Kwai Chung, Hong Kong, August 26th, 2026
CoinMarketCap has obtained SOC 2 Type 1 attestation and completed a SOC 1 Type 1 examination following independent reviews of the controls that underpin its market data systems. The company said both reports supplement the international information-security and privacy certifications it already holds.
The SOC 2 Type 1 attestation was carried out in line with AICPA attestation standards and evaluates the design and implementation of controls against the applicable Trust Services Criteria for Security. The SOC 1 Type 1 examination covers controls relevant to internal control over financial reporting. Both reports are Type 1 engagements, meaning they describe controls as they existed at a specified date rather than assessing their operation over a period of time. CoinMarketCap said copies of the reports are available to partners and clients on request.
These SOC reports are additions to a dual ISO certification the company achieved in June 2026. CoinMarketCap is certified to ISO/IEC 27001:2022 for information security management under certificate IS 838849, and to ISO/IEC 27701:2019 for privacy information management under certificate PM 838852. Both certifications were independently assessed and issued by the British Standards Institution. The company said the certifications are maintained through a three-year certification cycle with annual surveillance audits, and that both certificates remain active.
The stated scope of the SOC and ISO assessments covers the parts of the business that process user and market information. That scope includes price tracking and the market-data feeds and APIs that distribute that information; the cloud systems and operational procedures that support those services; account management and handling of personally identifiable information (PII); and CoinMarketCap’s consumer applications on iOS and Android.
In explaining the rationale for publishing independent attestations and certifications, the company drew a distinction between security that is asserted by a vendor and security that has been independently evaluated and documented. CoinMarketCap noted its data is used upstream by a wide range of crypto infrastructure, supplying wallets, trading front-ends, research tools, and programmatic users such as AI agents. The company said procurement teams, compliance groups, and institutional counterparties usually rely on recognized frameworks and independent reports, and that SOC reports and ISO certificates are the credentials those teams are accustomed to reviewing.
The privacy program is governed by ISO/IEC 27701, which extends ISO 27001 and sets out how personal data is collected, processed, and protected. CoinMarketCap described ISO/IEC 27701 as designed to align with GDPR and other applicable global privacy regulations. The company emphasised that, for a platform with users across many jurisdictions, alignment with global privacy standards is as important as the underlying security controls themselves.
"Millions of people use CoinMarketCap to make decisions about their money," said Rush, CEO of CoinMarketCap. "Trust in that data should be demonstrated rather than claimed. Independent assessors have examined how we run security and privacy, and documented it in a form our partners and clients can review."
CoinMarketCap said it is continuing to scale its developer and enterprise offerings, including market-data APIs and products aimed at agents that consume data programmatically. The company described compliance credentials as increasingly a prerequisite in commercial discussions with institutional customers, noting that many institutional counterparties have obligations that require evidence of vendor controls. CoinMarketCap indicated it intends to maintain and broaden its assessment program over time.
Contact:
Marketing Manager: Min Park
Email: [email protected]