DocuSign, Inc.

United States · www.docusign.com · 44 vendors

DocuSign is a technology company that provides electronic signature and digital transaction management services. The company's platform allows users to send, sign, and manage documents electronically, eliminating the need for physical paperwork. DocuSign's services are used by individuals and businesses of all sizes to streamline their agreement processes.

Resilience scores

Disruption prediction

DocuSign, Inc. has a 99% probability of disruption in the next 6 months.

23 of DocuSign, Inc.'s 44 vendors monitored for disruptions.

Technology vendors

Services catalogue

9 services in catalogue across 4 categories; runs on 44 sub-vendors.

Insights

Last updated 2026-09-13 · revision 11

44 direct vendors, 345 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DocuSign exhibits high migration readiness from a technical perspective, driven by its modern, cloud-native, and microservices-based architecture. The internal tech stack leverages advanced cloud platforms (Microsoft Azure, Google Cloud Platform), AI/ML technologies (OpenAI, Google Gemini, vLLM, YOLOv9), and an API-first design (extensive REST APIs and SDKs). This technical foundation provides significant flexibility for adapting to new environments or migrating workloads between cloud providers. The company's strong financial growth indicates ample resources to fund complex migration initiatives. The multi-cloud strategy (Azure, GCP) also reduces lock-in to a single cloud provider, enhancing migration flexibility. However, several factors introduce significant complexity and potential challenges for a large-scale migration. DocuSign operates within an extremely complex and global regulatory environment, maintaining compliance with numerous stringent standards (GDPR, HIPAA, SOC 2, ISO 27001, FedRAMP, PCI DSS, eIDAS, CCPA/CPRA, BSI C5, FDA 21 CFR Part 11). Any migration would require meticulous planning and execution to ensure continuous adherence to these diverse requirements, particularly for regulated industries and government clients. The "NIS2 (Network and Information Security Directive 2)" is currently under "Assessment Required" status with a medium risk, representing a potential future compliance hurdle. Furthermore, DocuSign has extensive and specific data residency requirements across multiple regions (EU, Germany, Australia, Canada, US, Japan, Asia-Pacific). Maintaining these commitments during a migration, especially for sensitive customer data, would necessitate careful architectural design and potentially localized infrastructure deployments, adding considerable overhead. While the provided data states "Total Vendors: 0," which is inconsistent with the listed tech stack (Azure, GCP, OpenAI, Google Gemini are clearly vendors), assuming these critical dependencies exist, deep integrations with specific AI models and platforms could present technical lock-in challenges. Additionally, the "App Center" boasts 1,000+ third-party integrations, implying a vast ecosystem of dependencies that would need to be re-evaluated, re-established, or re-certified during a major migration. While technically capable, the sheer scale of regulatory, data residency, and integration complexities temper the overall migration readiness.

Compliance

13 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

DocuSign has proactively obtained EU Binding Corporate Rules (BCRs) as both a data processor and data controller — one of the most rigorous GDPR compliance mechanisms available. BCR approval requires extensive review by EU Data Protection Authorities. DocuSign also operates as a qualified Trust Service Provider (TSP) under eIDAS via Docusign France SAS, is listed on the EU Trusted List managed by ANSSI (France), and holds ISO 27001:2022, ISO 27017, and ISO 27018 certifications. The company serves 1.7 million customers globally including EU residents and enterprises, and has dedicated EU data residency options. The combination of BCR approval, eIDAS compliance, and robust certifications significantly reduces residual GDPR risk. Enforcement risk is low given the depth of documented compliance measures.

Evidence: https://www.docusign.com/trust/privacy/binding-corporate-rules, https://www.docusign.com/trust/compliance/certifications, https://www.docusign.com/trust/privacy, https://eidas.ec.europa.eu/efda/tl-browser/#/screen/tl/FR, https://www.docusign.com/trust

CPRA — Compliant

DocuSign is headquartered in San Francisco, California, and is subject to CCPA/CPRA as a large technology company processing personal data of California residents. DocuSign explicitly publishes a 'Notice to California Residents' on its website (linked in the footer of every page), demonstrating active CCPA compliance. As a company with revenues well exceeding $25M annually and processing data of millions of California residents, CCPA/CPRA obligations are clear. Risk is Low given the explicit public disclosure of California-specific privacy rights and the company's mature privacy compliance program evidenced by EU BCR approval.

Evidence: https://www.docusign.com/privacy#8, https://www.docusign.com/privacy, https://www.docusign.com/trust/privacy, https://www.docusign.com/trust/compliance/certifications

BSI C5 — Compliant

DocuSign has achieved C5 Type II compliance, which is the most rigorous level of C5 assessment (Type II tests operating effectiveness over a period of time, not just design). C5 is the German Federal Office for Information Security (BSI) standard for cloud service providers and is increasingly required for German public sector and regulated industry customers. Type II compliance demonstrates sustained, independently verified security controls. Risk is Low given the verified Type II compliance status.

Evidence: https://www.docusign.com/trust/compliance/certifications, https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html, https://www.docusign.com/de-de

Financials

Three-year financials

Financial Resilience Score: 8/10

DocuSign demonstrates strong financial resilience anchored by a highly recurring subscription revenue model (approximately 97-98% of revenue), which provides excellent visibility and predictability. The company has successfully transitioned from GAAP operating losses in FY2023 to positive operating income in FY2024 and FY2025, driven by cost discipline, workforce restructuring, and reduced share-based compensation as a percentage of revenue. Non-GAAP operating margins have expanded into the high-20s to around 30% range. The balance sheet is robust with a net cash position where cash and short-term investments comfortably exceed convertible debt, providing significant financial flexibility. Free cash flow generation has been consistent and strong, exceeding $800M annually in FY2024 and FY2025, enabling substantial share buybacks (authorizations over $1.0B) and self-funding of R&D investments. However, resilience is tempered by meaningful revenue growth deceleration from 19% in FY2023 to high single digits in FY2025, as the eSignature category matures. Dollar Net Retention Rate has declined from over 120% in FY2022 to around 100%, indicating slowing expansion within existing customers. The strategic pivot to Intelligent Agreement Management (IAM) carries execution risk, and competitive pressure from Adobe, Microsoft, and Dropbox Sign creates ongoing pricing challenges.

Key strengths: 97-98% recurring subscription revenue provides high visibility, Strong free cash flow generation (~$800M+ annually), Net cash position with cash exceeding convertible debt, Market leadership in eSignature with 1.7M+ customers, 95% of Fortune 500 as customers, Non-GAAP operating margins around 30%, Transition from GAAP operating losses to positive operating income

Risk factors: Revenue growth deceleration from 19% to high single digits, Dollar Net Retention Rate declined from >120% to ~100%, Competitive pressure from Adobe, Microsoft, Dropbox Sign, IAM platform product transition execution risk, Stock-based compensation dilutes shareholders significantly, Lengthening enterprise sales cycles due to macro conditions, Maturing eSignature category limits organic growth

Revenue by geography

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report