Hi John,
SOC, IRAP and FEDRAMP are cloud specific, so you won't find anything for Db2 on-prem.
ITAR doesn't seem to be a security compliance or certification, rather a law that IBM needs to comply with. I don't have any information on that.
HIPAA - it's not something a software product can be certified against, as it involves organizational controls. However, I believe Db2 has the necessary technical controls that a company can successfully use Db2 in a HIPAA environment.
I hope that helps.
------------------------------
GREG STAGER
------------------------------