🔒 Inside Kyotu Technology’s ISO 27001 Certification: How the Audit Actually Went
Kyotu Technology is now ISO/IEC 27001:2022 certified. The certificate is new; the way of working behind it isn't. We built our processes over years of delivering projects, then spent months aligning them with the ISO standard - and DEKRA's three-day on-site audit closed with no nonconformities. Here's why we went for it, what got checked, and what it means for you if you're our client today or thinking about making us your IT partner.
10 min read
In this Article:
- We hold ISO/IEC 27001:2022 certification, registration number 00082600610, issued by DEKRA Certification on 18 August 2026 – independently verifiable, not self-declared.
- The audit closed with no nonconformities, major or minor. The system it examined wasn’t built for the occasion – it grew from years of delivery practice, then months of aligning that practice with the ISO standard.
- The certified scope is our whole delivery model: enterprise IT systems, AI/ML/LLM, Blockchain and Big Data solutions, systems integration, and DevOps for IT and cloud infrastructure.
- 3.75 of the 5 total auditor-days went to ISO 27001 alone – from access and asset management to incident handling and business continuity.
- The certificate runs until 17 August 2029, with surveillance audits in 2027 and 2028. Certification is a cycle, not a trophy.
What is ISO/IEC 27001:2022?
ISO/IEC 27001:2022 is the current international standard for information security management systems (ISMS) – a certifiable framework that defines how an organization identifies security risks, picks and justifies controls, and proves in an external audit that those controls actually operate. The 2022 revision is the newest edition, with a restructured control set covering organizational, people, physical and technological safeguards.
The key word is certifiable. Anyone can claim to “take security seriously”. ISO 27001 replaces that claim with a third-party audit against a published standard, performed by an accredited body, with a public registration number you can verify without taking our word for anything.
Why did we do this – and what do we actually do better now?
Honest answer: we didn’t do it for a logo in the footer. We build and run systems that touch our clients’ data, source code and production environments. At some point “we’re careful” stops being a serious answer to the question of how that responsibility is managed – both for our clients and for ourselves.
The processes DEKRA examined weren’t written for the audit. They grew over years of shipping projects: paying close attention to what clients actually need, deciding fast, staying agile when scope shifts, treating quality as everyone’s job rather than a QA gate at the end. If you’ve read our values – responsibility, trust and honesty, quality, courage – that’s not a poster we wrote and then tried to live up to. It’s the other way around: we wrote down how the company already worked. Continuous improvement, kaizen, has been part of that culture from the start.
What the ISO project added was months of holding that practice against an international standard, line by line: checking where a good habit needed to become a defined system, closing gaps, writing down what lived in people’s heads. That alignment work changed real things in how we operate:
- Access is reviewed on a rhythm, not on a hunch. Who can reach which client environment, repository or system is checked regularly as a standing routine – not when someone happens to remember after a project ends.
- Every risk has an owner and a deadline. Our risk register isn’t a spreadsheet nobody opens. Each risk carries an owner, a treatment plan, a due date, a verification step and a residual-risk call. If it slips, it’s visible.
- Incidents end in changes, not just fixes. Every incident goes through analysis, and the output feeds training and process updates. The auditors specifically confirmed this loop works – findings actually change how we operate, instead of dying in a postmortem doc.
- We know what we protect. A maintained asset inventory with information classification means security decisions start from facts, not from someone’s memory of what’s where.
- Continuity plans are tested, not laminated. Business continuity isn’t a binder on a shelf – restore and continuity procedures get exercised, and the results feed back into the plans.
- Security questionnaires stopped being a fire drill. When a client’s vendor-risk team sends a 200-question security assessment, the answers now exist in a maintained system. What used to take weeks of chasing people takes days.
None of this required ISO 27001 in theory. In practice, an external audit with a hard date is what turns “we should systematize this” into “it’s systematized”. That was the point.
What does this mean for you – as our client, or a future one?
If you’re already working with us: the way we handle your environments, code and data has now been checked by an external auditor, end to end, against an international standard – and it passed clean. Access to your systems is governed by a reviewed process. If an incident touches your project, it’s handled through a tested procedure with analysis and follow-through, not improvisation.
If you’re considering us as your IT partner: your security, legal or procurement team gets an artifact they can verify in minutes – certification body, registration number 00082600610, scope, validity dates. In public tenders and corporate RFPs, especially in regulated industries and the DACH market, ISO 27001 is routinely a pass/fail requirement before proposals are even scored. We now clear that bar with an accredited certificate, and our Tenders & Procurement team handles exactly these formal requirements daily – certificate documentation is available for any proceeding.

