A Process That Never Ends
SUSE is committed to delivering best effort security to its customers and to the Open Source community. We believe that trust in Open Source Software, security in general, and the user's privacy in particular, are both indispensable and indefeasible. The Security Certifications and Security Solutions Teams continually work to certify all SUSE products, and develop security solutions to ensure the highest level of trust and reliability for our customers.
Latest News
-
SUSE receives USGv6 and IPv6 Ready Program certifications for SUSE Linux Enterprise Server 16 from the University of New Hampshire Interoperability Laboratory
04/09/2026 - SUSE Linux Enterprise Server (SLES) 16 has been certified by the University of New Hampshire Interoperability Laboratory (UNH-IOL) against the technical requirements of the USGv6-R1 profile and the IPv6 Readiness Program. Security-enhancing USGV6 compliance is a mandatory requirement for any new IT purchase by the United States Federal Government, and the deadline for transitioning 80% of all systems currently used by federal agencies and contractors from IPv4 to IPv6-only networks was in September 2025.
-
SUSE Linux Enterprise Server 15 SP4 is now Common Criteria EAL 4+ certified
02/24/2026 - SUSE Linux Enterprise Server 15 SP4 has received the Common Criteria EAL 4+certification from the BSI.
-
SUSE SLES 15 SP4 Common Criteria Protection Profile for Operating System Certified
02/24/2026 - SUSE Linux Enterprise Server 15 SP4 Protection Profile for the Operating System Protection Profile has been certified with the BSI scheme.
-
SUSE achieves Chinese Government Standard GB 18030-2022 certification
01/29/2026 - SUSE has once again achieved certification by the Chinese government for SUSE Linux Enterprise 16 for the GB 18030-2022 standards. This certification is the Chinese ideographic character set and encoding standard mandated by the Chinese government. It was updated in 2022 and supports the extended character support implemented August 1, 2023.
-
SUSE SLES 15 SP4 Common Criteria Protection Profile for Virtualization Certified
01/27/2026 - SUSE Linux Enterprise Server 15 SP4 Protection Profile for Virtualization has been certified with the BSI scheme.
-
SUSE receives USGv6 and IPv6 Ready Program certifications for SUSE Linux Micro 6.2 from the University of New Hampshire Interoperability Laboratory
01/26/2026 - SUSE Linux Micro 6.2 (SL Micro) has been certified by the University of New Hampshire Interoperability Laboratory (UNH-IOL) against the technical requirements of the USGv6-R1 profile and the IPv6 Readiness Program. Security-enhancing USGV6 compliance is a mandatory requirement for any new IT purchase by the United States Federal Government, and the deadline for transitioning 80% of all systems currently used by federal agencies and contractors from IPv4 to IPv6-only networks was in September 2025.
-
NIST FIPS 140-3 validation for the SUSE Linux Enterprise Server 15 SP6 OpenSSL 3 Cryptographic Module
11/26/2025 - SUSE has attained NIST FIPS 140-3 certification of our SUSE Linux Enterprise Server (SLES) 15 SP6 OpenSSL 3 Cryptographic Module.
-
SUSE Receives Renewed ISO 27001 and ISO 27701 Certifications
11/01/2025 - SUSE has successfully obtained renewed certifications for ISO 27001:2022 and ISO 27701:2019 from LRQA. These certifications reaffirm SUSE’s continued commitment to information security and privacy excellence.
The certifications demonstrate that SUSE’s Information Security Management System (ISMS) and Privacy Information Management System (PIMS) meet internationally recognized standards, providing our customers, partners, and employees with confidence that data is managed securely and responsibly.
You can download the renewed certifications using the link: ISO 27001 and ISO 27701
-
SUSE Transitions to New Certification Body LRQA and Upgrades Information Security Standards to ISO/IEC 27001:2022
06/03/2025 - SUSE has moved to a new certification authority LRQA Group Limited, and successfully completed the new version of ISO 27001:2022 and ISO 27701:2019 certification. These certifications serve as a testament to SUSE's ongoing dedication to excellence, providing our customers with the assurance that our practices meet the highest industry and compliance standards. To request the latest certificate please contact: cybersecurity@suse.com
-
NIST CMVP Process for FIPS Validation and Updates, Patches, and CVEs
02/07/2025 - NIST has updated their site outlining the process for handling updates, patches, and CVEs for certified modules. You can read their statement at: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/cmvp-flow in the section entitled "FIPS Validation and Updates, Patches, and CVEs".
-
SUSE receives SOC2 and SOC3 Certification
02/06/2025 - SUSE has attained SOC 2 and SOC 3 information security certification for both SUSE Corporate, as well as for Rancher Prime Hosted. The SOC 2 (Service Organization Control) Type 2 reports for SUSE Corporate and Rancher Prime Hosted provide a comprehensive assessment of SUSE's organizational security controls over the one-year audit period, and they demonstrate to our clients and partners that their data is being protected effectively and consistently. It also builds trust by proving SUSE has a defined set of security practices in place and operates them effectively. All of which are crucial for securing business deals, especially with large enterprises that require high data security standards, lowering risks, and identifying potential gaps that require additional or modified policies and procedures. SOC 2 reports are need-to-know basis and can be provide to our clients upon request. SOC 3 reports will be available online.
-
SUSE SLES 15 SP4 Common Criteria Certified
12/15/2023 - SUSE Linux Enterprise Server 15 SP4 is now Common Criteria certified with the BSI scheme. This guarantees that our operating system meets all the requirements of the NIAP Protection Profile General Purpose Operating System along with Functional Package for Secure Shell (SSH).