
Vendor-statedclickup and PCI DSS
clickup states it holds a PCI DSS attestation of compliance. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.
Evidence
What PCI DSS means, and what it does not
Only a registry listing (Visa Global Registry, Mastercard SDP) or an AOC letter is strong evidence. In the Visa registry only rows validated as PCI DSS with a validation date count; Third Party Agent registrations are not PCI evidence.
Read the PCI DSS guide and browse all vendors with evidenceQuestions buyers ask
Is clickup PCI DSS compliant?
clickup is listed as a PCI DSS validated service provider, as of 17 Sep 2026.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
Alternatives with PCI DSS evidence
Similar vendors (shared product tags or the Project management category) whose PCI DSS row is verified or vendor-stated, ranked by similarity.