- Auditor
- Accredited certification body, annual surveillance audit
- Validity period
- Valid until 30 November 2027 · recertification every three years
ISO/IEC 27001:2022 — Information security management system
Scope: Operations of the systems, network and cloud platform including the associated management processes at locations fra1, fra2, ber1, muc1 and hel1
Covers
- Existence and effectiveness of an information security management system
- Systematic risk assessment and derivation of measures from Annex A
- Roles, responsibilities, training and document control
- Processes for changes, access rights, suppliers and incidents
Explicitly does not cover
- No statement on the technical security of a single product or API
- Not a substitute for a penetration test — the standard audits processes, not attack surfaces
- No statement on GDPR compliance; that is a different legal framework
- The scope is freely selectable — without looking at the certificate, “ISO 27001” says little



