Your enterprise client requires "ISO 27001 host". You move to a certified provider. The client's auditor asks for the certificate: scope reads "Paris headquarters network administration" — not the public cloud offer where production lives. Valid certification; coverage of your service: none.
ISO 27001 attests an information security management system on an explicit scope — not a global "secure" promise. The logo opens the commercial door; the appendix decides whether you truly enter.
Read the certificate in three minutes
Start with the accredited certification body (COFRAC, UKAS, etc.). Check validity dates and surveillance audit frequency. Finally read the scope statement: which sites, which services, which exclusions.
Request the Statement of Applicability (SoA): Annex A controls retained or excluded, with justification. This document turns a logo into auditable evidence.
| Scope element | Good sign | Warning signal |
|---|---|---|
| Listed services | "EU-West IaaS" | Vague "information systems" |
| Sites | Named datacenter | Headquarters only |
| Exclusions | Documented | Absent |
| SoA | Provided under NDA | Refusal to share |
ISO 27001 and your responsibility
A certified host generally covers internal governance, datacenter access, and provider incident processes. You remain responsible for OS configuration, application patches, accounts, tested backups, and keys. Certification does not replace instance hardening.
Compare with SOC 2 at the host if your US client requires both frameworks — each report has its own scope.
The climax: the logo reassures procurement, the appendix reassures auditors
Decide and move forward without blind spots
Obtain certificate and SoA before contract signature, then compare scope phrase to exactly purchased SKU. Archive dated version for client audit renewals. Add SOC 2 if the client requires it. Browse the directory and our guides to filter providers transparent on compliance.
Frequently asked questions
Does ISO 27001 guarantee my site is secure?
It attests an information security management system on a defined scope — not that your instance is configured correctly. Application hardening, accounts, and backups remain your responsibility.
What to request instead of the logo?
Current valid certificate, Statement of Applicability (SoA), and scope appendix listing sites, services, and exclusions. Without these documents, the logo proves nothing about your contractual product.
Certified datacenter = certified shared hosting?
Not automatically. Scope may list "EU managed hosting platform" or only "corporate IT" — read the exact phrase before adding it to your compliance file.
Difference between ISO 27001 and SOC 2?
ISO 27001 is international ISMS certification. SOC 2 is a US attestation report on Trust Services criteria — complementary, each with scope to read line by line.
ISO 27001: the logo opens the door — the scope appendix decides whether you truly enter.
