Frequently asked questions
SOC 1
What is a SOC 1 report? A SOC 1 report is a report issued by an independent CPA firm under AICPA standards, covering controls that could affect customers' financial reporting. It is designed for customers' finance teams and their financial statement auditors.
How do I get a copy of the report? SOC 1 reports contain confidential detail and are shared with customers under NDA on request through your Adobe account team.
How often is the report issued? The report is issued annually, covering the audit period stated in the report.
SOC 2
What is a SOC 2 report? A SOC 2 report is an attestation report issued by an independent CPA firm. A Type II report tests whether controls operated effectively over a period, usually twelve months, rather than at a single point in time.
What is the difference between SOC 1, SOC 2, and SOC 3? SOC 1 covers controls relevant to financial reporting. SOC 2 covers the Trust Services Criteria in detail and is shared under NDA. SOC 3 is a public summary of the SOC 2 examination.
How do I get a copy of the report? SOC 2 reports are shared with customers under NDA on request through your Adobe account team.
Does a SOC 2 report make my organization compliant? A SOC 2 report provides independent assurance over the service provider's controls. Customers remain responsible for their own controls, configurations, and use of the service.
SOC 2 + HIPAA
What does the HIPAA mapping add? The independent auditor tests additional criteria mapped to HIPAA Security Rule safeguards alongside the standard Trust Services Criteria.
Is there such a thing as HIPAA certification? No. There is no official HIPAA certification scheme. This report demonstrates independent testing of controls mapped to HIPAA requirements.
Do I still need a Business Associate Agreement? Yes. Customers handling PHI should have a BAA in place. The report supports the relationship but does not replace the agreement.
SOC 3
What is a SOC 3 report? A SOC 3 report is a short, general-use report based on the same examination as SOC 2. It states the auditor's opinion without detailed control descriptions or test results.
How do I get it? SOC 3 reports are intended for public distribution and can be downloaded without an NDA.
ISO 27001
What is ISO 27001? ISO 27001 is the leading international standard for managing information security through a risk-based management system, certified by an accredited third party with annual surveillance audits on a three-year cycle.
What does Enterprise scope mean? Enterprise scope means that the certification covers the organization-wide ISMS rather than an individual product.
How can I verify the certificate? Certificates can be downloaded from the Trust Center or verified through the certification body's public register.
ISO 27017
What is ISO 27017? ISO 27017 is a code of practice adding cloud-specific guidance and controls for cloud service providers and customers, assessed alongside the ISO 27001 certification.
Why does it matter for cloud customers? It matters for cloud customers because it demonstrates that cloud-specific risks, such as shared responsibility and virtual environment separation, are explicitly addressed.
ISO 27018
What is ISO 27018? ISO 27018 is a code of practice for public cloud providers acting as PII processors, covering commitments such as transparency, purpose limitation, and customer control over personal data.
How does it relate to privacy law? It supports privacy compliance programs such as GDPR by evidencing recognized PII handling practices, but it is not itself a legal compliance certification.
ISO 22301
What is ISO 22301? ISO 22301 is a certifiable standard showing the organization can plan for, respond to, and recover from disruption to keep services running.
What does this tell me as a customer? It tells you that the continuity and disaster recovery arrangements are independently certified, supporting service resilience commitments.
ISO 9001
What is ISO 9001? ISO 9001 is a certifiable standard for quality management, focused on consistent processes, customer satisfaction, and continual improvement.
Is it security related? Not directly. It certifies quality management practices that underpin reliable and consistent service delivery.
SSPA (Microsoft)
What is SSPA? SSPA is Microsoft's program requiring suppliers to meet its Data Protection Requirements and attest annually, with independent assessment where Microsoft requires it.
Who does this matter to? This matters primarily to Microsoft as the customer. Inclusion shows the listed services meet Microsoft's supplier data protection requirements.
