Unicis is pursuing ISO 27001:2022 certification — an international standard that demonstrates our commitment to protecting customer data and information assets with industry-leading security practices.
ISO 27001:2022 certification means:
When we're certified, you can trust that Unicis protects your compliance data as seriously as banks protect financial data.
ISO 27001 is the globally recognized standard for information security. It requires:
For a compliance software provider (like Unicis), ISO 27001 is essential trust for customers.
As part of ISO 27001, Unicis commits to:
| Commitment | Target |
|---|---|
| Incident Detection | Detect 100% of security incidents via monitoring |
| Critical Incident Response | ≤ 2 hours to respond to P1 security incidents |
| Security Patch Deployment | ≤ 7 days for critical vulnerabilities |
| Access Control | 100% approval of access requests; revoke within 24h of employee departure |
| Audit Frequency | Annual third-party security audits |
| Encryption | All customer data encrypted at rest and in transit |
See the Scorecard for real-time performance against these security metrics.
ISO 27001:2022 helps Unicis comply with:
| Regulation | How ISMS Supports It |
|---|---|
| GDPR (EU) | Data protection and incident notification requirements |
| NIS2 (EU) | Cybersecurity measures for critical infrastructure |
| CRA (EU) | Cyber resilience for connected products |
| DORA (EU) | Digital operational resilience (for regulated entities) |
See NIS2 Scope and CRA Scope for details on how these regulations apply to Unicis.
| Phase | Timing | Status |
|---|---|---|
| Foundation | Sept–Oct 2026 | Security policy & risk assessment |
| Implementation | Nov–Dec 2026 | Security controls documented and tested |
| Certification Audit | Jan–May 2027 | Third-party audit |
| Certified | May 2027 | ISO 27001 certificate issued |
Running in parallel with ISO 20000-1:2018 (service management).
| Document | Purpose | Audience |
|---|---|---|
| Information Security Policy | Our security commitment and responsibilities | Customers & Partners |
| Risk Assessment Framework | How we identify and manage security risks | Customers & Partners |
| Security Performance Scorecard | Real-time metrics on incidents, patches, access control | Customers & Partners |
| Security Controls | Technical and organizational measures we implement | Customers & Partners |
Have questions about Unicis security or compliance?
→ Email us: security@unicis.tech