Docusign

Legal & Compliance United States Website Reviewed Sept. 2, 2026

Electronic signature and agreement management: eSignature, CLM, Identify and Notary, with EU and UK qualified signature options.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 Accredited third-party certification body Docusign eSignature and supporting production infrastructure Current
ISO/IEC 27017:2015 and ISO/IEC 27018:2019 Accredited third-party certification body Cloud security controls and protection of PII in public cloud Current
SOC 1 Type II and SOC 2 Type II Independent third-party auditor Docusign eSignature and related services; reports available to customers under NDA Current
PCI DSS Qualified Security Assessor Docusign Payments and billing cardholder data environment Current
eIDAS Qualified Trust Service Provider EU/UK supervisory body via the Docusign QTSP Qualified electronic signatures and seals for EU and UK transactions Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
SOC 2 Type 2
Full
GDPR 2016/679
Full
Docusign acts as processor under its DPA; SCCs and UK IDTA available
PCI DSS v4.0
Full
PCI DSS applies to Docusign payment and billing systems
HIPAA Security
Partial
HIPAA BAA available on eligible Docusign plans

Assess Docusign in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.