ISO 27001 based on BSI IT-Grundschutz

For all data centres and cloud services.

One certificate, one number, one scope, with the report to download. For system houses, MSPs and software vendors who build their own evidence on it. You are an end customer? We will put you in touch with a suitable partner.

Certificate BSI-IGZ-0552-2023Issued by the BSIData centres and cloud services

What the certificate gives you

All of our operations, not one building

The scope covers all of our data centres and cloud services.

Evidence you can check

Certificate number BSI-IGZ-0552-2023. The certificate and the certification report are available here as a PDF.

A basis for your customers’ evidence

Anyone who has to assess their service providers under NIS2 or DORA can use the certificate as evidence for the part we run.

The evidence in the original

The certificate is only valid together with the complete certification report. That is why you get both in one file.

  • Siegel: ISO 27001 auf Basis von BSI IT-Grundschutz

    ISO 27001 based on BSI IT-Grundschutz

    Scope
    Data centres and cloud services
    Certificate no.
    BSI-IGZ-0552-2023
    Certificate as PDF
  • Siegel: PCI DSS

    PCI DSS v4.0

    Scope
    Physical Security / Colocation Services, Hanover location
    More about PCI DSS

What IT-Grundschutz adds compared with “ISO only”

Two routes to the same standard

Native ISO 27001 ISO 27001 based on IT-Grundschutz
Who issues the certificate an accredited certification body the BSI itself, after the audit by a BSI-certified auditor
Basis ISO/IEC 27001 with the controls from Annex A ISO/IEC 27001 with Annex A, plus the methodology under BSI Standard 200-2 and the IT-Grundschutz Compendium
How specific the requirements are The objectives are set; the company chooses the controls based on its own risk analysis. The Compendium sets out specific requirements for rooms, networks, systems and processes.
Risk analysis for the entire scope additionally for everything with high or very high protection requirements, under BSI Standard 200-3
Review annual surveillance audits annual surveillance audits
What you have in hand Certificate Certificate and certification report from the BSI

Native ISO 27001

Who issues the certificate
an accredited certification body
Basis
ISO/IEC 27001 with the controls from Annex A
How specific the requirements are
The objectives are set; the company chooses the controls based on its own risk analysis.
Risk analysis
for the entire scope
Review
annual surveillance audits
What you have in hand
Certificate

ISO 27001 based on IT-Grundschutz

Who issues the certificate
the BSI itself, after the audit by a BSI-certified auditor
Basis
ISO/IEC 27001 with Annex A, plus the methodology under BSI Standard 200-2 and the IT-Grundschutz Compendium
How specific the requirements are
The Compendium sets out specific requirements for rooms, networks, systems and processes.
Risk analysis
additionally for everything with high or very high protection requirements, under BSI Standard 200-3
Review
annual surveillance audits
What you have in hand
Certificate and certification report from the BSI

An honest assessment

IT-Grundschutz does not turn an ISO 27001 certificate into a different standard. It defines what the route there looks like: following a published methodology and with requirements that can be looked up for every module.

For your own assessment, that has a practical advantage. You can hold our controls against the same catalogue the auditor used. And besides the certificate, you get the BSI's report.

The certificate shows how we secure our operations. It does not show how you secure yours: systems and applications you run yourself on our infrastructure, your own ISMS and your NIS2 or DORA compliance lie outside it.

What the certificate shows

  • the information security of our operations
  • audited under the BSI certification scheme
  • valid together with the certification report

Scope: all data centres and cloud services

Certificate BSI-IGZ-0552-2023 applies to all of our data centres and cloud services. Colocation is covered just as our cloud services are.

The locations are listed in the box. How they are equipped is shown on the Data centres page.

  • DE01 Hannover, three availability zones (VZ-A, VZ-B, VZ-C)
  • DE02 Wolfsburg, more than 80 km away
  • DE03 Frankfurt, more than 250 km away
  • the Secure Public Cloud, run in Hanover and Wolfsburg

Four questions for any cloud provider, answered by us

A certificate answers the fourth question. The first three belong in the same assessment.

1

Who owns the data centre?

We do. Our own data centres in Hanover, Wolfsburg and Frankfurt; kyberio is German-owned.

2

Which law applies when it matters?

German law. The CLOUD Act does not apply to us.

3

Who has access?

Our own staff, by role, logged. Physical access only when registered and accompanied.

4

Can it be verified?

Through certificate BSI-IGZ-0552-2023 and on site: you can visit our data centres by arrangement.

The four questions in detail

Documents for your supplier assessment

Certificate and certification report

ISO 27001 based on BSI IT-Grundschutz, BSI-IGZ-0552-2023.

PDF, 1.7 MB

Security concept

Physical, digital and organisational security in our data centres.

PDF, 258 KB

Data processing agreement

Our data processing agreement under Art. 28 GDPR.

PDF, 153 KB

Questions about the ISO 27001 certification

Is ISO 27001 based on IT-Grundschutz a full ISO 27001 certification?

Yes. It covers the requirements of ISO/IEC 27001 including the controls from Annex A. On top of that come the methodology under BSI Standard 200-2 and the requirements of the IT-Grundschutz Compendium. The differences in detail are in the comparison above.

Who issued the certificate?

The Federal Office for Information Security (BSI). The audit was carried out by a BSI-certified auditor under the BSI certification scheme. You can download the certificate and report here.

Does your certificate make us NIS2 or DORA compliant?

No. It shows the information security of our operations. In your supplier or service provider assessment, you can use it as evidence for that part. The obligations for your own systems, processes and reporting channels remain with you.

Can we visit the data centre?

Yes, by arrangement. Write to us using the form below and we will agree a date with you.

We are not an IT service provider. Can we still work on your infrastructure?

Yes. We put you in touch with a kyberio partner who fits your project and looks after you. Write to us using the form below or look directly under Find a partner.

Questions about the evidence? Talk to us

Filling in a supplier questionnaire, or want to clarify the scope for your project? Write to us and we will get back to you personally.

  • No obligation, free of charge.
  • We refer end customers to a suitable partner.
If you are buying for your own company, we will put you in touch with a suitable partner.
A sentence or two is enough.

How we process your details is explained in our privacy notice.