~~NOTOC~~ ====== ISO 27001:2022 Certification ====== Unicis is pursuing **ISO 27001:2022 certification** — an international standard that demonstrates our commitment to **protecting customer data and information assets** with industry-leading security practices. {{tag>iso27001 information-security certification standards security}} ====== What This Means for You ====== ISO 27001:2022 certification means: * **Your data is protected** — We implement security controls aligned with international best practices * **Confidentiality** — Customer compliance data is encrypted and access-controlled; only authorized people can access it * **Integrity** — We detect and prevent unauthorized changes to your data * **Availability** — Your data is backed up; we can recover from incidents quickly * **Incident response** — If a security issue occurs, we detect it, investigate it, and fix it within hours * **Regular audits** — Third-party auditors verify our controls are working When we're certified, you can trust that Unicis protects your compliance data as seriously as banks protect financial data. ====== Why ISO 27001:2022? ====== ISO 27001 is the **globally recognized standard for information security**. It requires: * **Asset protection** — Identifying and securing all information assets * **Access control** — Only authorized people access sensitive data * **Encryption** — Data is scrambled in transit and at rest * **Incident management** — Rapid detection and response to security threats * **Risk assessment** — Regular evaluation of security risks and controls * **Compliance** — Supporting GDPR, NIS2, DORA, and other EU regulations For a compliance software provider (like Unicis), ISO 27001 is **essential trust for customers**. ====== Our Security Commitments ====== As part of ISO 27001, Unicis commits to: ^ Commitment ^ Target ^ | **Incident Detection** | Detect 100% of security incidents via monitoring | | **Critical Incident Response** | ≤ 2 hours to respond to P1 security incidents | | **Security Patch Deployment** | ≤ 7 days for critical vulnerabilities | | **Access Control** | 100% approval of access requests; revoke within 24h of employee departure | | **Audit Frequency** | Annual third-party security audits | | **Encryption** | All customer data encrypted at rest and in transit | See the [[pub:company:scorecard|Scorecard]] for real-time performance against these security metrics. ====== Regulatory Support ====== ISO 27001:2022 helps Unicis comply with: ^ Regulation ^ How ISMS Supports It ^ | **GDPR (EU)** | Data protection and incident notification requirements | | **NIS2 (EU)** | Cybersecurity measures for critical infrastructure | | **CRA (EU)** | Cyber resilience for connected products | | **DORA (EU)** | Digital operational resilience (for regulated entities) | See [[pub:trust_center:nis2_scope_determination|NIS2 Scope]] and [[pub:trust_center:cra_scope_determination|CRA Scope]] for details on how these regulations apply to Unicis. ====== Timeline ====== ^ Phase ^ Timing ^ Status ^ | **Foundation** | Sept–Oct 2026 | Security policy & risk assessment | | **Implementation** | Nov–Dec 2026 | Security controls documented and tested | | **Certification Audit** | Jan–May 2027 | Third-party audit | | **Certified** | May 2027 | ISO 27001 certificate issued | Running in parallel with [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018]] (service management). ====== Key Documentation ====== ^ Document ^ Purpose ^ Audience ^ | [[pub:trust_center:isms_policy|Information Security Policy]] | Our security commitment and responsibilities | Customers & Partners | | [[pub:trust_center:risk_framework|Risk Assessment Framework]] | How we identify and manage security risks | Customers & Partners | | [[pub:company:scorecard|Security Performance Scorecard]] | Real-time metrics on incidents, patches, access control | Customers & Partners | | [[pub:trust_center:controls|Security Controls]] | Technical and organizational measures we implement | Customers & Partners | ====== Related ====== * [[pub:trust_center:policies:it_security_policy|IT Security Policy]] — Detailed security procedures * [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018]] — Service Management (parallel program) * [[pub:trust_center:nis2_scope_determination|NIS2 Scope & Compliance]] * [[pub:trust_center:cra_scope_determination|CRA Scope & Compliance]] * [[pub:trust_center:vendor_questionnaires|Vendor Security Assessment]] * [[pub:trust_center:subprocessors|Trusted Subprocessors]] ====== Org Structure & Accountability ====== * [[pub:company:accountability_chart|Accountability Chart]] — Leadership roles (ISMS Sponsor, Security Implementation Lead) * [[pub:company:leadership|Leadership Team]] — Meet the Unicis team * [[pub:company:traction|Quarterly Planning & Reviews]] — How we review security performance ====== Questions About Security? ====== Have questions about Unicis security or compliance? → Email us: **security@unicis.tech** ---- ==== Navigation ==== ← [[pub:trust_center:iso_20000_1_overview|ISO 20000-1:2018]] | [[pub:trust_center|Trust Center →]] ---- //Last reviewed: October 2026 — next review: Q4 2026// {{tag>iso27001 information-security isms certification trust}}