CoinMarketCap has obtained a SOC 2 Type 1 attestation report and completed a SOC 1 Type 1 examination, following independent assessments of the controls protecting the systems behind its market data. The announcement was made on August 26th, 2026 from Kwai Chung, Hong Kong.
The SOC 2 Type 1 report examines the design and implementation of controls against the applicable Trust Services Criteria for Security, while the SOC 1 Type 1 report covers controls relevant to internal control over financial reporting. Both Type 1 reports reflect controls as at a specified date rather than over a period of time and are available to partners and clients on request.
These reports add to the dual ISO certification CoinMarketCap obtained in June 2026. The company is certified to ISO/IEC 27001:2022 for information security management and ISO/IEC 27701:2019 for privacy information management, both independently assessed and awarded by the British Standards Institution. The certifications are maintained through a three-year cycle with annual surveillance audits.
The scope of the assessments covers price tracking, market data, APIs, cloud systems and operational processes, account management, personally identifiable information handling, and the CoinMarketCap applications on iOS and Android. The privacy certification is designed to align with GDPR and other global privacy regulations.
CoinMarketCap CEO Rush emphasized the importance of independent verification, saying: “Millions of people use CoinMarketCap to make decisions about their money. Trust in that data should be demonstrated rather than claimed. Independent assessors have examined how we run security and privacy, and documented it in a form our partners and clients can review.”
The company continues to expand its developer and enterprise business, including market data APIs and agent-facing products. Compliance credentials are increasingly a prerequisite for institutional clients whose own obligations require evidence of vendor controls. CoinMarketCap states that it intends to maintain and extend its assessment program over time.