
Summary
A-LIGN has 2 registry-verified rows and 5 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, A-LIGN states on its trust centre that it holds SOC 2, though no independent report details were provided in this evidence. As of 17 Sep 2026, A-LIGN is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 17 Sep 2025 and audited by RISC Point. As of 17 Sep 2026, A-LIGN is listed in the EU-US Data Privacy Framework registry as active for both the EU-US Certification and UK Extension Certification, with certification issued 15 Jun 2020 and set to expire 6 Jul 2027. As of 17 Sep 2026, A-LIGN states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 42001, and HITRUST, and states on its trust centre that it holds GDPR compliance, though no independent verification of these claims was found. As of 17 Sep 2026, no public evidence found regarding a HIPAA BAA offering for A-LIGN.
- As of 17 Sep 2026, A-LIGN is listed in the FedRAMP registry as FedRAMP Authorized (issued 17 Sep 2025, auditor RISC Point).
- As of 17 Sep 2026, A-LIGN is listed in the EU-US Data Privacy Framework registry as active (EU-US and UK Extension Certifications), issued 15 Jun 2020, expiring 6 Jul 2027.
- As of 17 Sep 2026, A-LIGN states on its trust centre that it holds SOC 2, ISO/IEC 27001, ISO/IEC 42001, HITRUST, and GDPR compliance, with no independent verification found in this evidence.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among compliance and grc vendors
2verified rows
Category median 1, across 118 indexed compliance and grc vendors. A-LIGN has more verified rows than 97 percent of them.
compliance auditscompliance managementgrcregulatory audits
Compare with similar vendors
Pick your own comparisonCompliance grid
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source - FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · RISC Point
ISO/IEC 27001Vendor-statedVendor states ISO 27001 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO 42001 on its trust centre
as of 17 Sep 20261 source
HITRUSTVendor-statedVendor states HITRUST on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, UK Extension Certification
as of 17 Sep 20261 source
No public evidence yet for HIPAA, PCI DSS, CSA STAR, Cyber Essentials, ISO 27701. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.
Change history
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026HITRUST evidence addedA HITRUST row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
Similar vendors with evidence
Related by product tags and the Compliance and GRC category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.