Contacts
Get in touch
Close

We’re Now ISO 27001:2022 Certified. Here’s What Changes for Our Clients

13 Views

Summarize Article

 

Key takeaways

  • WebOsmotic is now certified to ISO/IEC 27001:2022, the current edition of the international standard for information security management systems, jointly published by ISO and IEC.
  • Annex A of the 2022 edition sets out 93 controls across four themes, replacing the 114 controls across 14 categories in the withdrawn 2013 edition.
  • Certification bodies stopped issuing or renewing ISO/IEC 27001:2013 certificates after October 31, 2025, following the accreditation industry’s three-year transition window, per Coalfire.
  • Vendor and supply chain compromise costs an average of $4.91 million per breach and takes 267 days to contain, the longest of any attack vector tracked, per IBM’s 2025 Cost of a Data Breach Report.
  • For clients, working with an ISO 27001 certified software development partner changes due diligence conversations, contract language, and incident response expectations from day one.

WebOsmotic has completed its ISO/IEC 27001:2022 certification audit. Our engineering organization is now an ISO 27001 certified software development partner, with an information security management system (ISMS) that covers the four control themes set out in Annex A of the standard: organizational, people, physical, and technological. This certification is what it now means to work with WebOsmotic as an ISO 27001 certified software development partner on any new or existing engagement.

Third-party involvement in data breaches reached 48% of all breaches analyzed in 2025, a 60% jump from the year before, according to Verizon’s 2026 Data Breach Investigations Report. When a client hands sensitive data, source code, or infrastructure access to a software partner, that partner becomes part of the client’s own attack surface. Certification is one way to show that surface is measured and controlled, not assumed. This article explains what the certification covers, what it does not cover, how to check a certificate before relying on it, and what changes for clients working with WebOsmotic starting now.

What ISO/IEC 27001:2022 certification actually verifies

Certification does not mean an organization has no security risk. It means an accredited third-party auditor confirmed that the organization runs a documented, tested management system for identifying and treating information security risk, and that the system holds up under review, not just on paper.

The four control themes an auditor checks

Annex A groups the standard’s controls into four themes:

  • Organizational controls – policies, roles, supplier relationships, and how the organization handles its own information security governance
  • People controls – background screening, security awareness, terms of employment, and disciplinary process
  • Physical controls – facility access, equipment security, and secure disposal of media
  • Technological controls – access management, cryptography, secure coding, network security, logging, and cloud service protections

Clients evaluating an ISO 27001 certified software development partner can map any specific requirement, encryption, background screening, incident logging, back to one of these four themes rather than taking a vendor’s word for it.

What the certified scope covers at WebOsmotic

Every ISO/IEC 27001:2022 certification applies to a defined scope, not to a company by default. WebOsmotic’s certified scope covers the engineering and delivery processes behind client software builds: access control to code repositories and client environments, secure development practices across the SDLC, incident detection and response, and the infrastructure our teams use to deliver and support projects. Our Statement of Applicability documents which of the 93 Annex A controls apply to that scope and the reasoning behind any exclusions, following the standard’s risk-based approach rather than a fixed checklist.

Why certification matters for vendor information security risk management

A certificate on a website is easy to claim. What it represents is not.

The data behind rising vendor risk

Third-party involvement in breaches climbed from 30% to 48% year over year, per Verizon’s 2026 DBIR, the largest single-year jump the report has recorded in nineteen editions. IBM’s 2025 Cost of a Data Breach Report puts the average cost of a supply chain compromise at $4.91 million, with a 267-day average lifecycle from detection to containment, longer than any other breach category the report tracks. Software vendors sit inside that exposure because they typically hold code access, infrastructure credentials, and client data by the nature of the engagement. Closing that exposure before a contract is signed, not after an incident, is exactly what working with an ISO 27001 certified software development partner is meant to demonstrate.

What client due diligence teams are actually asking for now

Buyers running a vendor information security risk management program increasingly ask for audit evidence directly rather than a self-reported questionnaire: the certificate itself, the Statement of Applicability, the certified scope, and confirmation of the current audit date. A documented risk management process treats a software partner’s certification status as a starting checkpoint, then verifies scope and currency before signing, since a 2013-era certificate or an out-of-scope claim tells a buyer very little.

What this means for procurement timelines

Procurement cycles that once took weeks of back-and-forth over a custom security questionnaire can move faster when a vendor already holds current, in-scope certification. Legal and security teams still review the documentation, but the review starts from an audited baseline instead of a blank form. For buyers managing several vendor evaluations at once, that difference compounds across a procurement calendar. Shortlisting an ISO 27001 certified software development partner earlier in the vendor search often removes an entire review cycle later.

What changes for clients working with an ISO 27001 certified software development partner

Contracts and due diligence

Security schedules in statements of work can reference the certified ISMS and its scope directly instead of building a custom security annex from scratch for each engagement. Clients can request the certificate, scope statement, and Statement of Applicability ahead of signing. This is one concrete advantage of working with an ISO 27001 certified software development partner instead of a vendor still building its security program from scratch.

