ISO 27001
Certified information security management system
Certified to ISO/IEC 27001:2022
The international benchmark for information security management systems. Plus ISO 27017 (cloud-specific controls) and ISO 27018 (privacy in the public cloud) as aligned extensions.
Overview
ISO/IEC 27001 is the international standard for information security management systems (ISMS). VxCloud is certified to the 2022 revision by an accredited certification body, with our ISMS covering the VxCloud cloud platform, corporate IT, development environments, and customer data handling. Our scope statement is available on request.
Beyond core 27001, we align with ISO/IEC 27017 (code of practice for cloud services) and ISO/IEC 27018 (protection of PII in public clouds) as extensions of the ISMS. Surveillance audits occur annually, with the full three-year recertification cycle conducted by our accredited certification body. Certificates and scope statements are available under NDA.
What's included
Production-grade capabilities, ready to enable in your workspace.
ISO 27001:2022 certified
Current revision of the standard. Certified by an accredited international certification body.
ISO 27017 aligned
Cloud-specific controls from the 27017 code of practice are implemented and documented in the ISMS.
ISO 27018 aligned
PII-in-public-cloud controls from 27018 apply to any personal data processed by VxCloud on customer behalf.
Annual surveillance audits
Each year between recertifications, the auditor verifies ongoing ISMS operation and addresses any nonconformities.
Full ISMS documentation
Policies, procedures, risk assessments, and Statement of Applicability available under NDA for customer audits.
Risk-based approach
ISMS is driven by continuous risk assessment, with controls proportional to identified risks, not checkbox compliance.
Business outcomes
Measurable impact teams see when they adopt iso 27001.
Annex A controls implemented
All applicable Annex A controls from ISO 27001:2022 are implemented, with justifications for any exclusions documented.
International procurement acceptance
ISO 27001 is recognized in every major market. European customers often require it as a procurement baseline.
Certificate validity with annual surveillance
Continuous ISMS operation between recertifications, with annual surveillance audits validating ongoing effectiveness.
GDPR alignment foundation
ISO 27001 + 27018 provide a strong technical foundation for GDPR Article 32 security-of-processing requirements.
How customers use it
Real scenarios from VxCloud customers across regulated industries and fast-moving teams.
German manufacturer subject to BSI IT-Grundschutz
ISO 27001 certificate + aligned 27017/27018 reports satisfy vendor due diligence for BSI-regulated environments.
Multinational bank with operations in 30 countries
ISO 27001 is the cross-jurisdictional lingua franca. One certificate replaces 20 country-specific questionnaires.
EU agency procurement process
ISO 27001 + GDPR compliance documentation clears the EU public-sector vendor assessment without bespoke questionnaires.
UK NHS trust vendor onboarding under DSP Toolkit
ISO 27001 is accepted evidence for the majority of DSP Toolkit security requirements.
Frequently asked questions
Still have questions? Our enterprise team answers within one business day.
Yes — the certificate and scope statement are available under NDA through your CSM or our trust center. The certificate identifies the accredited certification body and the current validity period.
Related enterprise capabilities
Ready to move forward with ISO 27001?
Talk to our enterprise team — we'll scope your requirements, map the right capabilities, and build a rollout plan tailored to your organization.