DocuSign configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On DocuSign, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the DocuSign connector needs.
Checks (7)
severity: medium Sign On Paper Enabled fix difficulty: easy #
Disable sign-on-paper to enforce electronic-only signatures
- Sign in to the DocuSign Admin console at admin.docusign.com
- Navigate to Accounts and select the target account
- Open the Signing Settings section
- Locate the Allow Signers to Sign on Paper option and disable it
- Save changes to enforce electronic signatures only
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Signer Reassignment Enabled fix difficulty: easy #
Disable signer reassignment to prevent envelope forwarding to unintended recipients
- Sign in to the DocuSign Admin console at admin.docusign.com
- Navigate to Accounts and select the target account
- Open the Signing Settings section
- Locate the Allow Signers to Change Recipients option and disable it
- Save changes to prevent signer reassignment
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium PowerForms Enabled fix difficulty: easy #
Disable PowerForms to prevent publicly accessible signing URLs
- Sign in to the DocuSign Admin console at admin.docusign.com
- Navigate to Accounts and select the target account
- Open the Sending Settings section
- Locate the PowerForms option and disable it
- Save changes to prevent self-service signing URL creation
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high No Signer Certificate Required fix difficulty: medium #
Enable digital certificate requirement for signers to strengthen document integrity
- Sign in to the DocuSign Admin console at admin.docusign.com
- Navigate to Accounts and select the target account
- Open the Signing Settings section
- Locate the Require Signer Certificate or Digital Signature option and enable it
- Select the appropriate certificate type for your compliance requirements
- Save changes to enforce certificate-backed signing
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Recipient Domain Validation Disabled fix difficulty: medium #
Enable recipient domain validation to restrict which email domains can receive envelopes
- Sign in to the DocuSign Admin console at admin.docusign.com
- Navigate to Accounts and select the target account
- Open the Sending Settings section
- Enable the Restrict Email Domains for Recipients option
- Add the list of allowed recipient email domains
- Save changes to enforce domain restrictions
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high No IP Restrictions fix difficulty: medium #
Configure IP address filtering to restrict API and web access to known corporate IP ranges
- Sign in to the DocuSign Admin console at admin.docusign.com
- Navigate to Security Settings in the left-hand navigation
- Locate the IP Address Filtering or IP Restrictions section
- Enable IP address filtering and add your corporate IP address ranges in CIDR notation
- Verify that all legitimate users and systems fall within the allowed ranges before saving
- Save changes to enforce IP-based access control
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Bulk Recipients Enabled fix difficulty: easy #
Disable bulk recipients in Sending Settings unless required for documented business operations
- Sign in to the DocuSign Admin console at admin.docusign.com
- Navigate to Accounts and select the target account
- Open the Sending Settings section
- Locate the Enable Bulk Send option and disable it
- Save changes to restrict bulk recipient envelope sending
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10