When a company or a public body buys in software from an external supplier, it is placing its data – and that of its customers or citizens – in the hands of a third party. The question very few organisations ask before signing the contract is: what security controls does that supplier have over my data?
ISO 27001 certification is the most objective answer to that question. Not because it is perfect or because it guarantees that an incident will never happen, but because it certifies that the supplier has an audited information security management system, with controls that are documented and continually improved.
This guide explains what ISO 27001 really certifies, how to read a certificate critically and what specific risks you take on if your software supplier does not have it.
What is ISO 27001?
ISO/IEC 27001 is the international standard that specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). The current version dates from 2022.
It is not a product certification (it does not certify that the software itself is secure). It is a process certification: it certifies that the organisation developing or managing the software has a management system with controls to protect the confidentiality, integrity and availability of information.
The Annex A controls of ISO 27001:2022 cover 93 areas, organised into 4 themes:
- Organisational controls: security policies, incident management, business continuity
- People controls: training, confidentiality agreements, remote working
- Physical controls: protection of data centres, access to premises
- Technological controls: access management, encryption, backups, security in software development
What ISO 27001 does and does NOT certify
What it does certify
- That the supplier has a documented security policy approved by senior management
- That there is a formal process for assessing and treating security risks
- That access to systems is controlled and audited
- That there is a security incident management process
- That software development follows documented security practices (controls A.8.25 to A.8.31 of the standard)
- That internal and external audits of the ISMS are carried out
- That senior management periodically reviews the system and approves improvements
What it does not certify
- That the software is free of vulnerabilities
- That the supplier will never suffer a security incident
- That every employee always follows the procedures
- That the technical infrastructure is secure in itself (that is assessed by other controls, such as penetration testing)
ISO 27001 is a management system, not an absolute technical guarantee. But a certified supplier is statistically less likely to suffer a serious incident and, if it does, it has defined processes for managing and reporting it.
How to read an ISO 27001 certificate
Not all ISO 27001 certificates are equal. Before accepting one as valid, check the following:
1. Certification body
The certification must have been issued by a body accredited by ENAC (Entidad Nacional de Acreditación, Spain’s national accreditation body) or by an equivalent body within the IAF (International Accreditation Forum). The most common in Spain are AENOR, Bureau Veritas, SGS, BSI Group, Applus and TÜV Rheinland.
A certificate issued by a body not accredited by ENAC or the IAF has no recognised validity. This happens more often than you might think: some companies display certificates from bodies whose accreditation is doubtful.
How to check: Go to the ENAC website (enac.es) → Entidades acreditadas (accredited bodies) → search for the body that issued the certificate. If it does not appear, the certificate is not valid.
2. Scope of the certificate
An ISO 27001 certificate has a defined scope: which activities, processes, systems or sites are included. A supplier may be certified for “software development for clients in the financial sector” and not for “technical support” or “cloud infrastructure”.
Check that the scope of the certificate includes the service you are going to buy. If the supplier is going to maintain your system in production but the certificate covers only development, the maintenance is not audited.
3. Validity dates
ISO 27001 certificates are valid for three years, with annual surveillance audits. Check that the certificate is in force and that the last surveillance audit took place less than 12 months ago.
4. Version of the standard
The current version is ISO/IEC 27001:2022. If the certificate refers to the 2013 version, the supplier may be in the process of transitioning, but it should have completed the transition by 31 October 2025 (the end of the transition period set by the IAF).
The risks of buying software without ISO 27001
GDPR risk
When you engage a software supplier that processes personal data belonging to your company or your customers, that supplier is a data processor under the GDPR. You are obliged to sign a data processing agreement with it and to check that it offers sufficient guarantees of compliance. If the supplier suffers a data breach and does not have ISO 27001, you, as the data controller, can be fined by the AEPD (the Spanish Data Protection Agency) for failing to exercise due diligence in selecting the processor.
GDPR fines can reach 4% of global annual turnover or €20 million, whichever is higher.
Business continuity risk
A supplier without formal business continuity management (which is one of the ISO 27001 controls) may be unable to provide its service after an incident. Without tested backups, a documented recovery plan and system redundancy, a ransomware attack or a hardware failure can leave your systems out of action for days or weeks.
Risk in tenders and contracts
In regulated sectors (the public sector, financial services, utilities, health), ISO 27001 is starting to appear as a minimum requirement in tender specifications. Working with an uncertified supplier can invalidate your compliance with the security requirements of the specifications and, in the public sector, can lead to termination of the contract.
Reputational risk
If one of your suppliers suffers a data breach that affects your customers, the public perception is that your company failed to take the necessary precautions, regardless of where legal liability lies. Selecting suppliers with recognised security certifications is part of the due diligence expected of any organisation.
ISO 27001 vs other security certifications
| Certification | What it covers | Who it matters to |
|---|---|---|
| ISO 27001 | Information security management system | Any company that handles sensitive information |
| ENS (Esquema Nacional de Seguridad, Spain’s National Security Framework) | Security for Spanish public sector systems | Suppliers to the Spanish public sector |
| SOC 2 | Security of cloud services (United States) | SaaS providers with North American clients |
| PCI DSS | Security of card payments | Companies that process card payments |
| TISAX | Security in the automotive industry | Suppliers to the automotive sector |
For most Spanish companies, the combination of ISO 27001 + ENS covers every contracting scenario: the private sector (ISO 27001) and the public sector (ENS). A supplier that holds both certifications can work with any type of client without security restrictions.
This is the combination CEDESA maintains, together with ISO 9001 and ISO 56001: its certifications page shows the issuing body and the scope of each one, which is exactly what this article recommends asking any supplier for.
Questions you should ask your software supplier
Before signing the contract, ask for answers to these questions in writing:
- Do you hold current ISO 27001 certification? Can I see the certificate and verify the issuing body?
- Does the scope of the certificate include the service I am going to buy?
- When was the last surveillance audit and what were the findings?
- Do you have a tested business continuity plan? How often do you test it?
- How do you manage security incidents? How quickly would you notify me of a breach affecting my data?
- What controls do you apply to secure software development? Do you carry out vulnerability assessments before go-live?
- How do you control your employees’ and subcontractors’ access to my data?
A supplier with genuine ISO 27001 certification should be able to answer all these questions with specific documentation, not generalities. If the answers are vague or there is reluctance to share information about the ISMS, that is a warning sign.