Group Purchasing
Group Purchasing

SANS Trust & Legal Compliance

Our Commitment to Security, Privacy, and Compliance

SANS invests in independent audits, industry-recognized standards, and continuous controls monitoring to protect our customers, learners, and partners. This page centralizes our certifications, attestations, and request pathways so you can quickly verify our posture and obtain the documentation you need.

Validated Certifications

ISO/IEC 27001 is a globally recognized standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). Certification under this standard demonstrates that SANS has a comprehensive, risk-based approach to protecting sensitive information and that its security controls are independently verified for effectiveness and continuous improvement. Find SANS on the official IAF CertSearch registry: https://www.iafcertsearch.org/certified-entity/WZMBgGoO6i5LBWaoGKvVaoZh

Cyber Essentials is a UK Government–backed, industry-supported certification designed to help organizations protect against common cyber threats. Achieving CE and CE+ demonstrates that SANS meets the technical requirements for secure configuration, boundary protection, access control, malware defense, and patch management; reinforcing SANS’s commitment to operational security and threat resilience. SANS CE / CE+ certificates are searchable via the official IASME portal at https://iasme.co.uk/cyber-essentials/ncsc-certificate-search/

SOC 2 reports are independent third-party audits conducted under the American Institute of Certified Public Accountants (AICPA) standards to evaluate how effectively an organization’s systems safeguard data. These reports demonstrate that SANS maintains rigorous controls around security, availability, confidentiality, processing integrity, and privacy, and that those controls are operating as designed to protect customer information.

To obtain SANS’s latest SOC 2 reports or bridge letters, please contact us directly.

The Payment Card Industry Data Security Standard (PCI DSS) establishes global technical and operational requirements to protect payment card data and reduce the risk of fraud and breaches. Compliance demonstrates that SANS applies strict safeguards when handling cardholder data, including encryption, access control, and network monitoring.

To request SANS’s most recent PCI DSS attestation, please contact us directly.

Our Commitment to Transparency

SANS is committed to maintaining the highest standards of trust, integrity, and accountability in everything we do. By aligning with globally recognized frameworks and undergoing regular independent assessments, we ensure that our practices evolve alongside industry best standards, and that our customers can always rely on the security and integrity of their relationship with SANS.