Security and compliance for Knowledge Base in Acrobat

Last updated on 28 Sep 2026

Review the current compliance status, security safeguards, and compliance resources available for Knowledge Base in Acrobat.

Compliance Roadmap for Knowledge Base in Acrobat

Knowledge Base in Acrobat is built on Adobe's audited cloud infrastructure and is designed from the ground up to meet the same compliance bar as Acrobat Sign. Formal certifications for Knowledge Base in Acrobat are in progress. This page explains what's available today and what's coming, so you always know exactly where things stand.

Where things stand today

  • Knowledge Base in Acrobat runs on infrastructure governed by Adobe's Common Controls Framework (CCF) — the same control framework underlying Adobe's Sign infrastructure.

  • Formal certifications and audit reporting that explicitly name these services are in progress and expected to be completed as part of our standard audit processes per the table below.

  • Because the Compliance List on the Adobe Trust Center only lists services with a completed, named attestation or report, Knowledge Base in Acrobat is not yet listed there. Certifications are typically posted after the close of our annual audit cycle and a mandatory validation period; we expect the Knowledge Base in Acrobat compliance certifications to be posted in the November/December timeframe. Until then, this page — along with direct conversations with your Adobe account team — provide the most current information on Knowledge Base in Acrobat's compliance and security posture. 

Available now

HIPAA-Ready: Adobe is prepared to enter into Business Associate Agreements (BAAs) covering this service. An external review report is currently in process.

Additional certifications in progress

Compliance program Status
SOC 2 Targeted by end of 2026
SOC 3 Targeted by end of 2026
ISO 9001 Targeted by end of 2026
ISO 27001 Targeted by end of 2026
ISO 27017 Targeted by end of 2026
ISO 27018 Targeted by end of 2026
ISO 22301 Targeted by end of 2026
CSA STAR Level 2 Targeted by end of 2026
BSI C5 Certification (Germany) Targeted by end of 2026
FedRAMP Tailored Targeted by end of 2026
EudraLex Volume 4, Annex 11 Targeted by end of 2026
FDA 21 CFR Part 11 Future release
FedRAMP Moderate TBD

A target date indicates work in progress. It doesn't mean that Knowledge Base currently holds the listed certification or assessment. 

Visit the Adobe Trust Center for our published certifications or contact your Adobe account team for the latest status specific to Knowledge Base in Acrobat.

Need more details for a security review?

A security overview with data-flow diagrams showing how Knowledge Base in Acrobat operates within that environment, is available here: Knowledge Base in Acrobat Security Overview  

Customers conducting a security or privacy review can request a documentation packet under NDA covering existing SOC 2 and ISO reports for Adobe's audited environment, with details on the controls that govern data handling. A completed CAIQ (Consensus Assessments Initiative Questionnaire) self-assessment is also available on request.

Contact your Adobe account team to request this packet.

Use Knowledge Base with HIPAA-regulated data

Knowledge Base is HIPAA Ready. Organizations that plan to process protected health information (PHI) must complete the applicable Business Associate Agreement (BAA) process with Adobe before using Knowledge Base for that purpose.

Contact your Adobe account team to begin the BAA process.

Customers with regulated use cases must also disable access to Knowledge Base collections from PDF Spaces before ingesting regulated data. Disabling the integration prevents users from linking Knowledge Base collections to PDF Spaces or accessing collection content through PDF Spaces. Other Knowledge Base access methods continue to operate.

Note

Disabling PDF Spaces integration doesn't by itself establish compliance with a regulatory framework. Don't process PHI in Knowledge Base until the applicable BAA process and HIPAA enablement are complete.

For the complete process and configuration requirements, see Enable HIPAA readiness for Knowledge Base in Acrobat.

Things to know

  • HIPAA Ready doesn't mean that every use of Knowledge Base automatically complies with HIPAA.
  • Compliance programs shown with a target date are still in progress.
  • Target dates can change while certification and assessment work is underway.
  • Your organization remains responsible for using Knowledge Base in accordance with its agreements with Adobe and applicable legal and regulatory requirements.
  • Detailed architecture and other controlled security information are available through the NDA documentation rather than this public Help page.