Cryptocurrency August 26, 2026 07:30 AM

CoinMarketCap Secures SOC 1 and SOC 2 Type 1 Attestations, Confirms Dual ISO Certifications

Company publishes independent reports and maintains ISO 27001 and 27701 certifications as it expands enterprise and developer services

By Priya Menon
Share
Twitter Reddit Facebook LinkedIn

CoinMarketCap has completed independent SOC 2 Type 1 and SOC 1 Type 1 examinations of the controls protecting its market-data systems and has retained its dual ISO certifications for information security and privacy management. The reports and certifications cover the parts of the business that handle user and market information and are available to partners and clients on request.

CoinMarketCap Secures SOC 1 and SOC 2 Type 1 Attestations, Confirms Dual ISO Certifications
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • CoinMarketCap has completed SOC 2 Type 1 and SOC 1 Type 1 independent examinations of controls protecting its market-data systems.
  • The company holds dual ISO certifications: ISO/IEC 27001:2022 (certificate IS 838849) for information-security management and ISO/IEC 27701:2019 (certificate PM 838852) for privacy information management, both awarded by the British Standards Institution and maintained on a three-year cycle with annual surveillance audits.
  • The scope of the assessments covers price tracking, market-data feeds and APIs, cloud systems and operational processes, account management and PII handling, and iOS and Android applications; reports are available to partners and clients on request.

Kwai Chung, Hong Kong, August 26th, 2026

CoinMarketCap has obtained SOC 2 Type 1 attestation and completed a SOC 1 Type 1 examination following independent reviews of the controls that underpin its market data systems. The company said both reports supplement the international information-security and privacy certifications it already holds.

The SOC 2 Type 1 attestation was carried out in line with AICPA attestation standards and evaluates the design and implementation of controls against the applicable Trust Services Criteria for Security. The SOC 1 Type 1 examination covers controls relevant to internal control over financial reporting. Both reports are Type 1 engagements, meaning they describe controls as they existed at a specified date rather than assessing their operation over a period of time. CoinMarketCap said copies of the reports are available to partners and clients on request.


These SOC reports are additions to a dual ISO certification the company achieved in June 2026. CoinMarketCap is certified to ISO/IEC 27001:2022 for information security management under certificate IS 838849, and to ISO/IEC 27701:2019 for privacy information management under certificate PM 838852. Both certifications were independently assessed and issued by the British Standards Institution. The company said the certifications are maintained through a three-year certification cycle with annual surveillance audits, and that both certificates remain active.

The stated scope of the SOC and ISO assessments covers the parts of the business that process user and market information. That scope includes price tracking and the market-data feeds and APIs that distribute that information; the cloud systems and operational procedures that support those services; account management and handling of personally identifiable information (PII); and CoinMarketCap’s consumer applications on iOS and Android.

In explaining the rationale for publishing independent attestations and certifications, the company drew a distinction between security that is asserted by a vendor and security that has been independently evaluated and documented. CoinMarketCap noted its data is used upstream by a wide range of crypto infrastructure, supplying wallets, trading front-ends, research tools, and programmatic users such as AI agents. The company said procurement teams, compliance groups, and institutional counterparties usually rely on recognized frameworks and independent reports, and that SOC reports and ISO certificates are the credentials those teams are accustomed to reviewing.

The privacy program is governed by ISO/IEC 27701, which extends ISO 27001 and sets out how personal data is collected, processed, and protected. CoinMarketCap described ISO/IEC 27701 as designed to align with GDPR and other applicable global privacy regulations. The company emphasised that, for a platform with users across many jurisdictions, alignment with global privacy standards is as important as the underlying security controls themselves.

"Millions of people use CoinMarketCap to make decisions about their money," said Rush, CEO of CoinMarketCap. "Trust in that data should be demonstrated rather than claimed. Independent assessors have examined how we run security and privacy, and documented it in a form our partners and clients can review."

CoinMarketCap said it is continuing to scale its developer and enterprise offerings, including market-data APIs and products aimed at agents that consume data programmatically. The company described compliance credentials as increasingly a prerequisite in commercial discussions with institutional customers, noting that many institutional counterparties have obligations that require evidence of vendor controls. CoinMarketCap indicated it intends to maintain and broaden its assessment program over time.


Contact:

Marketing Manager: Min Park

Email: [email protected]

Risks

  • Type 1 SOC reports document controls as of a specified date rather than over a period of time, which limits their temporal coverage - this affects procurement and compliance teams relying on evidence of ongoing operational effectiveness (impacts enterprise procurement and institutional compliance functions).
  • The scope of the assessments is limited to the parts of the business that handle user and market information; other areas of the business are not described as covered by these reports (impacts counterparties and clients seeking comprehensive enterprise-wide assurances).
  • Maintaining ISO certifications relies on a three-year cycle with annual surveillance audits, meaning continued certification depends on passing periodic surveillance - lapses or audit findings could affect enterprise confidence (impacts enterprise customers and regulated institutional clients).

More from Cryptocurrency

Bernstein Predicts Bitcoin May Reach $300,000 by 2029 as Firm Frames Crypto as a Hedge Against Currency Debasement Aug 26, 2026 Bitcoin Pulls Back to Around $79,000 as Rally Pauses Ahead of U.S. Inflation Report Aug 26, 2026 Zerostack Says Crypto Treasury Totals $1.06 Billion, Trades Well Below Per-Share Crypto Value Aug 24, 2026 FlyEdge Launches Multilingual Public Preview for Airline Loyalty Tokenization on Aviation-Focused Chain Aug 24, 2026 Bitcoin grinds below critical resistance as momentum pauses Aug 24, 2026