Skip to content

FigmaCompliance, certifications and attestations

Certifications held, by family14 held
Status
Public
Founded
2012
Website
figma.com
Trust center Company profile
14
Certifications held
5
Backed by a registry
15
Pieces of evidence
Sep 24, 2026
Last captured
Across fru.devEarningsConferences

SOC reports

ISO standards

AI governance

US government

Health

Payments

Privacy

Cloud security

Regional

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

Added or renewedUpgradedIn process or ReadyLapsed or removed
  1. AddedFedRAMP ModerateFigma for Government
  2. In processFedRAMP ModerateFigma for Government
  3. AddedCSA STARFirst listed in the CSA STAR Registry
  4. AddedData Privacy FrameworkFigma, Inc.

Evidence

Every source, what it says and when it was read.

SOC 21 source

Held · Type IIVendor compliance page
...compliance programs—all meticulously designed to safeguard our customers’ data and privacy. SOC 2 Figma has an SOC 2 Type 2 report that shows our commitment to protecting customer data through robust security,...
Captured Sep 24, 2026Open source

SOC 31 source

HeldVendor compliance page
...and confidentiality controls that align with the AICPA Trust Services Criteria. Learn more SOC 3 Figma has an SOC 3 report that shows our commitment to protecting customer data through robust security, availability,...
Captured Sep 24, 2026Open source

ISO/IEC 270011 source

HeldVendor compliance page
...and confidentiality controls that align with the AICPA Trust Services Criteria. Learn more ISO 27001+ ISO 27017 ISO 27018 ISO 27701 Figma has certified its product and services against ISO/IEC 27001:2022 and ISO/IEC...
Captured Sep 24, 2026Open source

ISO/IEC 270171 source

HeldVendor compliance page
...confidentiality controls that align with the AICPA Trust Services Criteria. Learn more ISO 27001+ ISO 27017 ISO 27018 ISO 27701 Figma has certified its product and services against ISO/IEC 27001:2022 and ISO/IEC 27018:2019....
Captured Sep 24, 2026Open source

ISO/IEC 270181 source

HeldVendor compliance page
...controls that align with the AICPA Trust Services Criteria. Learn more ISO 27001+ ISO 27017 ISO 27018 ISO 27701 Figma has certified its product and services against ISO/IEC 27001:2022 and ISO/IEC 27018:2019. Learn...
Captured Sep 24, 2026Open source

ISO/IEC 277011 source

HeldVendor compliance page
...that align with the AICPA Trust Services Criteria. Learn more ISO 27001+ ISO 27017 ISO 27018 ISO 27701 Figma has certified its product and services against ISO/IEC 27001:2022 and ISO/IEC 27018:2019. Learn more ISO...
Captured Sep 24, 2026Open source

ISO/IEC 420011 source

HeldVendor compliance page
...certified its product and services against ISO/IEC 27001:2022 and ISO/IEC 27018:2019. Learn more ISO 42001 Figma has certified its AI management system against ISO/IEC 42001:2023. Learn more EU Cloud Code of Conduct The...
Captured Sep 24, 2026Open source

CSA STAR for AI1 source

Held · Level 1CSA STAR Registry

AI-CAIQ

Listed as Figma since 2022-04-13; STAR for AI Level 1
Captured Sep 23, 2026Since Apr 13, 2022Open source

FedRAMP1 source

Held · ModerateFedRAMP Marketplace

Figma for Government

FedRAMP Authorized, Moderate impact; authorized 2025-02-28 (Agency); assessor Schellman Compliance, LLC; 11 agency authorizations
Captured Sep 23, 2026Since Feb 28, 2025Open source

Data Privacy Framework1 source

HeldData Privacy Framework List

EU-US, UK extension, Swiss-US; non-HR data and HR data. Figma, Inc.

EU-US status: Active; certified since 2018-11-16; recertification due 2027-07-22; verification: Self-Assessment
Captured Sep 23, 2026Since Nov 16, 2018Renewal due Jul 22, 2027Open source

EU Cloud Code of Conduct2 sources

HeldCSA STAR Registry

Partner entry in the STAR Registry

Listed as Figma since 2022-04-13; EU Cloud Code of Conduct entry
Captured Sep 23, 2026Since Apr 13, 2022Open source
HeldVendor compliance page
...42001 Figma has certified its AI management system against ISO/IEC 42001:2023. Learn more EU Cloud Code of Conduct The EU Cloud Code of Conduct translates GDPR requirements into practical guidelines for Cloud Service Providers,...
Captured Sep 24, 2026Open source

CSA STAR1 source

Held · Level 1CSA STAR Registry

CAIQ

Listed as Figma since 2022-04-13; Level 1 (self-assessment)
Captured Sep 23, 2026Since Apr 13, 2022Open source

BSI C51 source

HeldVendor compliance page
...Computing Compliance Criteria Catalogue The Cloud Computing Compliance Controls Catalogue (C5) certification exists to meet rigorous, German government–backed standards for security, transparency, and operational...
Captured Sep 24, 2026Open source

TISAX1 source

HeldVendor compliance page
...assurance for regulated and public-sector customers, especially in Germany and the EU. Learn more TISAX Trusted Information Security Assessment Exchange (TISAX) is a European automotive industry-standard information...
Captured Sep 24, 2026Open source

Compare with

Weekly: vendors that gained or lost a certification, Wednesdays.