TrustArc APEC Privacy Recognition for Processors (PRP) Certification
Certification under the APEC Privacy Framework for data processors, independently assessed by TrustArc and recognised across APEC member economies.
TISAX
ENX-governed automotive industry information security assessment required across the supply chain. Applies to Adobe San Jose and Dublin office locations.
ISO 32000-2:2020 (PDF Standard)
ISO standard defining the PDF file format, ensuring interoperability, long-term preservation, and consistent rendering of PDF documents.
KY3P (Know Your Third Party) Assessment
Third-party risk assessment program used by financial institutions to evaluate vendor security controls and data protection practices.
CSA STAR Level 2
Third-party certification against the Cloud Security Alliance Cloud Controls Matrix, building on ISO 27001. Results published on the CSA STAR public registry.
ISO 9001:2015
International standard for quality management systems, certifying consistent processes, customer satisfaction, and continual service improvement.
ISO 27018:2019
Code of practice for public cloud PII processors covering transparency, purpose limitation, and customer control over personal data.
ISO 27017:2015
Code of practice adding cloud-specific security controls for cloud service providers and customers, assessed as an extension to ISO 27001.
ISO 27001:2022
International standard for information security management systems (ISMS). Certified by an accredited third party on a three-year cycle with annual surveillance audits.
ISO 22301:2019
International standard for business continuity management, independently certifying the ability to plan for, respond to, and recover from disruption.
ISO 14289-1:2014 (PDF/UA)
ISO standard for universally accessible PDF files, specifying requirements enabling reliable reading by assistive technology such as screen readers.
WCAG 2.2 Level AA
W3C Web Content Accessibility Guidelines v2.2 at Level AA, the internationally recognised benchmark for accessible digital content and interfaces.
Adobe Compliance Certifications, Standards, and Regulations
We comply with industry standards and regulations to help keep your data safe.
Completed certifications and attestations
Learn more about the specific compliance attestations for each Adobe product and service. All these attestations have been certified by third-party auditors.
Last Updated: September 22, 2026
Frequently asked questions
What is a SOC 1 report?
A SOC 1 report is a report issued by an independent CPA firm under AICPA standards, covering controls that could affect customers' financial reporting. It is designed for customers' finance teams and their financial statement auditors.
How do I get a copy of the report?
SOC 1 reports contain confidential detail and are shared with customers under NDA on request through your Adobe account team.
How often is the report issued?
The report is issued annually, covering the audit period stated in the report.
What is a SOC 2 report?
A SOC 2 report is an attestation report issued by an independent CPA firm. A Type II report tests whether controls operated effectively over a period, usually twelve months, rather than at a single point in time.
What is the difference between SOC 1, SOC 2, and SOC 3?
SOC 1 covers controls relevant to financial reporting. SOC 2 covers the Trust Services Criteria in detail and is shared under NDA. SOC 3 is a public summary of the SOC 2 examination.
How do I get a copy of the report?
SOC 2 reports are shared with customers under NDA on request through your Adobe account team.
Does a SOC 2 report make my organization compliant? A SOC 2 report provides independent assurance over the service provider's controls. Customers remain responsible for their own controls, configurations, and use of the service.
What does the HIPAA mapping add?
The independent auditor tests additional criteria mapped to HIPAA Security Rule safeguards alongside the standard Trust Services Criteria.
Is there such a thing as HIPAA certification?
No. There is no official HIPAA certification scheme. This report demonstrates independent testing of controls mapped to HIPAA requirements.
Do I still need a Business Associate Agreement?
Yes. Customers handling PHI should have a BAA in place. The report supports the relationship but does not replace the agreement.
What is a SOC 3 report?
A SOC 3 report is a short, general-use report based on the same examination as SOC 2. It states the auditor's opinion without detailed control descriptions or test results.
How do I get it?
SOC 3 reports are intended for public distribution and can be downloaded without an NDA.
What is ISO 27001?
ISO 27001 is the leading international standard for managing information security through a risk-based management system, certified by an accredited third party with annual surveillance audits on a three-year cycle.
What does Enterprise scope mean?
Enterprise scope means that the certification covers the organization-wide ISMS rather than an individual product.
How can I verify the certificate?
Certificates can be downloaded from the Trust Center or verified through the certification body's public register.
What is ISO 27017?