CSA STAR Level 2
What is CSA STAR Level 2? CSA STAR Level 2 is a Cloud Security Alliance program combining independent certification with the Cloud Controls Matrix (CCM), building on ISO 27001 or SOC 2.
How is Level 2 different from Level 1? Level 1 is a published self-assessment; Level 2 adds independent third-party assessment.
How can I verify it? Entries are published on the CSA STAR public registry.
BSI C5
What is BSI C5? BSI C5 is an attestation under ISAE 3000 against the C5 criteria catalogue published by Germany's Federal Office for Information Security (BSI). It is widely required by German public sector and regulated customers.
Is C5 only relevant in Germany? It originated in Germany and is strongest there, but it is increasingly recognized across Europe as a rigorous cloud assurance baseline.
How do I get the report? C5 attestation reports are shared with customers on request, typically under NDA.
TISAX
What is TISAX? TISAX is the Trusted Information Security Assessment Exchange, governed by the ENX Association. It is the standard security assessment required across the automotive supply chain.
What are the assessment levels? AL1 is a self-assessment, AL2 is a plausibility check by an approved audit provider, and AL3 is a full on-site audit for very high protection needs.
Is there a certificate? TISAX issues labels rather than certificates. Results are shared with participants through the ENX portal and are valid for three years.
Who asks for TISAX? Vehicle manufacturers and their suppliers ask for TISAX before exchanging sensitive information such as prototype or development data.
Which products are in scope? Adobe-wide Security is in scope. Does not apply to Adobe Acrobat Sign for Government. TISAX applies to Adobe's San Jose and Dublin office locations only.
Spain ENS
What is ENS? ENS is the Esquema Nacional de Seguridad, mandatory for Spanish public sector bodies and the private suppliers serving them.
What are the ENS categories? The ENS categories are Basic, Medium, and High, based on the impact a security incident would have on the services and information handled.
How is conformity shown? Conformity is shown through a certificate of conformity issued by an accredited body for Medium and High category, displayed with the official ENS mark.
KFSI CSP Self-assessment Checklist (Korea)
What is the KFSI CSP checklist? The KFSI CSP checklist is a structured self-assessment aligned to guidance from Korea's Financial Security Institute, used by Korean financial institutions when reviewing cloud services under local regulations.
Is it a certification? No. It is a self-assessment that supports the customer's own regulatory review.
ISMAP
What is ISMAP? ISMAP is the Information system Security Management and Assessment Program, Japan's scheme for assessing and registering cloud services for government use.
Why does ISMAP matter? ISMAP matters because Japanese government bodies are expected to procure from the ISMAP registered list, so registration opens the Japanese public sector market.
How often is it renewed? Registration is reviewed annually, which is why it is tracked by fiscal year.
How can I verify it? You can verify it on the public ISMAP cloud service registration list.
Adobe Acrobat Sign Aadhaar Assessment
What is Aadhaar eSign? Aadhaar eSign is a legally recognized electronic signature in India where the signer authenticates with their Aadhaar identity and an OTP or biometric, under the Information Technology Act.
Who oversees the framework? India's Controller of Certifying Authorities (CCA) oversees the framework, with eSign services delivered through empanelled providers.
IRAP Protected
What is IRAP Protected? IRAP Protected is the Information Security Registered Assessors Program, run by the Australian Signals Directorate. An endorsed IRAP assessor evaluates the service against the Australian Government ISM.
Is IRAP a certification? No. It is an independent assessment report. Each Australian agency makes its own risk-based authorization decision using the report.
What classification level is covered? The listed services are assessed at PROTECTED level.
How do agencies get the report? IRAP reports are shared with Australian government customers on request, typically under NDA.
TPN Blue Shield (Self-assessment)
What is TPN Blue Shield? TPN Blue Shield is a completed self-assessment on the Trusted Partner Network platform against the industry's content security best practices, based on the Motion Picture Association guidelines.
How is Blue Shield different from Gold Shield? Blue Shield is a self-assessment; Gold Shield adds an independent assessment by a TPN-accredited assessor.
Who relies on this? Major studios and content owners rely on TPN Blue Shield when deciding whether a vendor can handle pre-release content.
PCI DSS 4.0 ROC
What is a PCI DSS ROC? A PCI DSS ROC is a report on Compliance produced by a Qualified Security Assessor (QSA) after a full assessment of services that store, process, or transmit payment card data.
What evidence can customers get? Customers can get an Attestation of Compliance (AOC) summarizing the assessment is available to customers on request. Additionally, a responsibility matrix maybe requested for roles and responsibilities.
What changed in v4.0? PCI DSS 4.0 replaced v3.2.1 with stronger control requirements, targeted risk analysis and more flexible customized approaches.
How often is it assessed? Annually.
FedRAMP Class B
What is FedRAMP Class B? FedRAMP Class B is a tailored FedRAMP baseline for Class B services that do not store sensitive federal data beyond basic login information, assessed by an accredited Third Party Assessment Organization (3PAO).
How can agencies verify it? Agencies can verify it on the FedRAMP Marketplace and access of System Security Plan via Connect.gov.
FedRAMP Class C
What is FedRAMP Moderate? FedRAMP Moderate is an authorization against the FedRAMP Class C baseline, which draws on several hundred NIST SP 800-53 controls and covers the majority of unclassified federal data.
What happens after authorization? Continuous monitoring obligations apply, including regular scanning, reporting and annual assessment.
How can agencies verify it? Agencies can verify it on the FedRAMP Marketplace and access of System Security Plan via Connect.gov.
CJIS
What is CJIS? CJIS is the FBI's security policy governing how criminal justice information (CJI) is protected. It applies where services handle CJI for US law enforcement agencies.
Is there a CJIS certificate? No formal certification exists. Compliance is demonstrated to each agency through state-level CJIS Systems Agency processes, often supported by FedRAMP.
CMMC Level 1
What is CMMC Level 1? CMMC Level 1 is the foundational level of the Cybersecurity Maturity Model Certification, covering 15 basic practices for protecting Federal Contract Information (FCI).
How is it assessed? It is assessed through an annual self-assessment with senior official affirmation.
CMMC Level 2
What is CMMC Level 2? CMMC Level 2 is the CMMC level covering controlled unclassified information (CUI), aligned to the 110 controls of NIST SP 800-171.
How is it assessed? For most contracts, it is assessed by an accredited third-party assessment organization (C3PAO) every three years.
Which products are in scope? See the Cert to Product Mapping tab for the current list of products and services in scope.
What does Adobe Creative Cloud for enterprise include? Adobe Creative Cloud for enterprise includes Adobe Admin Console; Adobe Behance; Adobe Cloud Platform and Collaboration (Enterprise Storage Management); Adobe Developer Platform; Adobe Express; Adobe Firefly; Adobe Fonts; Adobe Frame.io; Adobe InDesign; Adobe Lightroom; Adobe Photoshop; Adobe Sensei; Adobe Stock; Adobe Substance 3D; Adobe XD; and identity, licensing, entitlement, and other supporting services.
What does Adobe Experience Cloud include? Adobe Experience Cloud includes Adobe Advertising Cloud; Adobe Analytics; Adobe Audience Manager; Adobe Campaign; Adobe Commerce on Cloud Data Services; Adobe Commerce on Cloud Other Services; Adobe Commerce as a Cloud Service; Adobe Commerce Optimizer; Adobe Connect; Adobe Core Services; Adobe Customer Journey Analytics; Adobe Experience Manager (including as a Cloud Service and Sites Optimizer); Adobe Experience Platform; Adobe GenStudio for Performance Marketing; Adobe Journey Optimizer; Adobe Learning Manager; Adobe Marketo (Engage and Measure); Adobe MixModeler; Adobe Pass; Adobe Real-Time Customer Data Platform; Adobe Target; and Adobe Workfront.
