Compliance frameworks, security audits, and quality certifications this company maintains.
Smartsheet maintains SOC 2 Type II certification covering security, availability, and confidentiality, providing enterprise customers in regulated industries with independent assurance that their project and work data is protected within Smartsheet's cloud infrastructure.
Smartsheet holds ISO 27001 certification for its information security management system, covering the cloud platform that hosts work management data for 90%+ of the Fortune 100 and government agencies across 190 countries.
Smartsheet holds FedRAMP Moderate authorization, enabling U.S. federal agencies including the Department of Defense and civilian agencies to use Smartsheet for program management and project tracking within government security requirements.
Smartsheet is GDPR compliant with EU data residency options, data processing agreements, and employee data handling controls that enable European enterprise customers to use Smartsheet for HR project management and workforce planning.
Smartsheet supports HIPAA-compliant deployments for healthcare organizations, with Business Associate Agreements and audit logging controls allowing hospitals and health systems to manage patient-adjacent project workflows within the platform.
Smartsheet supports CCPA compliance for California enterprises by providing data subject request workflows, data deletion capabilities, and privacy controls for user data stored within Smartsheet sheets and dashboards.
Smartsheet is ISO 27017 certified for cloud security controls, giving enterprise IT teams assurance that its shared-responsibility security model for work management data meets internationally recognized cloud provider standards.
Smartsheet's platform and mobile applications conform to WCAG 2.1 AA accessibility standards, enabling government agencies and enterprises with disability inclusion requirements to deploy Smartsheet as an accessible work management tool.
Smartsheet holds CSA STAR Level 2 certification for its cloud work management infrastructure, demonstrating third-party validated security controls for the multi-tenant SaaS environment that stores enterprise project and program data.
Regulatory
ITAR Compliance Support
CompliantSmartsheet supports ITAR compliance for defense contractors using the platform to manage export-controlled project workflows, with access controls, audit trails, and US-only data residency options for sensitive government contract management.