This is an old revision of the document!
ISO 27001:2022 Certification
Unicis is pursuing ISO 27001:2022 certification — an international standard that demonstrates our commitment to protecting customer data and information assets with industry-leading security practices.
What This Means for You
ISO 27001:2022 certification means:
- Your data is protected — We implement security controls aligned with international best practices
- Confidentiality — Customer compliance data is encrypted and access-controlled; only authorized people can access it
- Integrity — We detect and prevent unauthorized changes to your data
- Availability — Your data is backed up; we can recover from incidents quickly
- Incident response — If a security issue occurs, we detect it, investigate it, and fix it within hours
- Regular audits — Third-party auditors verify our controls are working
When we're certified, you can trust that Unicis protects your compliance data as seriously as banks protect financial data.
Why ISO 27001:2022?
ISO 27001 is the globally recognized standard for information security. It requires:
- Asset protection — Identifying and securing all information assets
- Access control — Only authorized people access sensitive data
- Encryption — Data is scrambled in transit and at rest
- Incident management — Rapid detection and response to security threats
- Risk assessment — Regular evaluation of security risks and controls
- Compliance — Supporting GDPR, NIS2, DORA, and other EU regulations
For a compliance software provider (like Unicis), ISO 27001 is essential trust for customers.
Our Security Commitments
As part of ISO 27001, Unicis commits to:
| Commitment | Target |
|---|---|
| Incident Detection | Detect 100% of security incidents via monitoring |
| Critical Incident Response | ≤ 2 hours to respond to P1 security incidents |
| Security Patch Deployment | ≤ 7 days for critical vulnerabilities |
| Access Control | 100% approval of access requests; revoke within 24h of employee departure |
| Audit Frequency | Annual third-party security audits |
| Encryption | All customer data encrypted at rest and in transit |
See the Scorecard for real-time performance against these security metrics.
Regulatory Support
ISO 27001:2022 helps Unicis comply with:
| Regulation | How ISMS Supports It |
| — | — |
| GDPR (EU) | Data protection and incident notification requirements |
| NIS2 (EU) | Cybersecurity measures for critical infrastructure |
| CRA (EU) | Cyber resilience for connected products |
| DORA (EU) | Digital operational resilience (for regulated entities) |
See NIS2 Scope and CRA Scope for details on how these regulations apply to Unicis.
Timeline
| Phase | Timing | Status |
|---|---|---|
| Foundation | Sept–Oct 2026 | Security policy & risk assessment |
| Implementation | Nov–Dec 2026 | Security controls documented and tested |
| Certification Audit | Jan–May 2027 | Third-party audit |
| Certified | May 2027 | ISO 27001 certificate issued |
Running in parallel with ISO 20000-1:2018 (service management).
Key Documentation
| Document | Purpose | Audience |
|---|---|---|
| Information Security Policy | Our security commitment and responsibilities | Customers & Partners |
| Risk Assessment Framework | How we identify and manage security risks | Customers & Partners |
| Security Performance Scorecard | Real-time metrics on incidents, patches, access control | Customers & Partners |
| Security Controls | Technical and organizational measures we implement | Customers & Partners |
Related
- IT Security Policy — Detailed security procedures
- ISO 20000-1:2018 — Service Management (parallel program)
Org Structure & Accountability
- Accountability Chart — Leadership roles (ISMS Sponsor, Security Implementation Lead)
- Leadership Team — Meet the Unicis team
- Quarterly Planning & Reviews — How we review security performance
Questions About Security?
Have questions about Unicis security or compliance?
→ Email us: security@unicis.tech