Independent comparison · no paid rankings
Home / Blog / Compliance / ISO 27001 certificate: verify scope rather than the logo

ISO 27001 certificate: verify scope rather than the logo

ISO 27001 on the sales slide often covers only headquarters and internal IT — not the shared datacenter where your VPS runs. The certificate is read in the appendix.

Hébergeurs.eu Editorial Team 3 min read Updated Jul 19, 2026

Your enterprise client requires "ISO 27001 host". You move to a certified provider. The client's auditor asks for the certificate: scope reads "Paris headquarters network administration" — not the public cloud offer where production lives. Valid certification; coverage of your service: none.

ISO 27001 attests an information security management system on an explicit scope — not a global "secure" promise. The logo opens the commercial door; the appendix decides whether you truly enter.

Read the certificate in three minutes

Start with the accredited certification body (COFRAC, UKAS, etc.). Check validity dates and surveillance audit frequency. Finally read the scope statement: which sites, which services, which exclusions.

Request the Statement of Applicability (SoA): Annex A controls retained or excluded, with justification. This document turns a logo into auditable evidence.

Scope elementGood signWarning signal
Listed services"EU-West IaaS"Vague "information systems"
SitesNamed datacenterHeadquarters only
ExclusionsDocumentedAbsent
SoAProvided under NDARefusal to share

ISO 27001 and your responsibility

A certified host generally covers internal governance, datacenter access, and provider incident processes. You remain responsible for OS configuration, application patches, accounts, tested backups, and keys. Certification does not replace instance hardening.

Compare with SOC 2 at the host if your US client requires both frameworks — each report has its own scope.

The climax: the logo reassures procurement, the appendix reassures auditors

Decide and move forward without blind spots

Obtain certificate and SoA before contract signature, then compare scope phrase to exactly purchased SKU. Archive dated version for client audit renewals. Add SOC 2 if the client requires it. Browse the directory and our guides to filter providers transparent on compliance.

Frequently asked questions

Does ISO 27001 guarantee my site is secure?

It attests an information security management system on a defined scope — not that your instance is configured correctly. Application hardening, accounts, and backups remain your responsibility.

Current valid certificate, Statement of Applicability (SoA), and scope appendix listing sites, services, and exclusions. Without these documents, the logo proves nothing about your contractual product.

Certified datacenter = certified shared hosting?

Not automatically. Scope may list "EU managed hosting platform" or only "corporate IT" — read the exact phrase before adding it to your compliance file.

Difference between ISO 27001 and SOC 2?

ISO 27001 is international ISMS certification. SOC 2 is a US attestation report on Trust Services criteria — complementary, each with scope to read line by line.


ISO 27001: the logo opens the door — the scope appendix decides whether you truly enter.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →