Q39
Are you PCI DSS compliant? At what level?
Webex Contact Center and Enterprise are PCI DSS v4.0.1 compliant; Webex Calling maintains PCI DSS v3.2.1 self-attestation of compliance.
ThirdProof independently checks public intelligence sources to show what your team can verify about Webex before Webex sends a questionnaire or a security document.
Webex's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Webex — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Webex's own trust page.
✓ FedRAMP Certified — Class C (Moderate) Checked August 2026.
Webex for Government (Cisco) is FedRAMP Certified at Class C (Moderate) via the Agency path (package F1511207635). Commercial Webex is a separate offering.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 25 returning usable evidence. The Webex assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Webex Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 51% of a 133-question vendor security questionnaire — without waiting for Webex. The remaining 65 are listed as open, so the follow-up you send is short and specific.
Q39
Webex Contact Center and Enterprise are PCI DSS v4.0.1 compliant; Webex Calling maintains PCI DSS v3.2.1 self-attestation of compliance.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Cisco Webex has signed Data Processing Agreements (DPAs) available and supports GDPR through data protection and privacy mechanisms.
Q40
Cisco Webex signs a standard BAA with covered entities and business associates, and is HIPAA compliant when a BAA is in place.
Q23
Webex encrypts data at rest and in transit using AES-256-GCM cipher for both messaging content and meeting recordings.
+ 63 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Narrative analysis for Webex
Webex is a mature, established collaboration platform owned by Cisco with a 27-year domain history and significant enterprise adoption.
The vendor demonstrates strong security fundamentals: ISO 27001 certification, SOC 2 Type II claims, comprehensive encryption (AES-256-GCM for data at rest and in transit), multi-factor authentication support, and an explicit commitment to not training AI models on customer data. Infrastructure exposure is minimal (2 open ports: 80, 443), domain reputation is clean across threat intelligence databases, and the vendor maintains documented incident response procedures with 72-hour breach notification compliance.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from external data sources without vendor participation or input.
2 findings identified for Webex
Historical media archives document a pattern of security incidents affecting Webex deployments between April and July 2026. Three high-severity articles reference critical vulnerabilities requiring patches, trojanzed application installers distributing Starland RAT malware, and fake Webex downloads used in malware distribution campaigns. …
Webex.com appears in 45 threat intelligence pulses on the OpenThreat Exchange. This high pulse count is typical for large, public-facing infrastructure providers and does not indicate direct risk from Webex itself. …
Evidence that positively supports Webex's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →Webex complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent Webex? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Webex assessment above is already written; ask for it and it lands in your inbox.