ISO 27017 is a code of practice adding cloud-specific guidance and controls for cloud service providers and customers, assessed alongside the ISO 27001 certification.
Why does it matter for cloud customers?
It matters for cloud customers because it demonstrates that cloud-specific risks, such as shared responsibility and virtual environment separation, are explicitly addressed.
What is ISO 27018?
ISO 27018 is a code of practice for public cloud providers acting as PII processors, covering commitments such as transparency, purpose limitation, and customer control over personal data.
How does it relate to privacy law?
It supports privacy compliance programs such as GDPR by evidencing recognized PII handling practices, but it is not itself a legal compliance certification.
What is ISO 22301?
ISO 22301 is a certifiable standard showing the organization can plan for, respond to, and recover from disruption to keep services running.
What does this tell me as a customer?
It tells you that the continuity and disaster recovery arrangements are independently certified, supporting service resilience commitments.
What is ISO 9001?
ISO 9001 is a certifiable standard for quality management, focused on consistent processes, customer satisfaction, and continual improvement.
Is it security related?
Not directly. It certifies quality management practices that underpin reliable and consistent service delivery.
What is SSPA?
SSPA is Microsoft's program requiring suppliers to meet its Data Protection Requirements and attest annually, with independent assessment where Microsoft requires it.
Who does this matter to?
This matters primarily to Microsoft as the customer. Inclusion shows the listed services meet Microsoft's supplier data protection requirements.
What is CSA STAR Level 2?
CSA STAR Level 2 is a Cloud Security Alliance program combining independent certification with the Cloud Controls Matrix (CCM), building on ISO 27001 or SOC 2.
How is Level 2 different from Level 1?
Level 1 is a published self-assessment; Level 2 adds independent third-party assessment.
How can I verify it?
Entries are published on the CSA STAR public registry.
What is BSI C5?
BSI C5 is an attestation under ISAE 3000 against the C5 criteria catalogue published by Germany's Federal Office for Information Security (BSI). It is widely required by German public sector and regulated customers.
Is C5 only relevant in Germany?
It originated in Germany and is strongest there, but it is increasingly recognized across Europe as a rigorous cloud assurance baseline.
How do I get the report?
C5 attestation reports are shared with customers on request, typically under NDA.
What is TISAX?
TISAX is the Trusted Information Security Assessment Exchange, governed by the ENX Association. It is the standard security assessment required across the automotive supply chain.
What are the assessment levels?
AL1 is a self-assessment, AL2 is a plausibility check by an approved audit provider, and AL3 is a full on-site audit for very high protection needs.
Is there a certificate?
TISAX issues labels rather than certificates. Results are shared with participants through the ENX portal and are valid for three years.
Who asks for TISAX?
Vehicle manufacturers and their suppliers ask for TISAX before exchanging sensitive information such as prototype or development data.
Which products are in scope?
Adobe-wide Security is in scope. Does not apply to Adobe Acrobat Sign for Government. TISAX applies to Adobe’s San Jose and Dublin office locations only.
What is ENS?
ENS is the Esquema Nacional de Seguridad, mandatory for Spanish public sector bodies and the private suppliers serving them.
What are the ENS categories?
The ENS categories are Basic, Medium, and High, based on the impact a security incident would have on the services and information handled.
How is conformity shown?
Conformity is shown through a certificate of conformity issued by an accredited body for Medium and High category, displayed with the official ENS mark.
What is the KFSI CSP checklist?
The KFSI CSP checklist is a structured self-assessment aligned to guidance from Korea's Financial Security Institute, used by Korean financial institutions when reviewing cloud services under local regulations.
Is it a certification?
No. It is a self-assessment that supports the customer's own regulatory review.
What is ISMAP?
ISMAP is the Information system Security Management and Assessment Program, Japan's scheme for assessing and registering cloud services for government use.
Why does ISMAP matter?
ISMAP matters because Japanese government bodies are expected to procure from the ISMAP registered list, so registration opens the Japanese public sector market.
How often is it renewed?
Registration is reviewed annually, which is why it is tracked by fiscal year.
How can I verify it?
You can verify it on the public ISMAP cloud service registration list.
What is Aadhaar eSign?
Aadhaar eSign is a legally recognized electronic signature in India where the signer authenticates with their Aadhaar identity and an OTP or biometric, under the Information Technology Act.