Engineering and delivery practice

  • Access to client repositories and environments follows defined roles, approval steps, and periodic review, not informal permission grants
  • Secure coding and change management practices are audited annually against Annex A technological controls, not just documented in an internal wiki
  • Cloud infrastructure and cryptographic controls are reviewed as part of the certified scope

Incident response and audits

A tested incident response procedure with defined internal escalation and client notification timelines sits behind every engagement in scope. Surveillance audits occur on a set annual cycle, giving clients a recurring, independent check on whether the ISMS still holds up rather than a one-time certificate that goes unverified for years.

How to verify a software development partner’s ISO 27001 certificate

Before signing a statement of work, a few checks take minutes and remove most of the guesswork around a vendor’s security claims:

  • Confirm the certificate names the current standard, ISO/IEC 27001:2022, not the withdrawn 2013 edition
  • Ask which certification body issued it and confirm that body holds accreditation for the standard
  • Request the Statement of Applicability and confirm the certified scope covers the specific systems and teams that will handle your data, not just a head office function
  • Check the certificate’s issue and expiry dates, since certificates run on a three-year cycle with annual surveillance audits in between
  • Ask for the date of the last surveillance audit and whether any major nonconformities were raised, since a certificate alone says nothing about what happened at the most recent review

A vendor that hesitates to share this information is telling a buyer something too. An ISO 27001 certified software development partner with nothing to hide can produce all five items inside a single email.

ISO/IEC 27001:2022 vs the 2013 standard: what actually changed

Aspect ISO/IEC 27001:2013 ISO/IEC 27001:2022
Annex A structure 114 controls across 14 categories 93 controls across 4 themes
New controls N/A 11 new controls, covering areas including threat intelligence, cloud security, data masking, and secure coding
Current validity Expired for certification purposes as of October 31, 2025 Current edition; the only version certification bodies issue today
Structural alignment Pre-harmonized structure Aligned to the ISO/IEC Annex SL harmonized structure shared across management system standards

 

Choosing a certified software development partner today means confirming the certificate specifies the 2022 edition. A 2013 certificate presented as current, whatever the expiration date printed on it, reflects a withdrawn standard and no longer carries accredited assurance.

Partner with an ISO 27001 certified software development team for your next build.

WebOsmotic pairs certified information security practice with full-cycle engineering delivery, from architecture through production support.

Talk to Our Team 

 

Certification to ISO/IEC 27001:2022 does not remove the need for a client’s own security review. It gives that review a documented starting point: a tested ISMS, an annual audit cycle, and a Statement of Applicability naming exactly which of the 93 controls apply to the systems handling client data. For clients selecting an ISO 27001 certified software development partner for a new build or a long-term engagement, that starting point changes how fast due diligence closes and how specific the security conversation gets.

Frequently asked questions

What is ISO/IEC 27001:2022 certification?

ISO/IEC 27001:2022 is the current edition of the international standard for information security management systems, published jointly by the International Organization for Standardization and the International Electrotechnical Commission in October 2022. It sets requirements for identifying information security risks, selecting controls to treat them, and running the whole system through continual review. Certification means an accredited third-party auditor confirmed that an organization’s ISMS meets these requirements. For a software partner, this covers areas including access control, secure development practice, incident management, and infrastructure security.

Is ISO 27001:2013 still valid?

No. Certification bodies stopped recognizing ISO/IEC 27001:2013 certificates after October 31, 2025, following the three-year transition window the accreditation industry set once ISO/IEC 27001:2022 replaced it, per Coalfire’s transition guidance. A 2013 certificate presented today reflects an expired standard. Confirming that a partner’s certificate specifies “ISO/IEC 27001:2022” rather than the 2013 edition is now a standard step in any vendor risk assessment. Comparing an ISO 27001 certified software development partner against one still presenting a 2013 certificate is not a close call.

What does an ISO 27001 certified software development partner do differently?

An ISO 27001 certified software development partner runs its security controls through a documented, audited management system rather than informal practice. Access to client systems and repositories follows defined roles and periodic review, security incidents follow a tested response procedure with set reporting timelines, and the Statement of Applicability names which of the 93 Annex A controls apply to the engagement. Clients working with WebOsmotic can request this documentation directly instead of relying only on a standalone security questionnaire.

Does ISO 27001 certification cover every WebOsmotic project?

Certification applies to the scope defined on the certificate, the specific systems, teams, and processes included in the audit, rather than extending automatically to every future engagement by default. WebOsmotic’s certified scope covers the engineering and delivery processes used across client software builds. Clients can request the scope statement and Statement of Applicability to confirm exactly what is covered for their specific engagement before signing.

How does ISO 27001 relate to GDPR, SOC 2, and other frameworks WebOsmotic supports?

ISO/IEC 27001:2022 and frameworks such as GDPR or SOC 2 overlap without replacing one another. ISO 27001 certifies the information security management system itself. GDPR sets legal requirements for personal data belonging to EU residents. SOC 2 reports on specific trust service criteria over a defined period. Working with a partner certified to ISO/IEC 27001:2022 gives a client a documented ISMS as one input into GDPR technical control design or SOC 2 readiness, not a substitute for either.

Ready to build with WebOsmotic?

Get ISO 27001 certified delivery, GDPR and SOC 2 aligned engineering practice, and a security-first team on your project from day one.

Get in Touch 

Manali Kabrawala
Manali Kabrawala

Project Manager – Full Stack

Let's Build Digital Legacy!







    Unlock AI for Your Business

    Partner with us to implement scalable, real-world AI solutions tailored to your goals.