Q39
Are you PCI DSS compliant? At what level?
PCI DSS compliance claim found on trust page (Vendor attested)
ThirdProof independently checks public intelligence sources to show what your team can verify about DocuSign before DocuSign sends a questionnaire or a security document.
DocuSign's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from DocuSign — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on DocuSign's own trust page.
✓ FedRAMP Certified — Class C (Moderate) Checked August 2026.
Docusign IAM eSignature is FedRAMP Certified at Class C (Moderate) via the Agency path (package F1609267945).
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The DocuSign assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest DocuSign Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 86% of a 133-question vendor security questionnaire — without waiting for DocuSign. The remaining 18 are listed as open, so the follow-up you send is short and specific.
Q39
PCI DSS compliance claim found on trust page (Vendor attested)
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Docusign operates on internal privacy and data protection policies aligned to industry best practices, including international regimes, such as the GDPR...undergoes rigorous review and approval by the Irish Data Protection Commission...Binding Corporate Rules (BCRs)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
Docusign will encrypt Customer Data using industry-recognized encryption standards and protocols, including cryptographic algorithms that meet or exceed current best practices and secure key management practices.
+ 110 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing DocuSign for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for DocuSign
DocuSign is a mature, publicly traded electronic signature and agreement management platform with a strong security posture and a Tier 4 (Low Risk) rating.
The vendor demonstrates robust governance and compliance infrastructure, including FedRAMP authorization for DocuSign CLM at the Moderate impact level, multiple vendor-attested certifications (ISO 27001, SOC 2 Type II, SOC 1 Type II, PCI DSS), a designated Chief Information Security Officer, and comprehensive security controls documented in published data processing agreements and security attachments. Infrastructure exposure is minimal with only standard web ports (80, 443) exposed, clean domain reputation across threat intelligence databases, and no critical CVEs detected.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from public registries, threat intelligence platforms, domain analysis tools, and vendor-published trust documentation without vendor participation.
4 findings identified for DocuSign
Adverse media coverage identified one article from September 2025 documenting a class action lawsuit against DocuSign with ongoing litigation and potential settlements. The article title ('Docusign Class Action Lawsuit Details and Litigation Exposed') suggests litigation remains active. …
HTTP security scanner HTTP security scan returned a grade C (score 55/100) for the docusign.com marketing site. The scan found 8 passing security header tests but 2 failures, specifically missing Content-Security-Policy and X-Frame-Options headers. …
DocuSign appears in 50 Open Threat Exchange threat intelligence pulses. Large, globally used SaaS vendors accumulate threat intelligence references because threat actors actively phish or impersonate them (as evidenced by historical media mentioning 'Docusign phishing' attacks). …
The primary IP address (15.197.167.90) associated with docusign.com has an IP reputation service confidence score of 2% with 1 reported incident. This IP is registered to Amazon Technologies Inc. and classified as Content Delivery Network infrastructure. …
Evidence that positively supports DocuSign's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →DocuSign complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent DocuSign? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The DocuSign assessment above is already written; ask for it and it lands in your inbox.