Compliance frameworks, security audits, and quality certifications this company maintains.
Gusto holds SOC 2 Type II certification covering its payroll processing, benefits administration, and HR data management systems that handle sensitive employee PII and financial data for 300,000+ small businesses.
Gusto's SOC 1 Type II attestation covers payroll processing controls relevant to employer financial reporting, required by accounting firms auditing Gusto's business clients who use Gusto for payroll disbursement.
Regulatory
IRS Authorized E-File Provider
CertifiedGusto is an IRS-authorized electronic filing provider, enabling Gusto to file W-2s, W-3s, 940s, and 941s directly with the IRS on behalf of all 300,000+ employer clients without requiring businesses to file separately.
Regulatory
State Licensed Insurance Broker
CertifiedGusto holds insurance broker licenses in all 50 US states, enabling Gusto Benefits to sell, enroll, and service health, dental, vision, and life insurance products for small business employers across the country.
Gusto complies with the California Consumer Privacy Act for the personal financial and HR data of California employees and employers processed through its payroll and benefits platform.
Regulatory
NACHA Certification
CertifiedGusto is NACHA-certified as an ACH originator, enabling it to initiate direct deposit payroll disbursements on behalf of 300,000+ employer clients without errors or compliance violations in ACH processing.
Regulatory
ERISA Compliance
CompliantGusto's 401(k) and FSA/HSA benefit administration complies with ERISA fiduciary standards, with Gusto acting as plan administrator and ensuring proper disclosure, contribution processing, and plan document maintenance.
Gusto is ISO 27001 certified, providing its embedded payroll partners and enterprise SMB clients with assurance that employee payroll and benefits data is protected under a systematic information security framework.
Gusto complies with the EU General Data Protection Regulation (GDPR) for its European operations and international data transfers, implementing appropriate data processing agreements and cross-border data transfer mechanisms for customers using Gusto with EU-based employees.
Gusto holds PCI DSS Level 1 certification for its payment card processing systems, ensuring that employer payroll and employee payment data processed through Gusto is protected to the highest standard required for large-volume card processors.