And if your vendor-risk process runs on questionnaires rather than certificates: send it over. The answers come from a live system, not a scramble.
How does the certification process work?
Initial certification runs in two stages, and the distinction matters when you read any vendor’s claims.
Stage 1 is the readiness review. The certification body examines the ISMS documentation: scope, security policy, risk methodology, the Statement of Applicability, internal audit and management review records. One question: is this system mature enough to be audited for real?
Stage 2 is the implementation audit. Auditors verify the documented system operates in practice – by sampling records, interviewing the people who do the work, and tracing real processes end to end. DEKRA kept a 14-day gap between our Stage 1 and Stage 2, which gives the audit team time for an independent review of Stage 1 findings before fieldwork starts.
Our Stage 2 ran 15-17 July 2026, fully on-site at our Wrocław engineering office – no remote shortcuts. (Day to day you’ll also find us in Warsaw and through our partner offices in Germany and the US, but the auditors went where the engineering happens.) A two-person DEKRA team spent five auditor-days on the combined audit, 3.75 of them on ISO 27001. The method is representative sampling: they don’t check every record, they pull samples across every area in scope. For us, the clean result matters less as a badge and more as confirmation that the system holds up in daily practice, not just in documentation.
After certification, the clock keeps running. The certificate is valid three years, to 17 August 2029. Surveillance audits are already scheduled for 2027 and 2028, with recertification in 2029. An ISO 27001 certificate without annual surveillance behind it is expired by definition – always check the dates.

What did the auditors examine at Kyotu Technology?
Twelve operational areas: strategic and system management, sales and client requirements, project management and service delivery, software development, deployment and maintenance, personnel and competence, subcontractors and suppliers, asset and access management, systems and network security, information security, physical security, incident management, and business continuity.

A few verifiable facts from the audit itself – without opening up the internals of our security architecture:
- Statement of Applicability, dated 13 July 2026: every control carries a documented justification. The auditors confirmed no gaps in that reasoning.
- Risk assessment cadence: risk analysis runs at least annually and after every significant change to the organization, infrastructure or services.
- Legal compliance register: 34 legal acts under active monitoring – data protection, copyright, national cybersecurity regulations – with change tracking supported by external legal counsel.
- Full transparency: the DEKRA team confirmed in the report that nothing was withheld from review. Every record they asked for, they got.
Among the strengths the auditors singled out: a management system genuinely fitted to how the organization works (not a template bought off the shelf), well-organized security communication and handling, structured project and service management, formal supplier qualification, and – their words – a mature approach to infrastructure automation within business continuity.
Does a clean audit mean the work is done?
No, and we wouldn’t trust a vendor who claims otherwise. ISO 27001 certifies a management system – a mechanism for continuously finding weaknesses, planning improvements and verifying them – not a state of perfection. Our ISMS was built and certified in 2026; it’s a young system with a documented improvement backlog, and the annual surveillance audits exist precisely to check that the improvement loop keeps turning. That’s the honest reading of any ISO 27001 certificate on the market, including ours.
ISO 27001 vs SOC 2: which one should you ask your vendor for?
Both are legitimate third-party security attestations; they answer slightly different questions.
| ISO/IEC 27001:2022 | SOC 2 Type II | |
|---|---|---|
| What it is | Certification of an information security management system against an international standard | Attestation report on controls over a defined period, against AICPA Trust Services Criteria |
| Who issues it | Accredited certification body (here: DEKRA under PCA/IAF) | Licensed CPA firm |
| Output | Public certificate with registration number, verifiable scope and validity | Confidential report shared under NDA |
| Geography | Global default; standard requirement in EU and DACH procurement | Default expectation in the US market |
| Best fit when | You run formal procurement, public tenders, or EU/DACH enterprise onboarding and need a verifiable, standardized certificate | You are a US buyer whose vendor-risk process is built around SOC reports |
For European and DACH enterprise procurement – where most of our clients operate – ISO 27001 is the artifact formal processes ask for by name.
FAQ
Is Kyotu Technology ISO 27001 certified? Yes. Kyotu Technology Sp. z o.o. is certified against ISO/IEC 27001:2022, certificate registration number 00082600610, issued by DEKRA Certification Sp. z o.o. on 18 August 2026, valid until 17 August 2029.
What is the scope of Kyotu Technology’s ISO 27001 certification? The certified scope covers the design, development, implementation, and maintenance of custom enterprise-class IT systems and AI/ML/LLM, Blockchain, and Big Data solutions, integration of IT systems, and DevOps services for IT and cloud infrastructure management – as stated on the certificate.
Who issued the certificate and how can I verify it? DEKRA Certification Sp. z o.o., an accredited certification body operating under the Polish Centre for Accreditation (PCA, accreditation AC 151) with IAF Multilateral Recognition Arrangement coverage. The registration number 00082600610 can be verified with the certification body, and we provide the certificate document in any formal procurement proceeding.
Did the certification audit find any nonconformities? No. The Stage 2 certification audit in July 2026 closed with zero nonconformities – neither major nor minor – and the audit team recommended certificate issuance for the full scope.
How long is the certificate valid? Three years, until 17 August 2029, with surveillance audits scheduled for 2027 and 2028 and recertification in 2029. ISO 27001 is a continuous cycle, not a one-time achievement.
Was this a combined audit with ISO 9001? Yes – DEKRA audited our integrated management system against ISO 9001:2015 and ISO/IEC 27001:2022 in a single process. The ISO 9001 side of the story is covered in a separate post.
What this changes for our clients
Nothing about how we work – and that’s the point. The audit certified practices that were already operating: risk-based access control, supplier qualification, incident handling with a working improvement loop, tested continuity procedures. What changes is what you can verify: a registration number, an accredited issuer, a defined scope, and validity dates you can check without taking our word for anything.
If your procurement, security or vendor-risk process needs the certificate documentation, the audit scope statement, or answers to a security questionnaire – contact us or go straight to the Tenders & Procurement hub. That’s the team that turns compliance artifacts into submitted proposals.