
TRUSTED BY REGULATED ORGANIZATIONS
Awards, Reviews, and Compliance Certifications
See the ratings buyers trust, the badges reviewers award, and the certifications your security team requires — all verified, all in one place.
Independent reviews
Real ratings from real users
Verified users across platforms trust FormAssembly.
Recognized by reviewers and the industry
FormAssembly earns G2 badges each reporting period based on verified user reviews and market presence.
FormAssembly Named a Leader in SoftwareReviews Online Forms Data Quadrant Report
FormAssembly earned top ratings in innovation and product strategy in SoftwareReviews 2025 Online Forms Data Quadrant Report.
Based on user reviews submitted through the SoftwareReviews platform, the Data Quadrant evaluates software vendors across satisfaction, performance, and emotional sentiment, offering a 360-degree view of the user experience and long-term software satisfaction.
Compliance and certifications
FormAssembly is built for organizations that operate under regulatory scrutiny. Every certification below reflects an independent audit or authorization, not a self-assessment.
FedRAMP High Impact – Authorized
The U.S. government’s most rigorous cloud-security authorization, at the High impact level. Relevant for federal agencies and contractors handling sensitive government data.
Learn More
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality over time — not a point-in-time snapshot. The report IT and vendor-risk teams ask for during procurement.
Learn More
HIPAA
Supports compliant collection and handling of protected health information (PHI), with a BAA available. For healthcare providers, payers, and any organization touching patient data.
Learn More
PCI DSS
Meets the Payment Card Industry Data Security Standard for securely collecting cardholder data. For any team processing payments through their forms.
Learn More
Section 508 / WCAG Accessibility
Forms can meet federal accessibility requirements so public-facing services are usable by people with disabilities. For government and higher-ed buyers with accessibility mandates.
Learn More
GDPR
Tooling and data-handling practices that support GDPR obligations for EU personal data (data residency, DPA, subject-rights workflows). For any organization collecting data from EU residents.
Learn More
FERPA
Supports protection of student education records. For higher-ed and K-12 institutions.
Learn More
GLBA
Supports safeguarding of consumer financial information. For financial-services organizations.
Learn More
21 CFR Part 11
Supports FDA requirements for electronic records and e-signatures. For life-sciences and clinical-research organizations.
Learn More
ISO 27001
Internationally recognized certification for an information security management system (ISMS). A common baseline requirement in enterprise and international vendor-risk reviews.
Learn More
TX-RAMP — Certified
Texas state cloud-security certification. Required for vendors serving Texas state agencies
Learn More
CCPA
Supports compliance with California’s consumer privacy laws, including data subject rights and disclosure obligations for personal information. For any organization collecting data from California residents.
Learn MoreFrequently asked questions
What awards has FormAssembly won?
FormAssembly holds G2 badges earned through verified user reviews, including recognition such as Users Most Likely to Recommend, Highest User Adoption, and High Performer It is also recognized on Capterra, TrustRadius, GetApp, Software Advice, and Info-Tech SoftwareReviews.
What compliance certifications does FormAssembly have?
FormAssembly is FedRAMP High Impact authorized, SOC 2 Type II audited, and PCI DSS compliant, and it supports HIPAA, GDPR, FERPA, GLBA, 21 CFR Part 11, ISO 27001, CCPA, TX-RAMP, and Section 508 accessibility. FedRAMP High authorization in particular is rare among form and data-collection platforms, making FormAssembly a fit for government agencies and other highly regulated buyers.
Is FormAssembly HIPAA compliant?
Yes. FormAssembly supports HIPAA compliance for organizations collecting protected health information (PHI) and offers a Business Associate Agreement (BAA). This makes it suitable for healthcare providers, payers, and any organization handling patient data. FormAssembly also holds FedRAMP High authorization, SOC 2 Type II, and PCI DSS.
Is FormAssembly SOC 2 compliant?
Yes. FormAssembly is SOC 2 Type II audited, meaning an independent auditor has verified its controls for security, availability, and confidentiality over a defined period — not just at a single point in time.
Is FormAssembly FedRAMP authorized?
Yes. FormAssembly holds FedRAMP High Impact authorization, the U.S. government’s most rigorous cloud-security authorization level. This makes it suitable for federal agencies and contractors handling sensitive government data, and it is a distinction few form and data-collection platforms hold.
How does FormAssembly compare to other form builders on G2?
FormAssembly holds a G2 rating of 4.5 out of 5 stars across 400+ reviews and has received the High Performer badge. Its key differentiator is depth of compliance: FormAssembly carries FedRAMP High authorization and SOC 2 Type II, credentials that set it apart in the online form category. Buyers evaluating form platforms for regulated environments should compare compliance posture, not just feature lists.
Ready to try it for yourself?
Book a personalized demo of FormAssembly or request a free trial today.
