Google Cloud Platform Services in Scope by Compliance Program

Last modified: May 11, 2026 | Previous Versions

Capitalized terms have the meaning stated in the applicable agreement between Customer or Partner and Google.

The following Services fall within the scope of one or more of: Google's ISO 27001 Certification, ISO 27017 Certification, ISO 27018 Certification, PCI DSS Certification, SOC 1 Report, SOC 2 Report and SOC 3 Report and Penetration Testing Report. A in the table below indicates that the Service (row) is in scope for the specified certification or report (column).

Service ISO 27001, 27017, 27018 Certifications SOC 1, 2, 3 Reports PCI DSS Certification Penetration Testing
Access Approval
Access Context Manager
Access Transparency
Advanced API Security
Agent Assist
AI Platform Deep Learning Container (ISO 27001 only)
AlloyDB
Anti-Money Laundering AI (ISO 27001 only)
API Gateway
Apigee
App Engine
App Hub (ISO 27001 only)
Application Integration
Artifact Analysis (ISO 27001 only)
Artifact Registry
Assured Workloads for Government
AutoML Tables
Backup for GKE
Bare Metal Solution
Bare Metal HSM (ISO 27001 only) (SOC 2 only)
Bare Metal Rack HSM (ISO 27001 only) (SOC 2 only)
Batch
BigQuery
BigQuery Data Transfer Service
Bigtable
Binary Authorization
Certificate Authority Service
Certificate Manager
Chrome Enterprise Premium
Cloud Asset Inventory
Cloud Billing
Cloud Build
Cloud CDN
Cloud Composer
Cloud Console Platform
Cloud Console App
Cloud Data Fusion
Cloud Deployment Manager
Cloud DNS
Cloud Endpoints
Cloud External Key Manager (Cloud EKM)
Cloud Filestore
Cloud Functions
Cloud Functions for Firebase
Cloud Healthcare
Cloud HSM
Cloud IDS
Cloud Interconnect
Cloud Key Management Service
Cloud Load Balancing
Cloud Logging
Cloud Monitoring
Cloud NAT (Network Address Translation)
Cloud Natural Language API
Cloud NGFW (ISO 27001 only)
Cloud Profiler
Cloud Router
Cloud Run
Cloud Scheduler
Cloud SDK
Cloud Shell
Cloud Source Repositories
Cloud Speaker ID
Cloud SQL
Cloud Storage
Cloud Storage for Firebase
Cloud Tasks
Cloud Trace
Cloud Translation
Cloud Vision
Cloud VPN
Cloud Workstations (ISO 27001 only)
Compute Engine
Config Connector
Config Controller (ISO 27001 only)
Config Sync
Connect
Container Registry
Conversational AI (formerly Contact Center AI)
Data Catalog
Database Center (ISO 27001 only)
Database Migration Service
Dataflow
Dataform (ISO 27001 only)
Dataplex
Dataproc
Dataproc Metastore
Datastore
DataStream
Dialogflow
Document AI
Document AI Warehouse
Earth Engine (ISO 27001 only)
Eventarc
Firebase App Check (ISO 27001 only)
Firebase AI Logic (ISO 27001 only)
Firebase App Distribution (ISO 27001 only)
Firebase Authentication
Firebase Cloud Messaging (ISO 27001 only)
Firebase Console (ISO 27001 only)
Firebase Crashlytics (ISO 27001 only)
Firebase Data Connect (ISO 27001 only)
Firebase Dynamic Links (ISO 27001 only)
Firebase Hosting
Firebase In-App Messaging (ISO 27001 only)
Firebase Machine Learning (ML) (ISO 27001 only)
Firebase Performance Monitoring (ISO 27001 only)
Firebase Realtime Database (ISO 27001 only)
Firebase Registry (ISO 27001 only)
Firebase Remote Config (ISO 27001 only)
Firebase Rules (ISO 27001 only)
Firebase Authentication
Firebase Test Lab
Firestore
GCVE
Gemini Enterprise (including Agentspace)
Gemini Code Assist
Gemini for Google Cloud
Gemini in BigQuery
Gemini in Firebase
Generative AI on Vertex AI
GKE Identity Service
GKE on AWS (ISO 27001 only)
GKE on Azure (ISO 27001 only)
Google Cloud Armor
Google Cloud Backup and DR
Google Cloud Contact Center as a Service (CCaaS)
Google Cloud Deploy
Google Cloud Identity-Aware Proxy
Google Cloud Marketplace
Google Cloud NetApp Volumes
Google Distributed Cloud connected (ISO 27001 only) (SOC 2 only)
Google Kubernetes Engine
Healthcare Data Engine (HDE)
Hub
Identity & Access Management (IAM)
Identity Platform
Conversational Insights
Key Access Justification (Access Sovereignty)
Knative serving
Looker (Google Cloud core)
Looker Studio
Managed Service for Apache Kafka (ISO 27001 only)
Managed Service for Microsoft Active Directory (AD)
Memorystore
Migrate to Virtual Machines
Migration Center
Model Armor
Network Connectivity Center
Network Intelligence Center
Network Service Tiers
NotebookLM for enterprise
Parallelstore (ISO 27001 only)
Persistent Disk
Personalized Service Health (ISO 27001 only)
Policy Controller
Privileged Access Manager (ISO 27001 only)
Pub/Sub
Ray on Vertex (ISO 27001 only)
reCAPTCHA Enterprise
Recommendations AI
Recommender
Resource Manager API
Retail Search
Risk Manager
SaaS Runtime (ISO 27001 only)
SecLM (ISO 27001 only)
Secret Manager
Secure Source Manager
Security Command Center
Sensitive Data Protection
Service Directory
Service Infrastructure
Spanner
Spectrum Access System
Speech-to-Text
Storage Transfer Service
Tables (ISO 27001 only)
Talent Solution
Text-to-Speech
Traffic Director
Transcoder API
Transfer Appliance (ISO 27001 only)
Vertex AI Colab Enterprise (ISO 27001 only)
Vertex AI Conversation
Vertex AI Platform
Vertex AI Search
Vertex AI Workbench Instances (ISO 27001 only)
Video Intelligence API
Virtual Private Cloud
VirusTotal (ISO 27001 only)
VPC Service Controls
Web Risk API
Workflows
Workload Manager
BigQuery Omni
Media CDN (ISO 27001 only)
Google Distributed Cloud Virtual (GDCV) for Bare Metal (ISO 27001 only)
Google Distributed Cloud Virtual (GDCV) for VMware (ISO 27001 only)
GKE Identity Service - Software (ISO 27001 only)
Binary Authorization – Software (ISO 27001 only)
Cloud Logging – Software (ISO 27001 only)
Cloud Monitoring – Software (ISO 27001 only)
Knative serving - Software (ISO 27001 only)
Config Connector - Software (ISO 27001 only)
Config Controller - Software (ISO 27001 only)
Config Sync - Software (ISO 27001 only)
Connect – Software (ISO 27001 only)
Migrate to Containers
Policy Controller - Software (ISO 27001 only)
Service Mesh – Software (ISO 27001 only)
Speech-to-Text On-Prem (ISO 27001 only)