Who oversees the framework?
India's Controller of Certifying Authorities (CCA) oversees the framework, with eSign services delivered through empanelled providers.
What is IRAP Protected?
IRAP Protected is the Information Security Registered Assessors Program, run by the Australian Signals Directorate. An endorsed IRAP assessor evaluates the service against the Australian Government ISM.
Is IRAP a certification?
No. It is an independent assessment report. Each Australian agency makes its own risk-based authorization decision using the report.
What classification level is covered?
The listed services are assessed at PROTECTED level.
How do agencies get the report?
IRAP reports are shared with Australian government customers on request, typically under NDA.
What is TPN Blue Shield?
TPN Blue Shield is a completed self-assessment on the Trusted Partner Network platform against the industry's content security best practices, based on the Motion Picture Association guidelines.
How is Blue Shield different from Gold Shield?
Blue Shield is a self-assessment; Gold Shield adds an independent assessment by a TPN-accredited assessor.
Who relies on this?
Major studios and content owners rely on TPN Blue Shield when deciding whether a vendor can handle pre-release content.
What is a PCI DSS ROC?
A PCI DSS ROC is a report on Compliance produced by a Qualified Security Assessor (QSA) after a full assessment of services that store, process, or transmit payment card data.
What evidence can customers get?
Customers can get an Attestation of Compliance (AOC) summarizing the assessment is available to customers on request. Additionally, a responsibility matrix maybe requested for roles and responsibilities.
What changed in v4.0?
PCI DSS v4.0 replaced v3.2.1 with stronger control requirements, targeted risk analysis and more flexible customized approaches.
How often is it assessed?
Annually.
What is SAQ-D?
SAQ-D is the most comprehensive PCI DSS Self-Assessment Questionnaire, used by eligible entities to formally self-attest against the full set of applicable requirements.
How does an SAQ differ from a ROC?
A ROC is an independent assessment by a QSA; an SAQ is a formal self-attestation signed by the entity.
What is FedRAMP Class B?
FedRAMP Class B is a tailored FedRAMP baseline for Class B services that do not store sensitive federal data beyond basic login information, assessed by an accredited Third Party Assessment Organization (3PAO).
How can agencies verify it?
Agencies can verify it on the FedRAMP Marketplace and access of System Security Plan via Connect.gov.
What is FedRAMP Moderate?
FedRAMP Moderate is an authorization against the FedRAMP Class C baseline, which draws on several hundred NIST SP 800-53 controls and covers the majority of unclassified federal data.
What happens after authorization?
Continuous monitoring obligations apply, including regular scanning, reporting and annual assessment.
How can agencies verify it?
Agencies can verify it on the FedRAMP Marketplace and access of System Security Plan via Connect.gov.
What is CJIS?
CJIS is the FBI's security policy governing how criminal justice information (CJI) is protected. It applies where services handle CJI for US law enforcement agencies.
Is there a CJIS certificate?
No formal certification exists. Compliance is demonstrated to each agency through state-level CJIS Systems Agency processes, often supported by FedRAMP.
What is CMMC Level 1?
CMMC Level 1 is the foundational level of the Cybersecurity Maturity Model Certification, covering 15 basic practices for protecting Federal Contract Information (FCI).
How is it assessed?
It is assessed through an annual self-assessment with senior official affirmation.
What is CMMC Level 2?
CMMC Level 2 is the CMMC level covering controlled unclassified information (CUI), aligned to the 110 controls of NIST SP 800-171.
How is it assessed?
For most contracts, it is assessed by an accredited third-party assessment organization (C3PAO) every three years.
Which products are in scope?
See the Cert to Product Mapping tab for the current list of products and services in scope.
What does Adobe Creative Cloud for enterprise include?
Adobe Creative Cloud for enterprise includes Adobe Admin Console; Adobe Behance; Adobe Cloud Platform and Collaboration (Enterprise Storage Management); Adobe Developer Platform; Adobe Express; Adobe Firefly; Adobe Fonts; Adobe Frame.io; Adobe InDesign; Adobe Lightroom; Adobe Photoshop; Adobe Sensei; Adobe Stock; Adobe Substance 3D; Adobe XD; and identity, licensing, entitlement, and other supporting services.
What does Adobe Experience Cloud include?
