> ## Documentation Index
> Fetch the complete documentation index at: https://devzone.nayax.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Certifications

> Nayax's PCI DSS, ISO/IEC 27001, and SOC 2 Type 2 certifications, what each one means, and where to verify them.

Nayax maintains independently validated certifications for payment
security, information security management, and internal controls. This
page explains what each certification means and how you can verify it.

## PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is the security
standard maintained by the PCI Security Standards Council (PCI SSC) for
organizations that store, process, or transmit payment card data. The PCI
SSC does not issue certifications itself: compliance is validated through
an assessment by an accredited PCI Qualified Security Assessor (QSA), who
confirms the organization meets the standard's requirements and issues an
Attestation of Compliance.

You can view [Nayax's current PCI DSS v4.0.1 Attestation of Compliance](https://www.nayax.com/wp-content/uploads/2026/07/Nayax_PCI-SCC-v4.0.1-Certificate-of-compliance-by-nabu_30-June-2026_signed.pdf).

## ISO/IEC 27001

ISO/IEC 27001 is the international standard for an Information Security
Management System (ISMS). It sets requirements for establishing,
implementing, maintaining, and continually improving a risk-based approach
to protecting the confidentiality, integrity, and availability of
information. An accredited, independent certification body issues the
certificate after an audit. The certificate is valid for three years, and
the certification body carries out annual surveillance audits to confirm
the ISMS still meets the standard.

You can view [Nayax's current ISO/IEC 27001:2022 certificate](https://www.nayax.com/wp-content/uploads/2026/03/ISOIEC-270012022_2025-12-25.pdf).

## SOC 2 type 2

Nayax holds a SOC 2 Type 2 certification with no exceptions noted by the
auditor. SOC 2 (System and Organization Controls 2) is a reporting framework
maintained by the American Institute of Certified Public Accountants
(AICPA). Independent, licensed CPA auditors examine an organization's
controls against the framework and issue the report. A Type 2 report goes
further than a Type 1: instead of assessing controls at a single point in
time, it evaluates whether those controls operated effectively over an
extended audit period.

## See also

* [Privacy Policy](https://www.nayax.com/legal/nayax-general-privacy-policy/)
* [Terms of Service](/docs/get-started/terms-of-service)
