Asana logo
✓ 12 of 32 frameworks
+ 2 partial
Security & General Standards
SOC 2 Type II

SOC 3

SOC 1 Type II

ISO 27001 (Information Security Management)

ISO 27017 (Cloud Security)

ISO 27018 (Cloud Privacy)

ISO 27701 (Privacy Information Management)

ISO 42001 (AI Management Systems)

ISO 9001 (Quality Management)

CSA STAR (Cloud Security Alliance)

HITRUST CSF

BSI C5 (German Cloud Security)

Privacy & Data Transfer
GDPR (EU)

CCPA / CPRA (California)

incl. CO, VA and other US state privacy laws

UK GDPR

LGPD (Brazil)

PIPEDA (Canada)

DPDP Act (India)
?

Not publicly documented

PIPL (China)
?

Not publicly documented

EU-US Data Privacy Framework

Swiss-US Data Privacy Framework

Global CBPR (APEC)

Global PRP (APEC)

Industry & Government
HIPAA (US Healthcare)
~

Enterprise tier + BAA

PCI DSS (Payment Card Industry)

FedRAMP (US Federal)

StateRAMP / TX-RAMP (US State)

DORA (EU Finance)
~

CJIS (US Law Enforcement)

FINRA (US Broker-Dealers)

IRAP (Australian Government)

Emerging & Strategic
NIST CSF (Cybersecurity Framework)
?

Not publicly documented

Data last verified: September 2026

Is this data outdated?

Spotted an error or a recent change in Asana's posture? Submit a correction.

Submit a correction →

Work at Asana?

Claim this profile to verify and enrich your compliance data.

Claim this profile →

Compare Asana with:

← All Productivity & Collaboration tools

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026