Skip to main content
Platform Review
PricingSign in
Pega assessment

Pega procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Pega
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow *Assessment status applicable if VoiceAI, digital messaging/web messaging, and Co-Browse are not used Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The American Institute of Certified Public Accountants (AICPA) Service Organization Controls (SOC) reports give assurance over control environments as they relate to the retrieval, storage, processing, and transfer of data. The reports cover IT General controls and controls around availability, confidentiality and security of customer data. The SOC 2 reports cover controls around security, availability, and confidentiality of customer data.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow ISO 27017 is an international standard offering guidance on information security controls for cloud services. These controls supplement the guidance of ISO 27002 and are included in Pega Cloud’s ISO 27001 certification. It helps address cloud security challenges by advising on effective measures like provider responsibilities, information sharing, personnel security, and compliance.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that required the creation of national standards to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge. The US Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement the requirements of HIPAA. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule. Adherence to applicable laws is a shared responsibility. Pega provides relevant security controls, guidance and feature capabilities that allow our clients to adhere to laws. Pega is designed to allow Clients to configure their own strategy for compliance with applicable laws.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Defense Information Systems Agency (DISA) published the Department of Defense Cloud Computing Security Requirements Guide (DoD CC SRG) that outlines the security model and requirements by which DoD will leverage cloud computing along with the security controls and requirements necessary for using cloud-based solutions. IL4 information covers controlled unclassified information (CUI), non-CUI information, non-critical mission information, and non-national security systems.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow *Assessment status applicable if Co-Browse is not used Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow ISO 9001 is an international standard for quality management systems that applies to software services by focusing on how an organization plans, delivers, monitors, and improves its software-related processes. It emphasizes consistent service delivery, clear requirements management, risk-based thinking, customer satisfaction, and continual improvement across software development, maintenance, support, and project management.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow ISO 27018 is a standard that provides guidelines for protecting personally identifiable information (PII) in the cloud. These guidelines supplement the guidance of ISO 27002 and are included in Pega Cloud’s ISO 27001 certification.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Security, Trust, Assurance, and Risk (STAR) Registry is a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow ISO 42001 is the first international standard for managing artificial intelligence (AI) responsibly. It provides a framework for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS). It demonstrates commitment to ethical, transparent, and risk-aware AI practices.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Hébergeurs de Données de Santé (HDS) certification is required for entities such as cloud service providers that host the personal health data governed by French laws and collected for delivering preventive, diagnostic, and other health services. The HDS regulation was issued by ASIP SANTÉ which, under the French Ministry of Health, is responsible for promoting electronically based healthcare solutions in France.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The General Data Protection Regulation is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. The GDPR is an important component of EU privacy law and of human rights law, in particular Article 8 of the Charter of Fundamental Rights of the European Union. Adherence to applicable laws is a shared responsibility. Pega provides relevant security controls, guidance and feature capabilities that allow our clients to adhere to laws. Pega is designed to allow Clients to configure their own strategy for compliance with applicable lawsCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow When evaluating the services listed under each compliance standard it should be noted that Pega relies on a common set of controls for the purposes of adherence. These common controls exist across the Pega Platform, the underlying infrastructure, and the operations, administration and management provided by Pega in Pega Cloud. Pega applications deployed within/on the Pega Platform inherit these controls which are attested to in the current scopeCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Cloud Computing Compliance Criteria Catalogue (C5) criteria catalogue specifies minimum requirements for secure cloud computing and is primarily intended for professional cloud providers, their auditors and customers.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Pega's security, privacy controls and policies allow clients to address a broad range of laws and regulations. Below are some examples:Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The California Consumer Privacy Act (CCPA) was enacted into law on June 28, 2018. The CCPA seeks to ensure California consumers have a certain level of privacy rights. Adherence to applicable laws is a shared responsibility. Pega provides relevant security controls, guidance and feature capabilities that allow our clients to adhere to laws. Pega is designed to allow Clients to configure their own strategy for compliance with applicable laws.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Effective as of July 17, 2023, eligible organizations in the United States that wish to self-certify their compliance pursuant to the UK Extension to the EU-U.S. DPF may do so; however, personal data cannot be received from the United Kingdom and Gibraltar in reliance on the UK Extension to the EU-U.S. DPF before the date that the adequacy regulations implementing the data bridge for the UK Extension to the EU-U.S. DPF enter into force. The data bridge will enable the transfer of UK and Gibraltar personal data to participating organizations consistent with UK lawCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Australian Prudential Regulation Authority (APRA) is Australia’s prudential regulator responsible for ensuring the safety, resilience, and stability of banks, insurers, and superannuation funds. APRA sets mandatory standards to strengthen financial institutions’ operational, information security, and risk-management capabilities. APRA issues prudential standards including the operational risk management standards of Prudential Standard 230 and the information security standards of Prudential Standard 234.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Cyber Essentials Plus is a UK Government-backed, industry-supported certification scheme introduced in the UK to help organizations demonstrate operational security against common cyber-attacks. It builds upon the Cyber Essentials certification by incorporating independent verification of technical controls.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow TISAX is an assessment and exchange mechanism for the information security of enterprises and allows recognition of assessment results among the participants.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow ISO/IEC 27001 is widely known, providing requirements for an information security management system (ISMS), though there are more than a dozen standards in the ISO/IEC 27000 family. Using them enables organizations of any kind to manage the security of assets such as financial information, intellectual property, employee details or information entrusted by third parties.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security authorizations for Cloud Service OfferingsCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslowThe effective date of the EU-U.S. DPF Principles, including the Supplemental Principles and Annex I of the Principles is July 10, 2023, which is the date of entry into force of the European Commission’s adequacy decision for the EU-U.S. DPF. The adequacy decision enables the transfer of EU personal data to participating organizations consistent with EU law.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Cyber Essentials is a UK Government-backed, industry-supported certification scheme introduced in the UK to help organizations demonstrate operational security against common cyber-attacks.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow STAR encompasses the key principles of transparency, rigorous auditing, and harmonization of standards outlined in the Cloud Controls Matrix (CCM). Publishing to the registry allows organizations to show current and potential customers their security and compliance posture, including the regulations, standards, and frameworks they adhere to. It ultimately reduces complexity and helps alleviate the need to fill out multiple customer questionnaires.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Infosec Registered Assessors Program (IRAP) ensures entities can access high-quality security assessment services.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Information System Security Management and Assessment Program (ISMAP) is a Japanese government program that assesses the security of cloud service providers (CSPs).Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Cybervadis offers a comprehensive risk assessment based on various factors, including data security, infrastructure security, and regulatory compliance. Pegasystems utilizes these ratings to identify potential vulnerabilities within the supply chain and to take effective measures to mitigate associated risks.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Published by the International Organization for Standardization, ISO 22301 is designed to help organizations prevent, prepare for, respond to and recover from unexpected and disruptive incidents. To do so, the standard provides a practical framework for setting up and managing an effective business continuity management system (BCMS). ISO 22301 aims to safeguard an organization from a wide range of potential threats and disruptions. The scope of the certification is limited to the BCMS supporting Pega Cloud and includes the organizations, systems, people and facilities directly involved in the deployment, maintenance, and monitoring of critical Pega Cloud services.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Esquema Nacional de Seguridad (ENS) is the Spanish National Security Framework. It is a set of security requirements and guidelines that are mandatory for all organizations that handle sensitive information on behalf of the Spanish government. The ENS is based on the principles of confidentiality, integrity, availability, and accountability. It is designed to protect sensitive information from unauthorized access, modification, or disclosure, and to ensure that it can be used only for authorized purposes.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The American Institute of Certified Public Accountants (AICPA) Service Organization Controls (SOC) reports give assurance over control environments as they relate to the retrieval, storage, processing, and transfer of data. The reports cover IT General controls and controls around availability, confidentiality and security of customer data. The SOC 1 reports are primarily concerned with examining controls that are relevant for the financial reporting of customersCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The EU-U.S. Data Privacy Framework (UK Extension to the EU-U.S. DPF), and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) were respectively developed in furtherance of transatlantic commerce by the U.S. Department of Commerce and the European Commission, the UK Government, and the Swiss Federal Administration to provide U.S. organizations with reliable mechanisms for personal data transfers to the United States from the European Union / European Economic Area, the United Kingdom (and Gibraltar), and Switzerland while ensuring data protection that is consistent with EU, UK, and Swiss law.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Developed in collaboration with data protection professionals, the HITRUST CSF rationalizes relevant regulations and standards into a single overarching security and privacy framework. The HITRUST Risk-based, 2-year (r2) Validated Assessment is globally recognized as a high-level validation showing that an organization successfully manages cyber risk by meeting and exceeding industry-defined and accepted information security requirements. The HITRUST r2 Validated Assessment + Certification is considered the gold standard for information protection assurances because of the comprehensiveness of control requirements, depth of quality review, and consistency of oversight. Pega’s HITRUST Assessment + Certification covers all the HIPAA Compliance Factors including the HIPAA Breach Notification, HIPAA Privacy Rule, and the HIPAA Security Rule.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Cybervadis is a platform for cybersecurity ratings designed to assess the cyber risk associated with a company’s third-party suppliers. At Pegasystems, a global technology company, Cybervadis is employed to evaluate the cybersecurity posture of our suppliers and partners. Through the assessment of cyber risk associated with our suppliers, Pegasystems can make well-informed decisions concerning the security and resilience of our supply chain.Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Pega’s Online Services may use social media features, such as ‘like’ or ‘share’ buttons (collectively, “Social Media Services”). Social Media Services may collect IP address, visited page details, and set a cookie or pixel to enable the feature to function properly. Social Media Services are either hosted by a third party or hosted directly on Pega’s Online Services. Your interactions with these features are governed by the privacy policy of the company providing the relevant Social Media Service.Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium You acknowledge that, as of the Effective Date of this agreement, Pega GenAI utilizes Microsoft’s Azure OpenAI Service. Client’s use of Pega GenAI shall comply with the terms of service from Microsoft (currently found at https://www.microsoft.com/licensing/terms/productoffering/MicrosoftAzure/MCA#ServiceSpecificTerms) and OpenAI (currently found at https://openai.com/policies/terms-of-use). In the future, Pegasystems may use additional Generative AI providers or may change third-party Generative AI providers. In either case, Pegasystems shall update the Subscription Documentation to indicate the new or updated Generative AI provider and the additional terms, if any, that may be applicable to Pega GenAI. Continued use of Pega GenAI shall serve as an acknowledgment from you to follow and be bound by such terms. Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow **Inclusive of AWS Bedrock, GCP Vertex, and Azure OpenAI Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow CyberGRX provides a cybersecurity platform designed to assist businesses in handling cyber risks related to third-party vendors. Pega leverages CyberGRX to streamline our vendor risk assessment process. With CyberGRX, Pega can assess the security posture of our third-party vendors, identify possible risks, and prioritize necessary mitigation measures.Captured 2026-06-08Open source →Finding permalink →
Tier differencesAll applicable tierslow *Digital Messaging, Co-Browse, and VoiceAI are not supported in Pega Cloud for Government Captured 2026-06-08Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.