EN 301 549 V3.2.1 (Harmonized European Accessibility Standard)
What is EN 301 549? EN 301 549 is the European standard specifying functional accessibility requirements for information and communications technology (ICT) products and services, including software, hardware, and digital content. Version 3.2.1 is the current harmonized version under the Web Accessibility Directive and the European Accessibility Act.
How does it relate to WCAG? EN 301 549 V3.2.1 incorporates WCAG 2.1 Level AA in full for web and non-web documents, and adds further requirements covering mobile applications, hardware, and two-way voice communications. Conformance with EN 301 549 therefore exceeds a WCAG-only assessment.
Is EN 301 549 mandatory? For public sector bodies in EU member states, EN 301 549 is mandatory under the Web Accessibility Directive. For private sector organizations supplying products or services in scope of the European Accessibility Act (applicable from June 2025), conformance is required by law.
How does Adobe demonstrate conformance? Adobe publishes Voluntary Product Accessibility Templates (VPATs) and Accessibility Conformance Reports (ACRs) for its products, evaluated against EN 301 549 criteria. These are available through the Adobe Accessibility Conformance Reports page at adobe.com/trust/accessibility (https://www.adobe.com/trust/accessibility).
Section 508 of the Rehabilitation Act of 1973
What is Section 508? Section 508 is an amendment to the US Rehabilitation Act requiring federal agencies to make their electronic and information technology (EIT) accessible to people with disabilities. It was substantially revised in 2017 to align with WCAG 2.0 Level AA and EN 301 549.
Who does Section 508 apply to? It applies directly to US federal agencies and, by extension, to any vendor whose products or services are procured by a federal agency. State and local governments, and private sector organizations, are not directly bound but often use it as a benchmark.
How does Adobe demonstrate conformance? Adobe publishes Voluntary Product Accessibility Templates (VPATs) and Accessibility Conformance Reports (ACRs) that detail how each product addresses Section 508 requirements. These documents are available at adobe.com/trust/accessibility (https://www.adobe.com/trust/accessibility).
Is Section 508 conformance the same as WCAG conformance? Substantially, yes. The 2017 refresh of Section 508 incorporates WCAG 2.0 Level AA by reference for web content and software. However, Section 508 also covers hardware, support documentation, and telecommunications, going beyond the web-content scope of WCAG alone.
GLBA-Ready
What is GLBA? The Gramm-Leach-Bliley Act (GLBA) is a US federal law requiring financial institutions — banks, insurance companies, securities firms, and similar entities — to explain how they share and protect customers' private financial information, and to implement a written information security program.
What does 'GLBA-Ready' mean for an Adobe service? 'GLBA-Ready' means that the service can be configured and used in a way that enables the customer to help meet its GLBA obligations. Adobe provides the contractual and technical controls necessary to support a customer's compliance program.
Does Adobe sign a Business Associate Agreement for GLBA? GLBA does not require a Business Associate Agreement in the HIPAA sense, but Adobe does provide data-processing agreements and security addenda that address the relevant safeguard requirements where needed.
FERPA-Ready
What is FERPA? The Family Educational Rights and Privacy Act (FERPA) is a US federal law protecting the privacy of student education records. It applies to educational agencies and institutions that receive funds under programs administered by the US Department of Education.
What does 'FERPA-Ready' mean for an Adobe service? 'FERPA-Ready' means that the service can be configured and used in a way that enables the customer to help meet its FERPA obligations. Under FERPA guidelines, Adobe can contractually agree to act as a 'school official' when it comes to handling regulated student data, enabling education customers to comply with FERPA requirements.
Is FERPA only relevant to US education institutions? Yes. FERPA applies specifically to US educational agencies and institutions receiving federal funding. Customers outside the United States or outside the education sector do not typically have FERPA obligations.
