ISO 27001 based on BSI IT-Grundschutz
For all data centres and cloud services.
One certificate, one number, one scope, with the report to download. For system houses, MSPs and software vendors who build their own evidence on it. You are an end customer? We will put you in touch with a suitable partner.
What the certificate gives you
All of our operations, not one building
The scope covers all of our data centres and cloud services.
Evidence you can check
Certificate number BSI-IGZ-0552-2023. The certificate and the certification report are available here as a PDF.
A basis for your customers’ evidence
Anyone who has to assess their service providers under NIS2 or DORA can use the certificate as evidence for the part we run.
The evidence in the original
The certificate is only valid together with the complete certification report. That is why you get both in one file.
-
ISO 27001 based on BSI IT-Grundschutz
- Scope
- Data centres and cloud services
- Certificate no.
- BSI-IGZ-0552-2023
-
PCI DSS v4.0
- Scope
- Physical Security / Colocation Services, Hanover location
What IT-Grundschutz adds compared with “ISO only”
Two routes to the same standard
| Native ISO 27001 | ISO 27001 based on IT-Grundschutz | |
|---|---|---|
| Who issues the certificate | an accredited certification body | the BSI itself, after the audit by a BSI-certified auditor |
| Basis | ISO/IEC 27001 with the controls from Annex A | ISO/IEC 27001 with Annex A, plus the methodology under BSI Standard 200-2 and the IT-Grundschutz Compendium |
| How specific the requirements are | The objectives are set; the company chooses the controls based on its own risk analysis. | The Compendium sets out specific requirements for rooms, networks, systems and processes. |
| Risk analysis | for the entire scope | additionally for everything with high or very high protection requirements, under BSI Standard 200-3 |
| Review | annual surveillance audits | annual surveillance audits |
| What you have in hand | Certificate | Certificate and certification report from the BSI |
Native ISO 27001
- Who issues the certificate
- an accredited certification body
- Basis
- ISO/IEC 27001 with the controls from Annex A
- How specific the requirements are
- The objectives are set; the company chooses the controls based on its own risk analysis.
- Risk analysis
- for the entire scope
- Review
- annual surveillance audits
- What you have in hand
- Certificate
ISO 27001 based on IT-Grundschutz
- Who issues the certificate
- the BSI itself, after the audit by a BSI-certified auditor
- Basis
- ISO/IEC 27001 with Annex A, plus the methodology under BSI Standard 200-2 and the IT-Grundschutz Compendium
- How specific the requirements are
- The Compendium sets out specific requirements for rooms, networks, systems and processes.
- Risk analysis
- additionally for everything with high or very high protection requirements, under BSI Standard 200-3
- Review
- annual surveillance audits
- What you have in hand
- Certificate and certification report from the BSI
An honest assessment
IT-Grundschutz does not turn an ISO 27001 certificate into a different standard. It defines what the route there looks like: following a published methodology and with requirements that can be looked up for every module.
For your own assessment, that has a practical advantage. You can hold our controls against the same catalogue the auditor used. And besides the certificate, you get the BSI's report.
The certificate shows how we secure our operations. It does not show how you secure yours: systems and applications you run yourself on our infrastructure, your own ISMS and your NIS2 or DORA compliance lie outside it.
What the certificate shows
- the information security of our operations
- audited under the BSI certification scheme
- valid together with the certification report
Scope: all data centres and cloud services
Certificate BSI-IGZ-0552-2023 applies to all of our data centres and cloud services. Colocation is covered just as our cloud services are.
The locations are listed in the box. How they are equipped is shown on the Data centres page.
- DE01 Hannover, three availability zones (VZ-A, VZ-B, VZ-C)
- DE02 Wolfsburg, more than 80 km away
- DE03 Frankfurt, more than 250 km away
- the Secure Public Cloud, run in Hanover and Wolfsburg
Four questions for any cloud provider, answered by us
A certificate answers the fourth question. The first three belong in the same assessment.
Who owns the data centre?
We do. Our own data centres in Hanover, Wolfsburg and Frankfurt; kyberio is German-owned.
Which law applies when it matters?
German law. The CLOUD Act does not apply to us.
Who has access?
Our own staff, by role, logged. Physical access only when registered and accompanied.
Can it be verified?
Through certificate BSI-IGZ-0552-2023 and on site: you can visit our data centres by arrangement.
Documents for your supplier assessment
Certificate and certification report
ISO 27001 based on BSI IT-Grundschutz, BSI-IGZ-0552-2023.
PDF, 1.7 MBQuestions about the ISO 27001 certification
Is ISO 27001 based on IT-Grundschutz a full ISO 27001 certification?
Yes. It covers the requirements of ISO/IEC 27001 including the controls from Annex A. On top of that come the methodology under BSI Standard 200-2 and the requirements of the IT-Grundschutz Compendium. The differences in detail are in the comparison above.
Who issued the certificate?
The Federal Office for Information Security (BSI). The audit was carried out by a BSI-certified auditor under the BSI certification scheme. You can download the certificate and report here.
Does your certificate make us NIS2 or DORA compliant?
No. It shows the information security of our operations. In your supplier or service provider assessment, you can use it as evidence for that part. The obligations for your own systems, processes and reporting channels remain with you.
Can we visit the data centre?
Yes, by arrangement. Write to us using the form below and we will agree a date with you.
We are not an IT service provider. Can we still work on your infrastructure?
Yes. We put you in touch with a kyberio partner who fits your project and looks after you. Write to us using the form below or look directly under Find a partner.
Questions about the evidence? Talk to us
Filling in a supplier questionnaire, or want to clarify the scope for your project? Write to us and we will get back to you personally.
- No obligation, free of charge.
- We refer end customers to a suitable partner.