compliance

4 posts

figma

Figma Achieves C5 Accreditation | Figma Blog (opens in new tab)

Figma has achieved C5 accreditation, Germany’s cloud security standard developed by the Federal Office for Information Security (BSI). The milestone strengthens Figma’s credibility with customers in Germany, Austria, and Switzerland by independently validating its security, availability, confidentiality, risk management, and operational transparency. It also supports organizations with strict regulatory and compliance requirements. ## C5 Accreditation and Cloud Security - C5 provides a recognized framework for evaluating cloud service security and reliability. - Independent accreditation confirms that Figma meets rigorous requirements for: - Information security - Risk management - Service availability - Confidentiality - Operational transparency - Figma is now listed in the BSI C5 register, allowing customers to review its security controls and operational practices more easily. ## Benefits for DACH Organizations - The accreditation gives organizations greater confidence when using Figma for cloud-based collaboration. - It is particularly relevant to customers in: - Government and the public sector - Financial services - Other highly regulated industries - Customers can more easily assess Figma against internal compliance, security, and assurance requirements. ## Continued Investment in the Region - Figma’s regional initiatives include: - Full German-language localization - European Union data storage options for enterprise customers - Expanded enterprise security and compliance capabilities - Nearly 90% of DAX 40 companies use Figma to design and build products collaboratively. Figma’s C5 accreditation reinforces its position as an enterprise-ready collaboration platform for organizations across the DACH region, especially those facing complex regulatory and security demands.

figma

Figma Deepens Roots in Australia with Local Data Hosting | Figma Blog (opens in new tab)

Figma is expanding its investment in Australia by introducing enterprise governance features and local hosting for Figma file data. Starting in Q4 2025, Australian customers will be able to store data locally, supporting organizations with strict security and compliance requirements. The move strengthens Figma’s position among regulated industries and marks its first data-residency offering in Asia Pacific. ## Local Data Hosting in Australia - Figma will host file data locally in Australia, including content from: - Figma - FigJam - Make - Sites - Buzz - Slides - Local hosting is intended for industries such as: - Government and the public sector - Healthcare - Financial services - The option provides greater control over data location while preserving Figma’s platform capabilities and scalability. - Australia is Figma’s first local data-hosting market in Asia Pacific, extending similar enterprise offerings already available in Europe and the United States. - Figma opened its Sydney office in November 2024 and serves customers including NAB, Safety Culture, and Atlassian. ## Governance+ for Enterprise Customers Governance+ gives enterprises more control over how employees access and use Figma. - **Centralized controls** - Enforce use of approved Figma instances and networks. - Use IP Allowlisting and Network Access Restrictions to prevent data from moving into unauthorized spaces. - **Account security** - Require two-factor authentication. - Extend idle session timeouts. - Support for multiple SSO configurations is planned. - **Data governance** - Monitor Figma activity through tools such as the Discovery Pipeline. - Support electronic communications retention and legal discovery requirements. ## Existing Enterprise Security Features Governance+ builds on existing enterprise capabilities, including: - Action logs - SAML single sign-on - Role assignments connected to identity-management systems - Restrictions on external collaborators joining an organization Governance+ is available now to customers on Figma’s Enterprise plan. Figma’s Australian data residency option will be particularly useful for organizations that must meet local storage, privacy, and regulatory obligations. Enterprise customers can adopt Governance+ immediately and register interest in local hosting ahead of its planned Q4 2025 launch.

figma

Figma Participates in TISAX Assessment for the European Automotive Industry | Figma Blog (opens in new tab)

Figma announced its participation in the Trusted Information Security Assessment Exchange (TISAX), a security and compliance benchmark for Europe’s automotive industry. The assessment is intended to reassure automotive customers that their design files are securely managed according to industry standards. Figma positions TISAX alongside its broader European data-protection efforts, including EU Cloud Code of Conduct certification and EU-based file hosting. ## TISAX and Automotive Data Security - TISAX is governed by the ENX Association on behalf of the German Automotive Industry Association (VDA). - It is widely recognized as a data-security and protection benchmark in Europe’s automotive sector, particularly in Germany. - Participation gives automotive product designers greater confidence that their Figma work is handled securely and compliantly. ## Figma’s Assessment Details Figma’s participation can be verified through the ENX portal using: - **Company:** Figma, Inc. - **Scope ID:** S3XH77 - **Assessment ID:** AV01AK-2 ## Broader European Compliance Efforts Figma describes TISAX as part of its wider investment in serving European customers: - It has received a compliance mark under the **EU Cloud Code of Conduct**. - Customers can choose to host Figma and FigJam files within the **European Union**. - These measures complement Figma’s broader security and compliance program. Figma’s participation in TISAX signals that organizations in the European automotive industry can use its collaborative design tools with greater assurance about security, compliance, and regional data-handling requirements.

figma

Figma's commitment to FedRAMP | Figma Blog (opens in new tab)

Figma is pursuing FedRAMP Moderate certification to make its collaborative design platform available to US government agencies and public-sector organizations. The certification process demonstrates that Figma meets rigorous security and privacy requirements and would allow government teams to safely design, prototype, and test digital services. Figma argues that its browser-based, collaborative workflow could help agencies iterate faster and improve citizen-facing software. ## FedRAMP Status and Purpose - Figma’s FedRAMP Moderate authorization is currently “in process.” - Listing on the FedRAMP Marketplace indicates that Figma has completed an audit and is moving through the final certification steps. - FedRAMP evaluates cloud applications against government security controls and categorizes them as low, moderate, or high impact. - Certification is necessary before Figma can fully host government data. ## Benefits for Public-Sector Users - Certification would allow government agencies, contractors, and civic-technology teams to: - Create software designs in Figma - Build and test interactive prototypes - Validate ideas through rapid iteration - Improve the usability of government applications - Figma says the certification will give customers confidence that their data and content meet demanding security and privacy standards. - Its browser-based and platform-agnostic design supports collaboration among distributed teams, including agencies and contingent workers. ## Public-Sector Collaboration and Modernization - The shift toward hybrid and remote work has increased demand for accessible, collaborative digital tools in government. - Figma connects this trend with broader efforts to improve customer experience and rebuild trust in government services. - The company believes public-sector organizations often work similarly to private companies despite having different missions and business models. - Collaborative design could help agencies ship services more quickly and achieve better outcomes for citizens. ## Building a Federal Government Team - Figma is expanding its federal-government organization, beginning with federal sales leader James Kohler. - The company is seeking people who understand government procurement and security requirements while also being able to build new programs from the ground up. - Kohler’s role is to adapt lessons from Figma’s private-sector work to the needs of government users. - Figma plans to encourage knowledge sharing between its commercial and government teams. ## Next Steps - Figma’s immediate goal is to complete FedRAMP certification and become authorized for federal use. - The company intends to continue engaging public-sector customers and sharing updates about its government efforts. Figma’s certification effort is a prerequisite for broader government adoption. If completed, the platform could give public-sector teams a secure way to collaborate on and rapidly improve digital services.