Google Workspace and Cloud Identity Services in Scope by Compliance Program

Capitalized terms have the meaning stated in the applicable agreement between Customer and Google.

The following Services fall within the scope of one or more of: Google's ISO 27001 Certification, ISO 27017 Certification, ISO 27018 Certification, SOC 1 Report, SOC 2 Report and SOC 3 Report and Penetration Testing Report. A in the table below indicates that the Service (row) is in scope for the specified certification or report (column).

Service ISO 27001, 27017, 27018 Certifications SOC 1, 2, 3 Reports Penetration Testing
Admin Console
Alert Center API (ISO 27001 only)
Apps Email Audit API (ISO 27001 only)
Apps Script (ISO 27001 only)
AppSheet (SOC 2/3 only)
Assignments
Calendar
Calendar API (ISO 27001 only)
Classroom
Cloud Identity
Cloud Search
Contacts
Data Transfer API (ISO 27001 only)
Directory API (ISO 27001 only)
Docs
Domain Shared Contacts API (ISO 27001 only)
Drive
Drive Activity API (ISO 27001 only)
Drive Rest API (ISO 27001 only)
Enterprise License Manager (ISO 27001 only)
Forms
Gemini app
Gemini in Workspace
Gmail
Gmail Rest API (ISO 27001 only)
Google Chat
Google Meet
Google Workspace Migrate
Groups
Groups Migration API (ISO 27001 only)
Groups Settings API (ISO 27001 only)
Keep
Mobile Device Management
NotebookLM
People API (ISO 27001 only)
Read Along
Reports API (ISO 27001 only)
Reseller API (ISO 27001 only)
SAML-based SSO API (ISO 27001 only)
Service Mesh
Sheets
Sheets API (ISO 27001 only)
Sites
Slides
Tasks
Tasks API (ISO 27001 only)
Vault
Voice


Other Services in Scope by Compliance Program

Capitalized terms have the meaning stated in the applicable agreement between Customer or Partner and Google.

These Services fall within the scope of one or more of: Google's ISO 27001 Certification, ISO 27017 Certification, ISO 27018 Certification, SOC 1 Report, SOC 2 Report and SOC 3 Report and Penetration Testing Report. A in the table below indicates that the Service (row) is in scope for the specified certification or report (column).

Service ISO 27001, 27017, 27018 Certifications SOC 1, 2, 3 Reports PCI DSS Certification Penetration Testing
Looker (original)
Google SecOps - SIEM
Google SecOps - SOAR
GTI for Google Security Operations
Mandiant Consulting Services (SOC 2 and 3 only)
Mandiant Security Validation (SOC 2 and 3 only)
Mandiant Advantage Threat Intelligence (SOC 2 and 3 only)
Mandiant Attack Surface Management (SOC 2 and 3 only)
Mandiant Managed Services (SOC 2 and 3 only)
Google Threat Intelligence (ISO 27001 only)



Previous Versions