Dun & Bradstreet · Trust Center

Dun And Bradstreet Trust Center

Trust center

Dun & Bradstreet publishes its security and compliance posture across a small set of public pages rather than a hosted trust-center product. There is no trust.dnb.com or security.dnb.com — both fail to resolve. The pages below are real, public and D&B-authored, and every certification recorded here is quoted from them.

Dun & Bradstreet maintains a public trust center documenting SOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, ISO/IEC 27701, ISO 22301, PCI DSS, SIG, HIPAA, and GDPR compliance.

Business DataCompany DataD-U-N-S NumberCreditRiskMaster DataData EnrichmentIdentity ResolutionComplianceSupply ChainSales IntelligenceMonitoring
Trust center: https://www.dnb.com/en-us/utilities/our-security.html

Certifications & Compliance

SOC 2 Type 2SOC 3ISO/IEC 27001:2022ISO/IEC 27701ISO 22301PCI DSSSIGHIPAAGDPR

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.dnb.com/en-us/utilities/our-security.html
url: https://www.dnb.com/en-us/utilities/our-security.html
description: >-
  Dun & Bradstreet publishes its security and compliance posture across a
  small set of public pages rather than a hosted trust-center product. There
  is no trust.dnb.com or security.dnb.com — both fail to resolve. The pages
  below are real, public and D&B-authored, and every certification recorded
  here is quoted from them.

pages:
  - name: Our Security
    url: https://www.dnb.com/en-us/utilities/our-security.html
    http_status: 200
    role: primary security posture page
  - name: Our Approach to Operational Resilience
    url: https://www.dnb.com/en-us/why-dnb/data-transparency/operational-resilience.html
    http_status: 200
    role: business continuity, DORA, ICT risk
  - name: Data Compliance at Dun & Bradstreet
    url: https://www.dnb.com/en-us/why-dnb/data-transparency/data-compliance.html
    http_status: 200
  - name: Our Data Transparency Commitment
    url: https://www.dnb.com/en-us/why-dnb/data-transparency.html
    http_status: 200
  - name: ISO Certifications
    url: https://www.dnb.com/en-us/utilities/ISO-certifications.html
    http_status: 200
  - name: Global Compliance & Ethics contacts
    url: https://www.dnb.com/en-us/why-dnb/data-transparency/contacts.html
    http_status: 200
  - name: ICT Risk and Digital Operational Resilience Position Statement (PDF)
    url: https://www.dnb.com/content/dam/web/company/about/content/irdor/DnB_ICT-Risk-and-Digital-Operational-Resilience-Position-Statement.pdf
  - name: Incident and Breach Response Policy Statement (PDF)
    url: https://www.dnb.com/content/dam/web/company/about/content/ibrp/DnB_Tier-1-CP-21-Incident-and-Breach-Response-Policy-Statement.pdf
    http_status: 200

certifications:
  - SOC 2 Type 2
  - SOC 3
  - ISO/IEC 27001:2022
  - ISO/IEC 27701
  - ISO 22301
  - PCI DSS
  - SIG
  - HIPAA
  - GDPR

certification_detail:
  - name: SOC 2 Type 2
    cadence: annual
    quote: >-
      "independent auditor certify a SOC2 Type 2 attestation annually,
      demonstrating operational effectiveness of controls (available under
      mutual NDA)"
    report_availability: under mutual NDA
  - name: ISO/IEC 27001:2022
    cadence: annual
    scope: multiple locations
    quote: >-
      "D&B also annually certifies to the ISO/IEC 27001:2022 Information
      Security Management Systems (ISMS) standard at multiple locations"
  - name: ISO/IEC 27701
    scope: markets where ISO 27001 is certified
    quote: >-
      "In markets in which they are certified as compliant with ISO 27001
      (Information Security Management Systems), they also hold an ISO 27701
      certification (Privacy Information Management Systems)"
  - name: PCI DSS
    cadence: annual
    quote: '"D&B annually undergoes PCI and SIG assessments"'
  - name: SIG
    cadence: annual
    quote: '"D&B annually undergoes PCI and SIG assessments"'

regulatory:
  - name: DORA (EU Digital Operational Resilience Act)
  - name: FTC Consent Order
  - name: GDPR

partner_requirements:
  url: https://www.dnb.com.hk/alliance-data-security-requirement
  note: >-
    D&B requires partners to maintain compliance with ISO 27001:2022 control
    requirements and to supply risk assessment and treatment reports within
    10 business days of a written request.

hosted_trust_center:
  exists: false
  probed:
    - {host: trust.dnb.com, result: does not resolve}
    - {host: security.dnb.com, result: does not resolve}

evidence:
  - source: https://www.dnb.com/en-us/utilities/our-security.html
    keywords: [soc2, iso/iec 27001, trust centre, gdpr]
    http_status: 200
  - source: https://www.dnb.com/en-us/why-dnb/data-transparency/operational-resilience.html
    keywords: [soc 2 type 2, iso 27001, iso 27701, iso 22301, pci, hipaa, dora]
    http_status: 200

absences:
  - No hosted trust center (no trust.dnb.com / Vanta / Drata style portal).
  - No downloadable attestation reports; SOC 2 is NDA-gated.
  - No certification scoped specifically to the Direct+ API.