for personal information comply with standards based on recognized laws and regulatory standards, including the OECD Privacy Guidelines, the EU General Data Protection Regulation (GDPR), the U.S. Health Insurance Portability and Accountability Act (HIPAA), APEC Privacy Framework, ISO 27001 International Standard for Information Security Management Systems, and other privacy laws and regulations globally. Access our TRUSTe certification stat
View source ↗Workday SOC 2 status and provider evidence
Review Workday’s public SOC 2 statement, report type, evidence source, and freshness.
Workday’s SOC 2 stack
No provider is named on the current source.
We will update this page if the company publishes more detail.
Frameworks named by Workday
ws and regulatory standards, including the OECD Privacy Guidelines, the EU General Data Protection Regulation (GDPR), the U.S. Health Insurance Portability and Accountability Act (HIPAA), APEC Privacy Framework, ISO 27001 International Standard for Information Security Management Systems, and other privacy laws and regulations globally. Access our TRUSTe certification status. Global Cross Border Privacy Rules (CBPRs) Certification and the Gl
View source ↗akon Employee Voice. Access our SOC 3 report for Workday Strategic Sourcing. Access our SOC 3 report for Workday Contract Intelligence and Contract Lifecycle Management (Evisort). ISO 27001, 27017, 27018, 27701 Workday maintains a comprehensive, integrated Information Security and Privacy Management System certified by Schellman Compliance, LLC. Our consolidated ISO certificate covers: ISO/IEC 27001:2022 – Core Information Security Management Sy
View source ↗cifically designed to provide data security and privacy, protect against security threats or data breaches, and prevent unauthorized access to your data. Our compliance resources. SOC 1 Applies to: Workday Enterprise Products, Workday Adaptive Planning, Workday VNDLY Service Organization Controls (SOC 1) reports provide information about a service organization’s control environment that may be relevant to the customer’s internal controls ove
View source ↗rance Reports on Controls at a Service Organization). The SOC 1 report covers the design and operating effectiveness of controls relevant to Workday enterprise cloud applications. SOC 2 Applies to: Workday Enterprise Products, Workday Adaptive Planning, Workday Strategic Sourcing, Workday Peakon Employee Voice, Workday VNDLY, HiredScore AI for Recruiting, HiredScore AI for Talent Mobility, Workday Contract Lifecycle Management, powered by Ev
View source ↗T Cybersecurity Framework and NIST 800-171 as part of the SOC 2+ Additional Subject Matter process, which includes an audited mapping of Workday controls against these frameworks. SOC 3 Applies to: Workday Enterprise Products, Workday Adaptive Planning, Workday Peakon Employee Voice, Workday Strategic Sourcing The AICPA has developed the SOC 3 framework for safeguarding the confidentiality and privacy of information that is stored and proces
View source ↗Primary compliance evidence
rance Reports on Controls at a Service Organization). The SOC 1 report covers the design and operating effectiveness of controls relevant to Workday enterprise cloud applications. SOC 2 Applies to: Workday Enterprise Products, Workday Adaptive Planning, Workday Strategic Sourcing, Workday Peakon Employee Voice, Workday VNDLY, HiredScore AI for Recruiting, HiredScore AI for Talent Mobility, Workday Contract Lifecycle Management, powered by Ev
Open source ↗