Skip to content
Blog

ISO 27001 and 27017: Audit With Zero Findings

3 September 2026 | INGATE Team

On 1 September 2026 we completed the final day of our Stage 2 audit. The auditor recorded no findings and no nonconformities. INGATE will therefore be certified to ISO/IEC 27001 shortly, with our cloud services additionally covered by ISO/IEC 27017.

The certificate itself has not been issued yet. That decision is taken after the audit by a body within the certification organisation that is independent of it. This step is part of the accreditation rules and the reason some time passes between audit and certificate.

Stage 1 and Stage 2

Certification runs in two stages that examine different things. Stage 1 is the documentation review: scope, security policy, risk assessment, risk treatment plan, Statement of Applicability, plus the internal audit and management review.

Stage 2 examines live operation. The auditor requests evidence, traces individual cases from report through to implementation, inspects configurations and interviews staff across the company:

  • Access rights and their periodic review
  • Change and approval processes
  • Logging and monitoring
  • Supplier management and business continuity plans
  • Handling of security incidents
  • Employee onboarding and offboarding

Findings and Validity

Findings come in three levels. A major means a requirement is systematically unmet, and no certificate is issued while one is open. A minor is an isolated lapse in an otherwise functioning process and requires a corrective action plan with a deadline. An opportunity for improvement is not a nonconformity but a pointer. An accumulation of similar minors can be raised as a major.

An initial audit usually ends with several minors. Once issued, the certificate is valid for three years, with surveillance audits in each of the two following years and a recertification audit in Stage 2 scope at the end of the cycle. Failing a surveillance audit can cost the certificate mid-term.

What ISO 27017 Adds

ISO/IEC 27017 is not a standalone certificate. It extends the scope of an ISO 27001 certification and is audited alongside it. Unusually for a security standard, it gives separate implementation guidance for the provider role and the customer role across much of its content. It covers topics that only arise in cloud environments:

  • Division of responsibilities between provider and customer
  • Separation of virtual environments on shared hardware
  • Hardening of virtual machines
  • Traceability of administrative access
  • Monitoring, including what data the customer receives for it
  • Deletion and return of customer data at the end of a contract
  • Aligned security management for virtual and physical networks

A second edition of the standard was published in 2026 and aligned with the structure of the current ISO/IEC 27002.

A Certified Chain From Building to Process

All the data centres we use are certified to ISO 27001, covering physical security, access control, power and cooling. The audit just completed adds INGATE's own information security management system, meaning processes and organisation. The chain of evidence no longer stops at the data centre door.

A certificate is only meaningful together with its scope. Annex A of ISO/IEC 27001 and its 93 controls are likewise not a mandatory checklist: which ones apply follows from an organisation's own risk assessment and is justified in the Statement of Applicability. We will publish our scope once the certificate is issued.

What This Means for Our Customers

  • One certificate instead of your own assessment: If you are ISO 27001 certified yourself, you have to assess and monitor your service providers. An accredited certificate replaces your own audits and supplier questionnaires.
  • Data processing agreements: Article 32 GDPR requires technical and organisational measures reflecting the state of the art, and evidence of them. That evidence is what your data protection officers and auditors receive.
  • NIS2 and DORA: Germany's NIS2 implementation act has been in force since December 2025 and requires an estimated 30,000 organisations to secure their supply chain as well. For financial services, DORA has applied since January 2025, with a register covering all ICT third-party providers. In both cases the hosting provider falls within the scope of review.
  • Clear responsibilities in the cloud: ISO 27017 requires the split of responsibilities between provider and customer to be recorded rather than assumed. That includes deletion and return of your data at the end of a contract.
  • Checked continuously: Annual surveillance audits keep the evidence current instead of tying it to the day of certification.

Once the certificate is issued we will inform all customers directly and set out the scope alongside our cloud services.

Technology Partners & Memberships

Dell PartnerDirect
Equinix
EMC Home of Data
Juniper Networks
LiveConfig
Microsoft Cloud Solution Provider
Microsoft SPLA Partner
RIPE NCC Member