TPN Gold Shield
What is TPN Gold Shield? Gold Shield is the highest tier of the Trusted Partner Network (TPN) program, operated under the Motion Picture Association (MPA) Content Security Best Practices. It requires an independent assessment by a TPN-approved assessor, who verifies that the organization's facilities, workflows, and technology controls meet MPA content security guidelines.
How is Gold Shield different from Blue Shield? Blue Shield is a completed self-assessment submitted to the TPN registry; Gold Shield adds a full third-party audit by a TPN-accredited assessor. Gold Shield is therefore a higher and independently verified level of assurance and is typically required for vendors handling the most sensitive pre-release content.
Who relies on TPN Gold Shield? TPN Gold Shield is relied upon by major studios, streaming platforms, and content owners who require independent verification that a vendor can securely handle pre-release, unreleased, or other sensitive media content before committing to a production partnership.
FDA 21 CFR Part 11 Ready
What is FDA 21 CFR Part 11? Title 21 of the US Code of Federal Regulations, Part 11, establishes the criteria under which the US Food and Drug Administration (FDA) considers electronic records and electronic signatures to be trustworthy, reliable, and equivalent to paper records and handwritten signatures. It applies to pharmaceutical, biotech, medical device, and other FDA-regulated companies that create, modify, maintain, archive, retrieve, or transmit records in electronic form.
What does 'FDA 21 CFR Part 11 Ready' mean for an Adobe service? It means that the service provides the technical and procedural controls needed to help customers operate in compliance with Part 11 requirements — such as audit trails, access controls, and electronic signature capabilities — and that Adobe can support the customer's validation activities. The customer remains responsible for their own validation and compliance program.
Is there an official 21 CFR Part 11 certification? No. The FDA does not certify software as Part 11-compliant. Readiness means the service has been designed and documented to support compliant use, and that Adobe provides the documentation customers need for their own system validation.
EudraLex Volume 4 Annex 11 Ready
What is EudraLex Volume 4 Annex 11? EudraLex is the collection of rules governing medicinal products in the European Union. Volume 4 covers Good Manufacturing Practice (GMP) guidelines. Annex 11 specifically addresses computerized systems used in GMP-regulated environments, covering validation, data integrity, audit trails, electronic records, and backup and recovery requirements.
What does 'EudraLex Volume 4 Annex 11 Ready' mean for an Adobe service? It means that the service can be used in a way that supports the customer's compliance with Annex 11 requirements, and that Adobe provides the documentation and controls necessary for the customer's own computerized system validation (CSV) activities. The customer remains responsible for conducting validation and ensuring the system is fit for its intended GMP use.
Who needs EudraLex Annex 11 compliance? Pharmaceutical manufacturers, contract research organizations (CROs), and other entities operating under EU GMP regulations need EudraLex Annex 11 compliance, including those manufacturing medicinal products for the EU market, regardless of where manufacturing takes place.
QTSP for Time Stamps
What is a Qualified Trust Service Provider (QTSP)? A Qualified Trust Service Provider is an entity that has been granted qualified status by a national supervisory body under the EU Regulation on Electronic Identification, Authentication and Trust Services (eIDAS). Qualified status is the highest level of trust service recognition under EU law and confers legal presumption of integrity on the services provided.
What does Adobe's QTSP status cover? Adobe's QTSP status specifically covers qualified electronic time stamps. A qualified time stamp provides legally binding, tamper-evident evidence of the exact date and time at which a document or record existed, equivalent in legal effect to a notarized date stamp in participating EU member states.
Why does QTSP status matter for customers? Documents time-stamped by a QTSP carry a legal presumption under eIDAS that the data existed at the indicated time and has not been altered since. This is particularly relevant for regulated industries requiring long-term document integrity, such as life sciences, financial services, and legal sectors operating in the EU.
Is QTSP status recognised outside the EU? QTSP status is an EU regulatory designation. Outside the EU, its recognition depends on bilateral agreements or local law. Several non-EU jurisdictions have adopted eIDAS-aligned frameworks that recognize EU qualified trust services.