Skip to content

Cloudflare encryption, keys & secrets security checks

Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.

On Cloudflare, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare connector needs.

Checks (9)

severity: critical SSL Encryption Disabled fix difficulty: easy #

Enable SSL/TLS encryption on the Cloudflare zone and set the mode to at least Full

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Overview
  3. Set the encryption mode to Full or Full (strict)
  4. Save changes and verify HTTPS is working

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: high SSL Mode Flexible fix difficulty: medium #

Upgrade Cloudflare SSL mode from Flexible to Full (strict) to encrypt origin traffic

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Overview
  3. Change the encryption mode from Flexible to Full (strict)
  4. Ensure your origin server has a valid SSL certificate installed
  5. Save changes and verify end-to-end HTTPS is working

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: high Always Use HTTPS Disabled fix difficulty: easy #

Enable Always Use HTTPS for the Cloudflare zone to redirect all HTTP traffic

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Edge Certificates
  3. Enable Always Use HTTPS

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: medium Automatic HTTPS Rewrites Disabled fix difficulty: easy #

Enable Automatic HTTPS Rewrites for the Cloudflare zone to fix mixed content issues

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Edge Certificates
  3. Enable Automatic HTTPS Rewrites

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: high HSTS Disabled fix difficulty: easy #

Enable HSTS on the Cloudflare zone with a max-age of at least 6 months

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Edge Certificates
  3. Scroll to HTTP Strict Transport Security (HSTS) and click Enable
  4. Configure max-age to at least 6 months and enable includeSubDomains

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: high Minimum TLS Version Weak fix difficulty: easy #

Set the Cloudflare zone minimum TLS version to 1.2 or higher

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Edge Certificates
  3. Set Minimum TLS Version to TLS 1.2 or higher

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: low Opportunistic Encryption Disabled fix difficulty: easy #

Enable Opportunistic Encryption for the Cloudflare zone

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Edge Certificates
  3. Enable Opportunistic Encryption

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC7.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: medium TLS 1.3 Disabled fix difficulty: easy #

Enable TLS 1.3 for the Cloudflare zone to improve security and performance

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Edge Certificates
  3. Enable TLS 1.3

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

severity: medium TLS Mode Not Strict fix difficulty: medium #

Set Cloudflare SSL/TLS encryption mode to Full (Strict) to verify origin certificates

  1. Log in to the Cloudflare Dashboard and select the zone
  2. Navigate to SSL/TLS > Overview
  3. Set the encryption mode to Full (Strict)
  4. Ensure a valid SSL certificate is installed on the origin server

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-5.1f.i GDPR (SaaS Security) GDPR-44.2 HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7

More Cloudflare checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial