Don’t wait to get protected
Get a free consultation with a cybersecurity expert and see Barracuda's cybersecurity solutions in action.
SOC 2 reporting
SOC 2 reports are independent attestations governed by the American Institute of Certified Public Accountants (AICPA) that evaluate the design and operating effectiveness of controls which service organizations put in place to protect their assets. These reports are intended to meet the needs of a broad range of users that require detailed information and assurance about the controls at a service organization
ISO 27001
ISO/IEC 27001 is a security management standard that specifies security management best practices and comprehensive security controls following the ISO/IEC 27002 best practice guidance
ENS (high)
Esquema Nacional de Seguridad (ENS) specifies security requirements pertaining to service providers in which government agencies and public organizations in Spain are dependent on.
Barracuda’s ENS “High” certification can be verified on the ENS portal.
ENS Certification
FIPS validation
FIPS (Federal Information Processing Standards) are a ruleset that outline methods for how data is handled and processed by encryption algorithms
UK Cyber Essentials
UK Cyber Essentials specifies security requirements which are designed to protect organisations against the most common internet-based cyber threats
Barracuda’s UK Cyber Essentials Certification can be verified on the IASME portal.
ISO 27017 (certification in progress)
ISO/IEC 27017 specifies security requirements pertaining to cloud services, which supplement the requirements of the ISO/IEC 27001 and ISO/IEC 27002 standards
ISO 27018 (certification in progress)
ISO/IEC 27018 specifies security requirements pertaining to protection of personally identifiable information (PII) in public cloud services, which supplement the requirements of the ISO/IEC 27001 and ISO/IEC 27002 standards
ISO 42001 (certification in progress)
ISO/IEC 42001 specifies requirements pertaining to organizations who provide and/or utilize AI-based products or services, ensuring both responsible development and usage of AI systems
GovRAMP (authorization in progress)
GovRAMP specifies requirements for cloud service providers serving US State, Local, Education and Tribal (SLED) government organizations
Barracuda’s listing of authorized and progressing products can be verified on the GovRAMP portal.
PCI DSS (SAQ-D attestation in progress)
PCI DSS specifies requirements for organizations that process, store, or transmit payment card data
CICLON (certification in progress)
CICLON is Spain’s official cloud‑product cybersecurity evaluation methodology, created by the National Cryptologic Centre (CCN) to certify the security of SaaS, PaaS, and IaaS solutions deployed in cloud environments
CMMC (Level 1 self-assessment in progress)
Cybersecurity Maturity Model Certification (CMMC) specifies security requirements which are designed to protect controlled unclassified information and federal contract information that is shared by the US Department of Defense with its contractors and subcontractors
Barracuda’s CMMC Certification can be verified on the US Department of Defense SPRS (Supplier Performance Risk System)
| Product security advisories | Last updated |
|---|---|
|
September 21st, 2026
|
|
|
September 3rd, 2026
|
|
|
August 14th, 2026
|
|
|
May 8th, 2026
|
|
|
December 10th, 2025
|
|
|
September 1st, 2025
|
|
|
August 4th, 2025
|
|
|
January 4th, 2024
|
|
|
February 28th, 2023
|
|
|
October 31st, 2022
|
|
|
March 8th, 2022
|
|
|
December 12th, 2021
|
If Barracuda becomes aware of any security event that results in the loss, disclosure, or alteration of the Customer Data stored by Barracuda, (“Security Incident”), Barracuda will promptly (1) notify the relevant Customer of the Security Incident; (2) investigate the Security Incident; and (3) take reasonable steps to contain and mitigate the effects of the Security Incident.
Barracuda will notify the customer of relevant Security Incidents by a means selected by Barracuda, including via email. Customers must ensure that accurate administrator contact information appears on each applicable Cloud Services portal. Barracuda’s obligation to report or respond to a Security Incident under this section is not an acknowledgement by Barracuda of any fault or liability with respect to a Security Incident.
Customers should contact support to report any suspected or known misuse of its Barracuda accounts or authentication credentials, or any other security incident related to a Barracuda product or service.
Get a free consultation with a cybersecurity expert and see Barracuda's cybersecurity solutions in action.
Company Information
Our Websites