generated: '2026-08-13' method: searched source: https://www.adobe.com/trust/compliance/compliance-list.html description: >- Adobe publishes a Trust Center with a per-service compliance list. Adobe Analytics is covered as part of Adobe Experience Cloud (named explicitly in footnote [3] of the compliance list), and the list's footnote [4] states that the FedRAMP Tailored authorization "Applies to Adobe Analytics and Adobe Campaign only." Certifications below are transcribed from the Adobe Experience Cloud row of that page, last updated by Adobe on 2026-05-21. trust_center: url: https://www.adobe.com/trust.html security: https://www.adobe.com/trust/security.html compliance_list: https://www.adobe.com/trust/compliance/compliance-list.html privacy: https://www.adobe.com/privacy/policy.html last_updated_by_provider: '2026-05-21' scope: service_offering: Adobe Experience Cloud includes_adobe_analytics: true evidence: >- "[3] Adobe Experience Cloud includes Adobe Advertising Cloud, Adobe Analytics, ..." — footnote on https://www.adobe.com/trust/compliance/compliance-list.html certifications: - name: FedRAMP Tailored status: authorized note: 'Footnote [4]: applies to Adobe Analytics and Adobe Campaign only.' - name: SOC 2 Type 2 status: attested scope_note: Security, Availability, & Confidentiality - name: SOC 3 status: attested scope_note: Security, Availability, & Confidentiality - name: ISO 9001:2015 status: certified - name: ISO 27001:2022 status: certified - name: ISO 27017:2015 status: certified - name: ISO 27018:2019 status: certified - name: ISO 22301:2019 status: certified - name: CSA STAR Level 2 status: certified - name: IRAP Assessed status: assessed note: 'Footnote [8]: applies to Customer Journey Analytics (CJA) Australia at Protected Level.' - name: HIPAA ready status: ready note: '"Ready" is Adobe''s term — the service can be configured to support the customer''s own HIPAA obligations; it is not a certification.' - name: GLBA ready status: ready - name: FERPA ready status: ready - name: TrustArc GDPR Privacy Practices Management Compliance Validation status: validated - name: TrustArc APEC Privacy Recognition for Processors (PRP) status: certified company_wide: - name: TISAX Registered note: 'Footnote [7]: applies to Adobe''s San Jose and Dublin office locations only.' - name: CMMC Level 1 - name: GDPR - name: CCPA notes: >- Certifications are published at the Adobe Experience Cloud service-offering level, not per API. No Adobe Analytics-specific SOC 2 report or certificate is published separately; customers request reports through Adobe. PCI DSS is NOT listed for Adobe Experience Cloud (it appears for Acrobat Sign, Adobe Commerce on Cloud, AEM Managed Services and adobe.com eCommerce only) — recorded here so the absence is not mistaken for coverage.