Adobe Experience Cloud includes Adobe Advertising Cloud; Adobe Analytics; Adobe Audience Manager; Adobe Campaign; Adobe Commerce on Cloud Data Services; Adobe Commerce on Cloud Other Services; Adobe Commerce as a Cloud Service; Adobe Commerce Optimizer; Adobe Connect; Adobe Core Services; Adobe Customer Journey Analytics; Adobe Experience Manager (including as a Cloud Service and Sites Optimizer); Adobe Experience Platform; Adobe GenStudio for Performance Marketing; Adobe Journey Optimizer; Adobe Learning Manager; Adobe Marketo (Engage and Measure); Adobe MixModeler; Adobe Pass; Adobe Real-Time Customer Data Platform; Adobe Target; and Adobe Workfront.
What is EN 301 549?
EN 301 549 is the European standard specifying functional accessibility requirements for information and communications technology (ICT) products and services, including software, hardware, and digital content. Version 3.2.1 is the current harmonized version under the Web Accessibility Directive and the European Accessibility Act.
How does it relate to WCAG?
EN 301 549 V3.2.1 incorporates WCAG 2.1 Level AA in full for web and non-web documents, and adds further requirements covering mobile applications, hardware, and two-way voice communications. Conformance with EN 301 549 therefore exceeds a WCAG-only assessment.
Is EN 301 549 mandatory?
For public sector bodies in EU member states, EN 301 549 is mandatory under the Web Accessibility Directive. For private sector organizations supplying products or services in scope of the European Accessibility Act (applicable from June 2025), conformance is required by law.
How does Adobe demonstrate conformance?
Adobe publishes Voluntary Product Accessibility Templates (VPATs) and Accessibility Conformance Reports (ACRs) for its products, evaluated against EN 301 549 criteria. These are available through the Adobe Accessibility Conformance Reports page at adobe.com/trust/accessibility.
What is Section 508?
Section 508 is an amendment to the US Rehabilitation Act requiring federal agencies to make their electronic and information technology (EIT) accessible to people with disabilities. It was substantially revised in 2017 to align with WCAG 2.0 Level AA and EN 301 549.
Who does Section 508 apply to?
It applies directly to US federal agencies and, by extension, to any vendor whose products or services are procured by a federal agency. State and local governments, and private sector organizations, are not directly bound but often use it as a benchmark.
How does Adobe demonstrate conformance?
Adobe publishes Voluntary Product Accessibility Templates (VPATs) and Accessibility Conformance Reports (ACRs) that detail how each product addresses Section 508 requirements. These documents are available at adobe.com/trust/accessibility.
Is Section 508 conformance the same as WCAG conformance?
Substantially, yes. The 2017 refresh of Section 508 incorporates WCAG 2.0 Level AA by reference for web content and software. However, Section 508 also covers hardware, support documentation, and telecommunications, going beyond the web-content scope of WCAG alone.
What is GLBA?
The Gramm-Leach-Bliley Act (GLBA) is a US federal law requiring financial institutions — banks, insurance companies, securities firms, and similar entities — to explain how they share and protect customers' private financial information, and to implement a written information security program.
What does “GLBA-Ready” mean for an Adobe service?
“GLBA-Ready” means that the service can be configured and used in a way that enables the customer to help meet its GLBA obligations. Adobe provides the contractual and technical controls necessary to support a customer's compliance program.
Does Adobe sign a Business Associate Agreement for GLBA?
GLBA does not require a Business Associate Agreement in the HIPAA sense, but Adobe does provide data-processing agreements and security addenda that address the relevant safeguard requirements where needed.
What is FERPA?
The Family Educational Rights and Privacy Act (FERPA) is a US federal law protecting the privacy of student education records. It applies to educational agencies and institutions that receive funds under programs administered by the US Department of Education.
What does “FERPA-Ready” mean for an Adobe service?
“FERPA-Ready” means that the service can be configured and used in a way that enables the customer to help meet its FERPA obligations. Under FERPA guidelines, Adobe can contractually agree to act as a “school official” when it comes to handling regulated student data, enabling education customers to comply with FERPA requirements.
Is FERPA only relevant to US education institutions?
Yes. FERPA applies specifically to US educational agencies and institutions receiving federal funding. Customers outside the United States or outside the education sector do not typically have FERPA obligations.