Adobe

SaaS / Software United States Website Reviewed Sept. 2, 2026

Creative Cloud, Document Cloud (Acrobat and Adobe Sign) and Experience Cloud - design, PDF and marketing software delivered as SaaS.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited third-party certification body Adobe cloud services covered by the Adobe Common Controls Framework Current
ISO/IEC 27018:2019 Accredited third-party certification body Protection of PII in public cloud for in-scope Adobe services Current
SOC 2 Type II Independent third-party auditor In-scope Adobe Document Cloud, Creative Cloud and Experience Cloud services; report available under NDA Current
PCI DSS Qualified Security Assessor Adobe commerce and payment processing environments Current
CSA STAR Cloud Security Alliance STAR registry entry / CAIQ for Adobe cloud services Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
GDPR 2016/679
Full
Adobe acts as processor under its DPA; SCCs and UK IDTA available
NIST Cybersecurity Framework
Partial
Adobe Common Controls Framework maps to NIST CSF
PCI DSS v4.0
Partial
PCI DSS scope limited to Adobe commerce and billing systems

Assess Adobe in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.