SOC2C

Is this your company? Buyers are checking Asana here. Claim asana.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Asana logo

Asana

asana.com· United States· 1000+ employees· Founded 2008
Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Report dated Jan 2026

Asana is SOC 2 Type II compliant, with its most recent report dated Jan 2026. Asana also holds SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, HIPAA, GDPR, CCPA, FedRAMP, and CSA STAR.

Framework
Auditor
Last report
Jan 2026
Renewal
Renews Jan 2027
View official trust center ↗

About

Work management and team collaboration platform.

Compliance & infrastructure

SOC 2 Type IISOC 2 Type ISOC 3ISO 27001ISO 27017ISO 27018ISO 27701HIPAAGDPRCCPAFedRAMPCSA STAR
Hosting
AWS

Compliance leadership

The person who leads Asana's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Asana's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

New Asana SOC Reports and ISO CertificatesMay 2026

We are pleased to announce that Asana has successfully completed a SOC 2 Type 1 audit for our Asana Gov platform — a significant milestone in our ongoing commitment to meeting the security and compliance requirements of government and public sector customers. In addition, we are pleased to share the following compliance updates for the Asana platform: The SOC 2 Type 2 report + HIPAA Assessment for the period February 1, 2025 to January 31, 2026 is now available for download via our Trust Center. The SOC 3 report for the same period is publicly available. Asana has also successfully completed its surveillance review against the ISO 27001:2022 standard. Current certifications for ISO 27001, ISO 27017, ISO 27018, and ISO 27701 are publicly available for download via the respective links.

New Asana SOC Reports and ISO certificatesApr 2025

Asana's SOC 2 Type 2 report + HIPAA Assessment for the period covering from February 2024 to January 2025 is now available to request for download from our Trust Center. Additionally, the Asana SOC 3 report for the same period is now publicly available. Asana successfully passed its recertification against the ISO 27001 standard, and was audited against the most recent version of the standard: ISO 27001:2022. Our up to date certifications for ISO 27001, ISO 27017, ISO 27018, and ISO 27701 are all available publicly for download by following the respective links.

New Security Assessment (Penetration Test) report published (August to November 2024)Nov 2024

Praetorian Security, Inc. just completed Asana's FY25 security assessment / penetration test. The scope of this test covers our web and mobile application, cloud infrastructure, Asana-owned integrations (subset selected by Asana Security), internal network, external network, and AI / Smart features. Please see the summary report on Asana's Trust Center: Penetration Testing

Asana Announces Commitment to Pursuing FedRAMP AuthorizationAug 2024

Asana has just publicly announced that we have committed to pursuing FedRAMP authorization - a commitment that will serve the complex needs of our customers in regulated industries. By pursuing FedRAMP, we expect numerous benefits to be extended to our customers, including: - Enhanced security and trust, especially among those in a regulatory environment - Expanded access for our customers working with or aspiring to do business with the U.S. Federal Government To learn more, check out our press release here and our blog post here.

New ISO 27001 SoA Published (February 2024)Feb 2024

As part of Asana’s annual security compliance audits, Asana was audited against the updated version of the ISO 27001 standard (ISO 27001:2022). As part of preparing for this audit, Asana updated its Statement of Applicability (SoA) in line with the new version, defining which ISO 27001:2022 controls were applied into the organization. Please find this updated SoA at Asana’s Trust Center here: ISO 27001 SoA.

New Disaster Recovery Summary Published (October 2023)Nov 2023

Asana just completed our annual Disaster Recovery Test in October 2023. The goal of this exercise is to model a worst case scenario where our infrastructure is completely lost and we are forced to bring up data from backup snapshots of our production environment, which we call snapshots. Please see the summary report on Asana's Trust Center: Disaster Recovery Summary

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Asana SOC 2 compliant?
Asana is SOC 2 Type II compliant, with its most recent report dated Jan 2026. On SOC2C this listing is Listed.
When does Asana's SOC 2 renew?
Asana's SOC 2 is due to renew in Jan 2027.
Is Asana SOC 3 compliant?
According to Asana's public trust center, Asana is SOC 3 compliant. On SOC2C this listing is Listed.
Is Asana ISO 27001 certified?
According to Asana's public trust center, Asana is ISO 27001 certified. On SOC2C this listing is Listed.
Is Asana ISO 27017 certified?
According to Asana's public trust center, Asana is ISO 27017 certified. On SOC2C this listing is Listed.