Book an Appointment

Trust Center: Self-Service Security Evidence

How to provide certificates, attestations, subprocessor lists and pentest summaries in a structured way – publicly where possible, NDA-protected where necessary.

Security reviews have become a fixture of B2B procurement: anyone buying software or managed services demands certificates, audit reports and information about subcontractors – driven by their own obligations under the GDPR, NIS2 and DORA. Without a central point of reference, vendors answer the same questions in ever new bespoke questionnaires, and confidential documents circulate uncontrolled by email. A trust center consolidates the evidence in one well-maintained place, tiers access by confidentiality and makes the maturity of the vendor's security organization verifiable. This article shows which content belongs in it, how NDA gating works and how the portal interlocks with security questionnaires.

The Essentials at a Glance

01

What a trust center is

A trust center is a central, usually publicly accessible portal through which a vendor provides its security and compliance evidence in a structured, self-service format – from certificates and audit reports to policy excerpts. Unlike a marketing page, it is aimed at scrutinizing third parties: at customers who, as controllers under Art. 28(3)(h) GDPR, may demand evidence and audits, and at procurement and security teams that must assess their direct suppliers under NIS2 (Art. 21(2)(d) of Directive (EU) 2022/2555). An established reference model is the Microsoft Service Trust Portal, which bundles audit reports from external auditors, pentest attestations and whitepapers – some freely accessible, some only after signing in and accepting a non-disclosure agreement.

02

What content belongs in it

The core consists of evidence from independent third parties: the ISO/IEC 27001 certificate, SOC 2 reports, the SOC 3 report – a summary version that may be distributed freely – and, in the German cloud market, the C5 attestation under ISAE 3000; with C5:2026, the BSI published an updated version of the catalogue in April 2026 with 168 criteria across 17 subject areas. Added to this are a well-maintained subprocessor list, summaries of recent penetration tests (management summary or attestation instead of the full report), the availability status or a link to the status page, and excerpts from key policies such as the information security policy. An entry in the public CSA STAR Registry complements this with a standardized self-assessment (CAIQ, Level 1) or an audited Level 2 credential (STAR Certification or Attestation).

03

Subprocessor list: the GDPR sets the pace

For the subprocessor list, Art. 28(2) GDPR sets the framework: further processors may only be engaged with the controller's specific or general written authorization; in the case of a general authorization, the processor must inform the controller of any intended addition or replacement, giving the controller the opportunity to object. Under Art. 28(4), the same data protection obligations must be passed on contractually to every further processor. A robust trust center list therefore states, for each subprocessor, the service provided, the processing location and the date of the last change – and offers a notification subscription that allows the duty to inform customers to be fulfilled verifiably. The details must match the data processing agreements exactly.

04

NDA gating: tiered access to confidential documents

Not every document belongs in the public domain: SOC 2 reports are restricted-use reports intended for a defined audience only, and full pentest reports or the Statement of Applicability give attackers needless insight. A tiered model has proven effective: certificates, SOC 3, policy excerpts and the availability status are freely accessible; after email verification come items such as DPA templates and detailed subprocessor information; behind a non-disclosure agreement sit SOC 2 and pentest reports as well as architecture documentation. Trust center platforms implement this with click-through NDAs and logged acceptance – Microsoft, for instance, requires sign-in with an organizational account and acceptance of a dedicated “Non-Disclosure Agreement for Compliance Materials” for its compliance materials. Access should be personal, time-limited and logged.

05

Benefits: fewer bespoke questionnaires, shorter review cycles

The value materializes in the procurement and sales process: prospects find standard evidence in self-service instead of requesting it individually, and security reviews start from a complete document set rather than a loop of follow-up questions – shortening review and thus sales cycles. A substantial share of bespoke security questionnaires can be pre-empted by published evidence and standardized self-assessments; the Cloud Security Alliance explicitly names reducing the burden of repeated vendor questionnaires as a purpose of the STAR Registry. At the same time, the portal is a signal of maturity: expired certificates or a neglected subprocessor list generate more follow-up questions there than trust.

06

Setup, maintenance and integration with security questionnaires

A trust center is not a one-off project but a maintained process with a clear owner – usually within the GRC or security team. Defined triggers keep the content current: recertifications and certificate expiry dates, new audit reports, completed penetration tests, and every subprocessor change sufficiently in advance of its effective date so that objection periods can run; versioning and approvals follow the document control of the ISMS. For integration with security questionnaires, the same curated knowledge base serves as the single source of truth: standard catalogues such as the CAIQ structure the answers, and where customers nevertheless send bespoke questionnaires, the answers reference the evidence stored in the trust center instead of releasing content individually all over again.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Microsoft Learn · 2026

Get started with the Microsoft Service Trust Portal

Documentation of the reference portal: audit reports from external auditors, pentest attestations, and the sign-in and NDA requirement for compliance materials and role-restricted documents.

AICPA & CIMA · o. J.

SOC 3 – SOC for Service Organizations: Trust Services Criteria for General Use Report

Establishes SOC 3 as a freely distributable general-use report, in contrast to the more detailed SOC 2 report, which may only be shared on a restricted basis.

Cloud Security Alliance · 2026

STAR Registry (Security, Trust, Assurance and Risk)

Public registry with CAIQ self-assessments (Level 1, to be updated annually) and audited Level 2 credentials (STAR Certification/Attestation) aimed at reducing repeated vendor questionnaires.

Amtsblatt der EU / EUR-Lex · 2016

Verordnung (EU) 2016/679 (DSGVO)

Art. 28(2)–(4) governs authorization, notification of changes and the right to object regarding further processors, as well as evidence and audit obligations.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Kriterienkatalog C5:2026

Current version of the cloud criteria catalogue (168 criteria across 17 subject areas); C5 attestations under ISAE 3000 are a common trust center credential in the German market.

Building a trust center or making yours review-ready?

We structure your evidence, define the NDA gating and connect the trust center with your questionnaire processes – happy to start with a no-obligation initial consultation.