"We are ISO 27001 certified." The line reassures in an RFP — until the buyer asks for the certificate and learns it covers headquarters and B2B managed services, not the shared plan where their application runs. That gap is common. It is the norm when nobody reads scope.
ISO/IEC 27001 attests that an organization has implemented an information security management system (ISMS) audited by a third party. At a host, that can be solid evidence — or a marketing shortcut if you confuse company certification with security of your server.
What ISO 27001 actually proves
A valid ISO 27001 certificate means an accredited auditor verified:
- a formal security policy;
- a documented risk assessment;
- selected controls (Annex A) justified in the SoA;
- processes for review, incidents, change, training;
- traceable continuous improvement.
What it does not automatically prove:
- that your site is hardened;
- that backups are tested for you;
- that support responds in 15 minutes;
- that the budget product meets the same bar as the certified enterprise line.
ISO 27001 describes how the host manages security — not how your application behaves on a Friday night.
Reading scope: certificate, SoA, annexes
Before scoring a comparison point, open three documents:
| Document | What it contains | Common trap |
|---|---|---|
| Certificate | Body, date, summary scope | Vague scope ("cloud services") |
| Statement of Applicability (SoA) | Controls adopted / excluded | Unexplained exclusions |
| Contract annex | Services actually covered | Sold product outside scope |
Ask directly: "Is my [exact offer name] included in the certificate scope?" A serious host answers in writing. Evasive sales talk deserves a second look.
ISO 27001 vs other badges: do not mix proofs
In the European market, ISO 27001 is often a credible baseline — especially at providers like Infomaniak or enterprise clouds — but it does not replace:
- HDS for health data;
- SecNumCloud for qualified cloud sovereignty;
- SOC 2 Type II sometimes required by US clients;
- your own GDPR obligations as controller.
Use ISO 27001 as a maturity filter: does the host have auditable security governance? Then add the sector frameworks your project requires.
When certification is real added value
Three cases where ISO 27001 changes the equation:
B2B due diligence. Enterprise clients send security questionnaires; ISO reduces friction — if scope covers your deployment.
Managed operations and outsourced administration. The more the host touches your system, the more an audited ISMS matters.
Comparing opaque providers. Two hosts at the same price: one publishing certificate + SoA beats one with only a shield icon.
For a personal blog or temporary landing page, requiring ISO 27001 may complicate buying without proportional gain. Match compliance spend to data sensitivity and client contractual requirements — not to logo collection on a sales page.
Ask whether the host publishes certificate and SoA proactively or only after legal review. Transparency at RFP stage often correlates with scope that actually covers the product you will buy.
The peak: certification protects the organization, not your negligence
Marketing turns this into a blanket promise: "ISO 27001 secure hosting." Reality is contractual and bounded. Your share — updates, access rights, encryption, restore tests — remains full.
Decide and move forward without blind spots
Download the certificate and note scope plus expiry date. Request the Statement of Applicability or a scope letter covering your product. Cross-check your GDPR, HDS or SecNumCloud obligations if applicable. Compare like for like via the directory and comparator. Archive evidence for your own client audits.
For the full regulatory picture, see GDPR, HDS, SecNumCloud — who needs what?.
Frequently asked questions
Does ISO 27001 automatically mean GDPR compliance?
No. ISO 27001 covers an ISMS — a management system for information security. GDPR imposes distinct legal obligations on data subjects' rights, legal bases and subprocessors. The two complement each other; one does not replace the other.
Does the certificate cover my VPS or shared hosting?
Not necessarily. Scope is defined in the certificate and Statement of Applicability. Verify your exact contractual offer is included — a datacenter certification does not automatically cover every retail hosting plan.
Is ISO 27001 equivalent to SecNumCloud or HDS?
No. Different frameworks with different legal weight. HDS is mandatory for health data in France; SecNumCloud addresses qualified cloud sovereignty; ISO 27001 attests an audited security management approach — useful, not a substitute.
What should you ask sales?
Request the full certificate, certification body, expiry date, scope and inclusion of your offer. Without the SoA, the logo is marketing decoration. Get written confirmation before you cite the certification in your own client contracts.
Next time a quote shows ISO 27001, ask for scope before price. A certificate without scope is a label — not proof.