Skip to content

DocuSign configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On DocuSign, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the DocuSign connector needs.

Checks (7)

severity: medium Sign On Paper Enabled fix difficulty: easy #

Disable sign-on-paper to enforce electronic-only signatures

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Accounts and select the target account
  3. Open the Signing Settings section
  4. Locate the Allow Signers to Sign on Paper option and disable it
  5. Save changes to enforce electronic signatures only

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Signer Reassignment Enabled fix difficulty: easy #

Disable signer reassignment to prevent envelope forwarding to unintended recipients

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Accounts and select the target account
  3. Open the Signing Settings section
  4. Locate the Allow Signers to Change Recipients option and disable it
  5. Save changes to prevent signer reassignment

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium PowerForms Enabled fix difficulty: easy #

Disable PowerForms to prevent publicly accessible signing URLs

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Accounts and select the target account
  3. Open the Sending Settings section
  4. Locate the PowerForms option and disable it
  5. Save changes to prevent self-service signing URL creation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high No Signer Certificate Required fix difficulty: medium #

Enable digital certificate requirement for signers to strengthen document integrity

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Accounts and select the target account
  3. Open the Signing Settings section
  4. Locate the Require Signer Certificate or Digital Signature option and enable it
  5. Select the appropriate certificate type for your compliance requirements
  6. Save changes to enforce certificate-backed signing

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Recipient Domain Validation Disabled fix difficulty: medium #

Enable recipient domain validation to restrict which email domains can receive envelopes

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Accounts and select the target account
  3. Open the Sending Settings section
  4. Enable the Restrict Email Domains for Recipients option
  5. Add the list of allowed recipient email domains
  6. Save changes to enforce domain restrictions

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high No IP Restrictions fix difficulty: medium #

Configure IP address filtering to restrict API and web access to known corporate IP ranges

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Security Settings in the left-hand navigation
  3. Locate the IP Address Filtering or IP Restrictions section
  4. Enable IP address filtering and add your corporate IP address ranges in CIDR notation
  5. Verify that all legitimate users and systems fall within the allowed ranges before saving
  6. Save changes to enforce IP-based access control

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Bulk Recipients Enabled fix difficulty: easy #

Disable bulk recipients in Sending Settings unless required for documented business operations

  1. Sign in to the DocuSign Admin console at admin.docusign.com
  2. Navigate to Accounts and select the target account
  3. Open the Sending Settings section
  4. Locate the Enable Bulk Send option and disable it
  5. Save changes to restrict bulk recipient envelope sending

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More DocuSign checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial