We've Expanded Our ISO Certifications
Security and compliance have never been box-checking exercises at OKX. We believe that both are continuous commitments to our customers' online security and privacy. As digital assets become an increasingly important part of the global financial system, our customers, partners and regulators rightly expect the same level of governance, operational discipline and independent assurance found across the world's leading financial institutions.
Last year, we announced that OKX had achieved ISO/IEC 27001:2022 certification and CSA STAR Level 1 certification, validating our Information Security Management System (ISMS) against internationally recognized standards. Today, we're pleased to share another important step in that journey.
Our Operating Service & Support Hub has now been certified to ISO/IEC 27001, while also achieving first-time certification to ISO/IEC 27017 for cloud security controls and ISO/IEC 27018 for the protection of personally identifiable information (PII) in the cloud. All three certifications were independently assessed by BSI Group, one of the world's leading certification bodies, and became effective on 14 April 2026.
Extending internationally recognized security standards to a critical customer function
OKX's Operating Service & Support Hub sits at the heart of our day-to-day operations. It supports customers around the world, processes sensitive customer information and plays an important role in delivering the secure, reliable experience users expect from OKX.
Extending our ISO/IEC 27001 certification to cover these operations demonstrates that the systems, processes and controls governing this critical function meet internationally recognized best practices for information security management.
For our customers, partners and regulators, that means greater confidence that the people, processes and technologies supporting these services operate within a well-governed, independently verified security framework.
Why ISO/IEC 27017 and ISO/IEC 27018 matter
As a global digital asset platform operating 24 hours a day, OKX relies on cloud infrastructure to support everything from customer onboarding and identity verification to trading, wallet services and operational support.
Cloud security and privacy are therefore not standalone technical considerations—they are fundamental to how we operate.
ISO/IEC 27017 provides internationally recognized guidance on securing cloud environments. It validates the controls governing areas such as cloud access management, monitoring, operational responsibilities and the secure operation of cloud workloads.
ISO/IEC 27018 complements this by focusing specifically on the protection of personally identifiable information stored and processed in cloud environments. It establishes internationally recognized practices for how personal data is collected, managed, protected and disclosed, reinforcing our commitment to safeguarding customer information throughout its lifecycle.
Together with ISO/IEC 27001, these certifications provide independent assurance that both our cloud infrastructure and the personal information entrusted to us are managed according to globally recognized security and privacy standards.
Independent assurance through rigorous assessment
Achieving internationally recognized certifications requires far more than implementing technical controls. Each certification involves a comprehensive independent assessment of governance, operational processes, risk management, documentation and day-to-day security practices.
Our certifications were awarded following a rigorous audit conducted by BSI Group, providing external validation that the controls supporting our Operating Service & Support Hub align with internationally recognized best practices.
Independent certification is an important part of how we demonstrate accountability to customers, our institutional partners and regulators around the world.
Part of a broader commitment to security and compliance
These certifications build on the broader security and compliance programme that underpins OKX's global operations.
Our approach combines internationally recognized management systems with continuous investment in cybersecurity, operational resilience, financial crime controls, privacy and governance. Alongside independent certifications, we continue to strengthen our security architecture through initiatives such as Proof of Reserves, robust risk management frameworks, ongoing monitoring and regular third-party assurance.
Security is not something we view as a competitive differentiator alone - it is a foundational requirement for building long-term trust in digital financial markets.
Building trust as we continue to grow
As the digital asset industry matures, customers increasingly expect the same levels of security, governance and operational resilience they experience across traditional financial services.
Expanding our ISO certification programme reflects our continued investment in meeting - and exceeding - those expectations.
By extending ISO/IEC 27001 to our Operating Service & Support Hub and achieving new certifications under ISO/IEC 27017 and ISO/IEC 27018, we are reinforcing our commitment to operating a secure, trusted and well-governed platform for customers around the world.
As OKX continues to grow globally, we remain committed to continuously strengthening the systems, controls and independent assurance that help our customers trade with confidence. Our ISO certification now spans our licensed entities across Singapore, the United Arab Emirates, the Bahamas, the United States, Turkey, and Malta, delivering consistent, independently verified security assurance to customers and regulators in each of these markets.
Digital Assets subject to volatility and not insured. Not financial/investment advice. Not all products and services offered in all regions. Exclusions and T&Cs apply.
© 2026 OKX. This article may be reproduced or distributed in its entirety, or excerpts of 100 words or less of this article may be used, provided such use is non-commercial. Any reproduction or distribution of the entire article must also prominently state: “This article is © 2026 OKX and is used with permission.” Permitted excerpts must cite to the name of the article and include attribution, for example “Article Name, [author name if applicable], © 2026 OKX.” Some content may be generated or assisted by artificial intelligence (AI) tools. No derivative works or other uses of this article are permitted.





