may assist organizations to address over 35 CIS Safeguards across various controls.
Key examples
Monitor managed devices and enforce posture requirements
Enforce encryption and enable least-privilege access
Support MFA, and manage and report on role-based access
Provide detailed logging and retention
Secure access through identity-based rules, with traffic limited to secure protocols
These mappings are documented in our CIS Controls matrix and summary overview, so customers can see exactly how Check Point SASE contributes to securing their environments.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 14
CIS Critical Security Controls
Customer support only
The Center for Internet Security (CIS) Critical Security Controls (v8) represent a prioritized set of actions that collectively form a strong cyber security foundation. Check Point SASE provides capabilities that may assist organizations to address over 35 CIS Safeguards across various controls.
Key examples
Monitor managed devices and
enforce posture requirements
Enforce encryption and
enable least-privilege access
Support MFA, and manage and
report on role-based access
Provide detailed logging and retention
Secure access through identity-based rules, with traffic limited to secure protocols
These mappings are documented in our CIS Controls matrix and summary overview, so customers
can see exactly how Check Point SASE contributes to securing their environments.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 15
Check Point Portal Compliance
Check Point SASE is managed through the Check Point Portal, a unified, cloud-delivered management experience for Check Point products and services.
The certifications below also apply to the Check Point Portal management environment, reinforcing the security of administrative operations and data within the management interface.
ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032
ISO/IEC 27701 SOC 2 Type II C5 (BSI, Germany) IRAP (Australia)
Together, these certifications help ensure secure administrative access, policy management, and account management.
Take the Complexity Out of Compliance
Compliance is never one-size-fits-all. Check Point SASE offers a flexible foundation for meeting regulatory and best-practice standards across sectors. By unifying secure networking and advanced threat prevention in one platform, we help streamline compliance and reduce the load on IT and security teams.
See how Check Point SASE can streamline your compliance efforts.
Talk to an Expert
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 15
Check Point Portal Compliance
Check Point SASE is managed through the Check Point Portal, a unified, cloud-delivered management experience for Check Point products and services.
The certifications below also apply to the Check Point Portal management environment, reinforcing
the security of administrative operations and data within the management interface.
ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27032
ISO/IEC 27701 SOC 2 Type II C5 (BSI, Germany) IRAP (Australia)
Together, these certifications help ensure secure administrative access, policy management, and account management.
Take the Complexity Out of Compliance
Compliance is never one-size-fits-all. Check Point SASE offers a flexible foundation for meeting regulatory and best-practice standards across sectors. By unifying secure networking and advanced threat prevention in one platform, we help streamline compliance and reduce the load on IT and security teams.
See how Check Point SASE can streamline your compliance efforts.
Talk to an Expert
https://sase.checkpoint.com/demo https://sase.checkpoint.com/demo
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 16
References and Resources
Check Point product certifications — https://www.checkpoint.com/about-us/product- certifications/
HIPAA: Securing healthcare organizations with Zero Trust — https://www.checkpoint.com/ resources/items/hipaa-securing-healthcare-organizations-with-zero-trust
Check Point SASE coverage of the CIS Critical Security Controls — https://www.checkpoint.com/ resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls
Addressing CIS Controls with Check Point SASE — https://www.checkpoint.com/resources/items/ addressing-cis-controls-with-harmony-sase
EU NIS 2 Directive (Directive (EU) 2022/2555) — https://eur-lex.europa.eu/legal-content/EN/TXT/? uri=CELEX:32022L2555
Check Point Trust Point — https://www.checkpoint.com/trust-point/
Strengthening authentication in the AI era: Check Point SASE and the CISA Secure by Design pledge — https://blog.checkpoint.com/
Legal Notice
Information contained in this compliance overview is provided for general informational purposes only, may be modified at any time, and does not constitute legal or professional advice, nor does it constitute a warranty or guarantee of compliance, fitness for a particular purpose, or suitability for any specific regulatory framework.
Check Point is a cyber security technology provider and does not provide compliance assessment or compliance certification services. References to laws, regulations, standards, frameworks, or industry requirements describe security capabilities that may support customer compliance initiatives, but do not mean that use of Check Point products or services alone will ensure compliance with any legal or regulatory obligation.
Customers are responsible for assessing their own compliance obligations and for configuring, implementing, and using the service in accordance with applicable laws and regulations, including data protection requirements. Compliance outcomes depend on numerous factors outside Check Point’s control, including customer configurations, internal policies and procedures, third-party systems, and operational practices.
www.checkpoint.com © 2026 Check Point Software Technologies Ltd. All rights reserved.
COMPLIANCE ALIGNMENT WITH CHECK POINT SASE | 16
References and Resources
Check Point product certifications — https://www.checkpoint.com/about-us/product-certifications/
HIPAA: Securing healthcare organizations with Zero Trust — https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust
Check Point SASE coverage of the CIS Critical Security Controls —
https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls
Addressing CIS Controls with Check Point
SASE — https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase EU NIS 2 Directive (Directive
(EU) 2022/2555) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555
Check Point Trust Point — https://www.checkpoint.com/trust-point/ Strengthening authentication in the AI era: Check Point SASE and the CISA Secure by Design pledge — https://blog.checkpoint.com/
Legal Notice
Information contained in this compliance overview is provided for general informational purposes
only, may be modified at any time, and does not constitute legal or professional advice, nor does it
constitute a warranty or guarantee of compliance, fitness for a particular purpose, or suitability for any specific regulatory framework.
Check Point is a cyber security technology provider and does not provide compliance assessment or
compliance certification services. References to laws, regulations, standards, frameworks, or industry requirements describe security capabilities that may support customer compliance initiatives, but do not mean that use of Check Point products or services alone will ensure compliance with any legal or
regulatory obligation.
Customers are responsible for assessing their own compliance obligations and for configuring,
implementing, and using the service in accordance with applicable laws and regulations, including
data protection requirements. Compliance outcomes depend on numerous factors outside Check
Point’s control, including customer configurations, internal policies and procedures, third-party systems, and operational practices.
www.checkpoint.com © 2026 Check Point Software Technologies Ltd. All rights reserved.
https://www.checkpoint.com/about-us/product-certifications/ https://www.checkpoint.com/about-us/product-certifications/ https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555 https://www.checkpoint.com/trust-point/ https://blog.checkpoint.com/ https://www.checkpoint.com https://www.checkpoint.com/about-us/product-certifications/ https://www.checkpoint.com/resources/items/hipaa-securing-healthcare-organizations-with-zero-trust https://www.checkpoint.com/resources/items/harmony-sase-coverage-of-the-cis-critical-security-controls https://www.checkpoint.com/resources/items/addressing-cis-controls-with-harmony-sase https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555 https://www.checkpoint.com/trust-point/ https://blog.checkpoint.com/ https://www.checkpoint.com