Security & Compliance Certifications

At Emmes Group, a leading technology-enabled Clinical Research Organization (CRO), we prioritize data security, compliance, and ethical technology use across all operations. Built on a strong foundation of trust and scientific integrity, our commitment to safeguarding client data is reflected in our certifications to international standards. Additionally, we are GDPR and HIPAA compliant, ensuring robust data protection and privacy across our global operations.

ISO

These certifications, issued by DNV (MGMT. SYS. RvA C 024), reinforce our dedication to secure cloud computing, clinical data privacy, and regulatory compliance in the life sciences sector. Emmes ensures that all technology-driven solutions meet the highest benchmarks for information governance, data protection, and risk management, particularly in the regulated environment of clinical research.

  • ISO ISO/IEC 27001:2022 – Information Security Management System (ISMS)
  • logo ISO/IEC 27018:2019 – Protection of Personal Data in the Cloud

FISMA

Emmes' Advantage eClinical Suite has been granted an independent agency Authority to Operate (ATO) by ISIT Consultants, Pvt. Ltd. under the Federal Information Security Modernization Act (FISMA), following the assessment against NIST SP 800-53 Rev. 5 (Moderate baseline) covering identification and access control, incident response, contingency planning, and system integrity, among other control families. This independent agency-level authorization is separate from, and precedes, the FedRAMP Marketplace authorization described below, which would extend reuse of that authorization to other federal agencies. Together, they reflect Emmes' commitment to protecting federally sponsored research data with the same rigor required of U.S. government systems.

FedRAMP

Our Advantage eClinical platform has achieved FedRAMP in progress status at the Moderate impact level, following an independent Readiness Assessment by an accredited Third-Party Assessment Organization (3PAO). This designation reflects that our cloud infrastructure, including encryption, identity verification, and continuous monitoring capabilities, meets FedRAMP's technical and procedural requirements at the readiness stage, as we progress toward full FedRAMP Authorization.