dot CMS

SECURITY & COMPLIANCE

Enterprise Security You Can Verify

Protect your content, data, and infrastructure with security controls built across the dotCMS platform. Independently assessed security, privacy, and AI governance programs help organizations meet rigorous security and compliance requirements.

 

ISO/IEC 27001 · ISO/IEC 42001 · SOC 2 Type II · TX-RAMP Level II

image
  • ISO/IEC 42001:2023

    ISO/IEC 42001:2023 Certified

    AI governance, independently verified.

     

    dotCMS is certified to ISO/IEC 42001:2023, the international standard for AI management systems. The certification covers the governance and risk management practices applied to customer-facing dotAI capabilities and internal AI use.

     

    In dotCMS, an AI agent is another actor in the system: it works inside the same roles, permissions, and workflows as a person, and every change it makes stays traceable and reversible through version history.


  • TXRAMP

    TX-RAMP Level II

    Security requirements for Texas public-sector organizations.

     

    dotCMS is certified at TX-RAMP Level II, demonstrating that dotCMS Cloud meets the security requirements established for cloud service providers working with Texas state agencies and other eligible public-sector organizations.

  • SOC 2 Type II Certified

    SOC 2 Type II

    Security controls tested over time.

     

    dotCMS has completed a SOC 2 Type II examination. An independent CPA firm assessed dotCMS controls against the AICPA Trust Services Criteria for security, availability, and confidentiality and tested their operating effectiveness over time.

     

    The full report and auditor test results are available through the dotCMS Trust Center.

  • ISO/IEC 27001:2022

    ISO/IEC 27001:2022

    Information security managed to an international standard.

     

    dotCMS is ISO/IEC 27001:2022 certified, demonstrating that its information security management system follows internationally recognized requirements for managing security risks and protecting information across its cloud services and supporting operations.

  • CAIQ

    CAIQ

    Cloud security controls, documented and accessible.

    dotCMS maintains a completed Consensus Assessments Initiative Questionnaire (CAIQ) from the Cloud Security Alliance, providing customers and auditors with detailed information about its cloud security practices and controls.

Check which dotCMS deployment meets your infrastructure and security standards

dotCMS runs where your policy requires it to run, under the same certified governance model. dotCMS Cloud on AWS is one deployment option, not the only one. Meet infrastructure, security, and data-residency requirements without locking your content strategy into one deployment model.

dotCMS Cloud

dotCMS Cloud

Fully managed on dotCMS's AWS infrastructure, including monitoring, patches, and upgrades.

Read More about Read More
Cloud Anywhere

Cloud Anywhere

Fully managed by dotCMS on AWS, Azure, or GCP, with you contracting directly with your own cloud provider.

Read more about Read more
Self-hosted

Self-hosted

You own and control the infrastructure, whether for company policy or geographic requirements.

Read more about Read more

AUTHENTICATION AND ACCESS

How do authentication and role mapping work in dotCMS?

dotCMS authenticates against your identity provider and enforces authorization with its own roles and permissions.

SAML single sign-on

Configured through the SAML App in the Apps tool. dotCMS documents configuration for Okta, Azure AD, Google, Amazon, and Shibboleth.

Role mapping

 Identity-provider role names are mapped onto existing dotCMS roles, so access is governed by the roles your IdP already assigns.


Per-site configuration

A different SAML configuration can be specified for each site, or one configuration applied across all sites.

API tokens

REST API calls authenticate with JWT API tokens, and every call uses the permissions of the user the token was created for. Content returned by the REST API always respects dotCMS permissions.

Security & Privacy Policies

dotCMS has implemented a set of corporate policies to take maximum security measures for our clients and our company. These policies are reviewed periodically (at a minimum once per year) as part of our business continuity plan. dotCMS currently has the following security & privacy policies implemented:

  • Code of Conduct

  • Cryptography Policy

  • Data Classification Policy

  • Data Deletion Policy

  • Data Protection Policy

  • Disaster Recovery Plan

  • Incident Response Plan

  • Information Security Policy

  • Privacy policy

  • Cookie Policy

  • GDPR policy

  • Acceptable Use Policy

  • Asset Management Policy

  • Backup Policy

  • Business Continuity Plan

  • Change Management Policy

  • Password Policy

  • Physical Security Policy

  • Responsible Disclosure Policy

  • Risk Assessment Program

  • Security Questionnaires Policy

  • System Access Control Policy

  • Vendor Management Policy

  • Vulnerability Management Policy

  • Content Modeling Best Practices: How to Structure Content for Reuse Across Pages, Sites, and AI
    19 Aug 26
    Product

    Content Modeling Best Practices: How to Structure Content for Reuse Across Pages, Sites, and AI

    Learn content modeling best practices to structure entity-centric, reusable content for pages, multi-site and multi-channel delivery, and AI search.

  • Driving Content Innovation: Our 2026 Roadmap
    3 Mar 26

    Driving Content Innovation: Our 2026 Roadmap

    Join VP of Product Freddy Montes for a walk through of the exciting things dotCMS is working on in 2026

  • Content Style Editor: Visual Design Control Inside Your CMS
    20 Feb 26

    Content Style Editor: Visual Design Control Inside Your CMS

    Eliminate developer bottlenecks with the dotCMS Content Style Editor, empowering content teams to instantly customize component styling, improve content reuse, and accelerate publishing without code.

  • 8 Best Open Source Intranet Software in 2026
    28 Jan 26

    8 Best Open Source Intranet Software in 2026

    Looking for the best open source intranet software? Find the top 8 solutions for 2026 to boost productivity and collaboration in your workplace.

  • A UX-Driven Approach to Modernizing dotCMS
    15 Jan 26

    A UX-Driven Approach to Modernizing dotCMS

    Modernizing a CMS isn’t about fixing what’s broken, it’s about leading its evolution. In this post, we share how dotCMS is taking a UX-led approach to future-proof the platform, aligning usability, scalability, and long-term product strategy to support what’s next.

Explore dotCMS for your organization

image

dotCMS Named a Major Player

In the IDC MarketScape: Worldwide AI-Enabled Headless CMS 2025 Vendor Assessment

image

Explore an interactive tour

See how dotCMS empowers technical and content teams at compliance-led organizations.

image

Built for Compliance. Certified for AI.

dotCMS is ISO 27001 and ISO 42001 certified, pairing independently verified information security with governed, accountable AI.