CoinMarketCap announced on Wednesday the completion of independent assessments for SOC 1 and SOC 2 Type 1 attestations, alongside dual ISO certifications, as part of its ongoing efforts to validate its data security and privacy controls.
The SOC 2 Type 1 report evaluates the design and implementation of controls against the Trust Services Criteria for Security, conducted in accordance with AICPA attestation standards. The SOC 1 Type 1 examination report addresses controls relevant to internal control over financial reporting. Both assessments were finalized in August 2026.
In June 2026, CoinMarketCap independently secured dual ISO certifications from the British Standards Institution. The ISO/IEC 27001:2022 certification, registered under IS 838849, covers information security management, while the ISO/IEC 27701:2019 certification, registered under PM 838852, addresses privacy information management. The latter is designed to align with GDPR and other global privacy regulations. The ISO certifications are maintained through a three-year cycle with annual surveillance audits.
The scope of the assessments included parts of the business handling user and market information, price tracking, market data APIs, underlying cloud systems, operational processes, account management, and the handling of personally identifiable information. The evaluation also covered CoinMarketCap’s applications on iOS and Android.
Rush, CEO of CoinMarketCap, said the certifications demonstrate the platform’s commitment to data security and privacy. "Millions of people use CoinMarketCap to make decisions about their money. Trust in that data should be demonstrated rather than claimed."
The company, which reports over 1 billion monthly page views and tracks 53 million cryptocurrencies, did not disclose additional financial or operational details related to the certifications.












