Skip to content

AsanaCompliance, certifications and attestations

Certifications held, by family12 held
Status
Public
Founded
2008
Website
asana.com
Trust center Company profile
12
Certifications held
3
Backed by a registry
12
Pieces of evidence
Sep 24, 2026
Last captured
Across fru.devEarnings

SOC reports

ISO standards

AI governance

US government

Health

Payments

Privacy

Cloud security

Regional

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

Added or renewedUpgradedIn process or ReadyLapsed or removed
  1. AddedFedRAMP ModerateAsana
  2. In processFedRAMP ModerateAsana
  3. AddedCSA STARFirst listed in the CSA STAR Registry
  4. AddedData Privacy FrameworkAsana

Evidence

Every source, what it says and when it was read.

SOC 21 source

Held · Type IIVendor compliance page
...and security standards with measures in place to help you meet your compliance obligations. SOC 2 (Type 2) Security, availability, confidentiality, and privacy trust services criteria Read documentation SOC 3...
Captured Sep 24, 2026Open source

SOC 31 source

HeldVendor compliance page
...Security, availability, confidentiality, and privacy trust services criteria Read documentation SOC 3 Overview of Service Organization Controls Read documentation GDPR Data protection and data subject rights for...
Captured Sep 24, 2026Open source

ISO/IEC 270011 source

HeldVendor compliance page
...relevant US state privacy laws in California, Colorado, Virginia, and more Read documentation ISO/IEC 27001:2022 Global standard for information security management systems Read documentation ISO/IEC 27017:2015 Code of...
Captured Sep 24, 2026Open source

ISO/IEC 270171 source

HeldVendor compliance page
...27001:2022 Global standard for information security management systems Read documentation ISO/IEC 27017:2015 Code of practice for information security controls for cloud services Read documentation ISO/IEC 27018:2019...
Captured Sep 24, 2026Open source

ISO/IEC 270181 source

HeldVendor compliance page
...Code of practice for information security controls for cloud services Read documentation ISO/IEC 27018:2019 Code of practice for protecting personally identifiable information (PII) Read documentation ISO/IEC 27701:2019...
Captured Sep 24, 2026Open source

ISO/IEC 277011 source

HeldVendor compliance page
...Code of practice for protecting personally identifiable information (PII) Read documentation ISO/IEC 27701:2019 Privacy information management standard supporting compliance with global privacy laws Read documentation...
Captured Sep 24, 2026Open source

FedRAMP1 source

Held · ModerateFedRAMP Marketplace

Asana

FedRAMP Authorized, Moderate impact; authorized 2026-06-22 (Agency); assessor Schellman Compliance, LLC; 1 agency authorization
Captured Sep 23, 2026Since Jun 22, 2026Open source

HIPAA (BAA)1 source

HeldVendor compliance page
...documentation CSA STAR Level 1 Cloud security controls compliance self-assessment Read documentation HIPAA Protection of patient health information in the United States Read documentation GLBA Privacy Rule and Safeguards...
Captured Sep 24, 2026Open source

Data Privacy Framework1 source

HeldData Privacy Framework List

EU-US, UK extension, Swiss-US; non-HR data. Asana

EU-US status: Active; certified since 2016-10-13; recertification due 2027-08-12; verification: Self-Assessment
Captured Sep 23, 2026Since Oct 13, 2016Renewal due Aug 12, 2027Open source

CSA STAR1 source

Held · Level 1CSA STAR Registry

CAIQ

Listed as Asana, Inc. since 2022-08-13; Level 1 (self-assessment)
Captured Sep 23, 2026Since Aug 13, 2022Open source

Compare with

Weekly: vendors that gained or lost a certification, Wednesdays.