Compliance frameworks, security audits, and quality certifications this company maintains.
DocuSign holds SOC 2 Type II certification covering security, availability, and confidentiality, providing the independent assurance that enterprise customers in financial services, healthcare, and government require before trusting DocuSign with agreement signing and storage.
DocuSign's global information security management system is ISO 27001 certified, ensuring that DocuSign's infrastructure protecting 1.6M customers' agreements and signatures meets internationally recognized security management standards.
Regulatory
FedRAMP Moderate
CertifiedDocuSign holds FedRAMP Moderate authorization, enabling US federal agencies to use DocuSign eSignature for electronically signing federal documents, contracts, and grants in compliance with US government cloud security requirements.
Regulatory
ESIGN Act Compliant
CompliantDocuSign eSignature complies with the US ESIGN Act and UETA, ensuring that all signatures captured through DocuSign are legally binding in US federal and state courts, a foundational compliance requirement for DocuSign's customer adoption.
DocuSign eSignature complies with EU eIDAS regulation, supporting Simple, Advanced, and Qualified Electronic Signatures (QES) required for DocuSign's customers operating in European Union member states with country-specific signature validity requirements.
DocuSign supports HIPAA-compliant agreement workflows through a Business Associate Agreement (BAA), enabling healthcare organizations to collect patient consent forms and execute clinical agreements through DocuSign while protecting protected health information.
DocuSign complies with GDPR for EU customer data, providing data processing agreements, EU data residency options, and right-to-erasure capabilities for the personal data of signers and administrators processed through DocuSign's European infrastructure.
DocuSign eSignature supports FDA 21 CFR Part 11 requirements for electronic records and signatures in life sciences, enabling pharmaceutical and medical device companies to use DocuSign for regulatory submissions and clinical trial documentation.
DocuSign's payment and billing infrastructure complies with PCI DSS standards, and DocuSign supports PCI-compliant agreement workflows for financial services customers processing cardholder agreements and consent documents.
DocuSign holds SOC 1 Type II certification for controls over financial reporting, required by financial services and audit firms that use DocuSign for executing audit engagement letters, financial contracts, and regulatory filings.