Skip to content
Find my data room
Data room terms / Security and compliance

ISO 27001

The short version

ISO/IEC 27001 sets out how an organization should run its security program as a managed cycle of risk assessment, controls and review. A certificate means an outside registrar has audited that cycle.

How it plays out on a deal

ISO 27001 is often required by European buyers and by banks that use it internally. Where SOC 2 reports on controls over a period, ISO 27001 certifies the management system that chooses and maintains those controls.

The certificate itself is short; the scope statement matters most. Check that it names the data room service and the locations that run it. A certificate that covers only a parent company's head office, or a data center operator, says little about the room you will use.

What to check in a review or demo

  1. 1Whether the certificate scope names the data room service.
  2. 2The issuing body, issue date and expiry, and whether it is accredited.
  3. 3Whether related standards, such as ISO 27017 or 27018 for cloud services, are also held.

ISO 27001: where the reviewed providers stand

Based on the certifications and attestations each provider lists publicly, as recorded in our review data. Ask for the current report or certificate and check its scope before relying on it.

Read alongside

Where this comes up on Data Room Review