VxCloud
Security & Compliance
🏅

ISO 27001

Certified information security management system

Certified to ISO/IEC 27001:2022

The international benchmark for information security management systems. Plus ISO 27017 (cloud-specific controls) and ISO 27018 (privacy in the public cloud) as aligned extensions.

27001:2022
Current standard
Accredited
Certification body
3 yr
Certificate validity
+27017/27018
Aligned extensions

Overview

ISO/IEC 27001 is the international standard for information security management systems (ISMS). VxCloud is certified to the 2022 revision by an accredited certification body, with our ISMS covering the VxCloud cloud platform, corporate IT, development environments, and customer data handling. Our scope statement is available on request.

Beyond core 27001, we align with ISO/IEC 27017 (code of practice for cloud services) and ISO/IEC 27018 (protection of PII in public clouds) as extensions of the ISMS. Surveillance audits occur annually, with the full three-year recertification cycle conducted by our accredited certification body. Certificates and scope statements are available under NDA.

What's included

Production-grade capabilities, ready to enable in your workspace.

ISO 27001:2022 certified

Current revision of the standard. Certified by an accredited international certification body.

ISO 27017 aligned

Cloud-specific controls from the 27017 code of practice are implemented and documented in the ISMS.

ISO 27018 aligned

PII-in-public-cloud controls from 27018 apply to any personal data processed by VxCloud on customer behalf.

Annual surveillance audits

Each year between recertifications, the auditor verifies ongoing ISMS operation and addresses any nonconformities.

Full ISMS documentation

Policies, procedures, risk assessments, and Statement of Applicability available under NDA for customer audits.

Risk-based approach

ISMS is driven by continuous risk assessment, with controls proportional to identified risks, not checkbox compliance.

Business outcomes

Measurable impact teams see when they adopt iso 27001.

100+

Annex A controls implemented

All applicable Annex A controls from ISO 27001:2022 are implemented, with justifications for any exclusions documented.

Global

International procurement acceptance

ISO 27001 is recognized in every major market. European customers often require it as a procurement baseline.

3 yr

Certificate validity with annual surveillance

Continuous ISMS operation between recertifications, with annual surveillance audits validating ongoing effectiveness.

EU-ready

GDPR alignment foundation

ISO 27001 + 27018 provide a strong technical foundation for GDPR Article 32 security-of-processing requirements.

How customers use it

Real scenarios from VxCloud customers across regulated industries and fast-moving teams.

European Enterprise

German manufacturer subject to BSI IT-Grundschutz

ISO 27001 certificate + aligned 27017/27018 reports satisfy vendor due diligence for BSI-regulated environments.

Global Finance

Multinational bank with operations in 30 countries

ISO 27001 is the cross-jurisdictional lingua franca. One certificate replaces 20 country-specific questionnaires.

Public Sector EU

EU agency procurement process

ISO 27001 + GDPR compliance documentation clears the EU public-sector vendor assessment without bespoke questionnaires.

Healthcare EU

UK NHS trust vendor onboarding under DSP Toolkit

ISO 27001 is accepted evidence for the majority of DSP Toolkit security requirements.

Frequently asked questions

Still have questions? Our enterprise team answers within one business day.

Yes — the certificate and scope statement are available under NDA through your CSM or our trust center. The certificate identifies the accredited certification body and the current validity period.

Related enterprise capabilities

Ready to move forward with ISO 27001?

Talk to our enterprise team — we'll scope your requirements, map the right capabilities, and build a rollout plan tailored to your organization.