Two EU hosts display ISO 27001. One certifies shared line and two DCs; another Public Cloud three countries but excludes managed backups. Same logo, incomparable without annexes.
Classic tender mistake: score certificate not score scope for real scenario.
Two certificates side by side without SoA prove nothing.
Five-line grid
Certified product, regions, backups, legal entity, expiry — fill your stack column before PDFs.
| Criterion | Host A | Host B | Your stack |
|---|---|---|---|
| Product | ? | ? | VPS / K8s |
Three-step method
Fixed common scenario. Same documents both vendors. Line-by-line match. OVHcloud ISO, Hetzner, Infomaniak.
Europe traps
Group cert vs billing entity, cloud scope without product list, 27017/18 confused with 27001, exclusions on services you use.
The peak: compare without annexes = fiction
RFP: one ISO yes line is not enough
Tender grids awarding one point for ISO certification without annexes produce fictional short lists. Demand certificate, statement of applicability, scope annex for exact product ordered — shared, public cloud, managed mail — and match each architecture component.
Uncovered gap is not always disqualifying if named, quantified, compensated. Ignored gap becomes audit finding.
Go further with the inquiry
Apply the article to your concrete case: what volume, what service level, what contractual constraints from clients or regulators? Write answers before opening the pricing page. Request written documents — full grid, DPA, certification scope, renewal terms — not homepage screenshots.
Compare at least two providers via the directory and compare tool on identical thirty-six-month assumptions. Share the short list with whoever signs the contract and whoever operates infrastructure daily. Archive terms dated at subscription so due diligence is defensible later.
Go further with the inquiry
Apply the article to your concrete case: what volume, what service level, what contractual constraints from clients or regulators? Write answers before opening the pricing page. Request written documents — full grid, DPA, certification scope, renewal terms — not homepage screenshots.
Compare at least two providers via the directory and compare tool on identical thirty-six-month assumptions. Share the short list with whoever signs the contract and whoever operates infrastructure daily. Archive terms dated at subscription so due diligence is defensible later.
RFP: one ISO yes line is not enough
Tender grids awarding one point for ISO certification without annexes produce fictional short lists. Demand certificate, statement of applicability, scope annex for exact product ordered — shared, public cloud, managed mail — and match each architecture component.
Uncovered gap is not always disqualifying if named, quantified, compensated. Ignored gap becomes audit finding.
RFP: one ISO yes line is not enough
Tender grids awarding one point for ISO certification without annexes produce fictional short lists. Demand certificate, statement of applicability, scope annex for exact product ordered — shared, public cloud, managed mail — and match each architecture component.
Uncovered gap is not always disqualifying if named, quantified, compensated. Ignored gap becomes audit finding.
Decide and move forward without blind spots
Start by framing your real scenario on one page: volumes, client constraints, required support level, and a thirty-six-month budget including domain, backup, and essential add-ons. Compare at least two hosts via the directory and compare tool with identical assumptions, archive pricing grids dated on subscription day, then have both the contract signer and daily infrastructure operator validate the short list.
Frequently asked questions
Two ISO equivalent?
No — compare scope, SoA, products.
Which documents?
Certificate, SoA, scope annex, expiry.
Align product first?
Yes — harmonize scenario before scoring.
ISO replaces GDPR DPA?
No — complementary frameworks.
Compare annexes, not logos.
