Published on: April 4, 2024
5 min read
Learn how the Security Compliance team uses the Agile planning and security features in the GitLab DevSecOps Platform to manage the certification process.

We recently expanded our compliance certification portfolio to include the automotive industry's TISAX and to support the issuance of the first GitLab Dedicated SOC 2 Type 2. GitLab's Security Compliance team is a proponent of dogfooding our platform, including our integrated project management and security features, so we accomplished this expansion using the GitLab DevSecOps Platform.
In this blog, we'll share the details of how we successfully leveraged GitLab's native features to implement security controls, enabling us to scale our compliance efforts and deliver results faster. You'll also learn how you can put these features to work in your own organization.
Start using GitLab for compliance today with a free trial.
Our security certifications structure is built upon GitLab's Agile planning features, allowing us to deliver results faster by managing requirements centrally and streamlining our workflows. Using Agile planning features also enables end-to-end visibility throughout compliance audits.
These Agile planning features ensure that compliance teams are able to leverage the same platform as their engineers, promoting transparency and efficient delivery of results.
Each of GitLab’s security certifications has security and compliance requirements that must be operating effectively to achieve certification.
GitLab offers native features within the platform that enable security and the achievement of industry-standard requirements.
We leveraged these key security features for our certifications and you can, too:
- [ISO 27001:2022](https://www.iso.org/standard/27001) 5.3, 8.32
- [TISAX](https://portal.enx.com/en-us/tisax/) 5.2.1
2. Protected branch settings. These configuration settings allow administrators to set branch protections and limit what users can do based on their configured permissions. For our certifications, protected branches were inspected for relevant projects to support the following requirements: - AICPA TSC CC8.1 - ISO 27001:2022 8.32 - TISAX 5.2.1, 5.2.2
GitLab makes compliance easier than ever. Agile planning enables end-to-end visibility throughout the audit. and security is integrated into the design of the product, leading to faster, more comprehensive achievement of compliance requirements.
Here at GitLab we are always pursuing the expansion of our security certification portfolio to give our customers and community additional assurance as well as additional transparency into our information security practices.
Have a certification you’d like to see us work towards? Have questions about how your organization can set up your GitLab instance to utilize our compliance features? Drop us a line by emailing [email protected], we’d love to hear from you!
Enjoyed reading this blog post or have questions or feedback? Share your thoughts by creating a new topic in the GitLab community forum.
Share your feedback