Q39
Are you PCI DSS compliant? At what level?
Webex Contact Center and Enterprise are PCI DSS v4.0.1 compliant; Webex Calling maintains PCI DSS v3.2.1 self-attestation of compliance.
ThirdProof independently checks public intelligence sources to show what your team can verify about Webex before Webex sends a questionnaire or a security document.
Webex's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Webex — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Webex's own trust page.
✓ FedRAMP Certified — Class C (Moderate) Checked August 2026.
Webex for Government (Cisco) is FedRAMP Certified at Class C (Moderate) via the Agency path (package F1511207635). Commercial Webex is a separate offering.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 25 returning usable evidence. The Webex assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Webex Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 51% of a 133-question vendor security questionnaire — without waiting for Webex. The remaining 65 are listed as open, so the follow-up you send is short and specific.
Q39
Webex Contact Center and Enterprise are PCI DSS v4.0.1 compliant; Webex Calling maintains PCI DSS v3.2.1 self-attestation of compliance.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Cisco Webex has signed Data Processing Agreements (DPAs) available and supports GDPR through data protection and privacy mechanisms.
Q40
Cisco Webex signs a standard BAA with covered entities and business associates, and is HIPAA compliant when a BAA is in place.
Q23
Webex encrypts data at rest and in transit using AES-256-GCM cipher for both messaging content and meeting recordings.
+ 63 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Webex for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Webex
Webex is a mature, established collaboration platform owned by Cisco with a 27-year domain history and significant enterprise adoption.
The vendor demonstrates strong security fundamentals: ISO 27001 certification, SOC 2 Type II claims, comprehensive encryption (AES-256-GCM for data at rest and in transit), multi-factor authentication support, and an explicit commitment to not training AI models on customer data. Infrastructure exposure is minimal (2 open ports: 80, 443), domain reputation is clean across threat intelligence databases, and the vendor maintains documented incident response procedures with 72-hour breach notification compliance.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from external data sources without vendor participation or input.
2 findings identified for Webex
Historical media archives document a pattern of security incidents affecting Webex deployments between April and July 2026. Three high-severity articles reference critical vulnerabilities requiring patches, trojanzed application installers distributing Starland RAT malware, and fake Webex downloads used in malware distribution campaigns. …
Webex.com appears in 45 threat intelligence pulses on the OpenThreat Exchange. This high pulse count is typical for large, public-facing infrastructure providers and does not indicate direct risk from Webex itself. …
Evidence that positively supports Webex's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →No SEC Enforcement Filings Found
SEC Filing Search →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Clean IP Reputation
IP Reputation →Webex complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent Webex? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Webex assessment above is already written; ask for it and it lands in your inbox.