ISO/IEC 27001:2022 is the most widely recognised information security management standard in the world, and it’s referenced constantly in UK procurement processes, vendor due diligence questionnaires and cyber insurance applications — often without much explanation of what it actually certifies. If you’re evaluating a hosting or colocation provider (or being asked by your own customers whether you hold it), it’s worth understanding what the certification actually covers, and just as importantly, what it doesn’t.
What ISO/IEC 27001 actually certifies
ISO/IEC 27001 certifies an organisation’s Information Security Management System (ISMS) — the documented policies, risk assessment processes, controls and continuous improvement cycle an organisation uses to manage information security risk. It is not a certification of a single product, a single data centre building, or a one-off security test. It’s a certification that the organisation has a systematic, auditable, continuously-maintained approach to identifying and managing information security risks, and that it actually follows that approach in practice, not just on paper.
The 2022 revision (superseding the 2013 version) restructured the standard’s Annex A controls into four themes — organisational, people, physical and technological — and added or consolidated controls addressing areas that have become significantly more relevant since 2013: cloud security, threat intelligence, data masking, and secure development practices among them.
How certification actually happens
Certification is issued by an accredited certification body — in our case, BSI (British Standards Institution) — following a structured audit process, not a self-assessment. The certification body itself needs to be accredited by a national accreditation body; in the UK, that’s UKAS (the United Kingdom Accreditation Service). This accreditation chain matters: it means the certifying body’s competence and impartiality is itself independently verified, rather than a vendor simply issuing its own certificates.
Certification isn’t a one-off event. After the initial certification audit, organisations undergo annual surveillance audits and a full recertification audit every three years, with the certifying body able to suspend or withdraw certification if controls lapse. This is what separates genuine ISO 27001 certification from an organisation simply claiming to be “ISO 27001 compliant” without independent verification — the latter is a self-assessed claim with no external accountability attached.
What it means for a hosting or colocation provider specifically
For a data centre and hosting business, an ISO 27001-certified ISMS typically covers areas including: physical and environmental security controls for the facility, access control and identity management for both staff and systems, incident response and business continuity procedures, supplier and third-party risk management, change management, and asset management and disposal. Because it’s a management system certification rather than a facility certification, it also demonstrates that these controls are consistently applied across the organisation, not just within the walls of one building.
What it doesn’t mean
- It doesn’t guarantee zero security incidents — no certification can. It certifies the existence and operation of a systematic risk management process, not a guarantee of a specific outcome.
- It doesn’t automatically cover every service a company offers unless the certificate’s stated scope explicitly includes them — always check the certificate’s scope statement, not just the headline claim.
- It isn’t the same as Cyber Essentials or Cyber Essentials Plus, which are UK government-backed schemes focused on specific technical controls (patching, firewalls, access control, malware protection) rather than a full management system — many organisations hold both, as they address different things.
Why this matters for UK procurement and compliance
For UK businesses handling personal data, ISO 27001 certification of your infrastructure provider is strong supporting evidence (though not, on its own, sufficient proof) of the “appropriate technical and organisational measures” required under UK GDPR. It’s also increasingly a hard requirement in supplier due diligence for public sector contracts, financial services, and enterprise vendor onboarding — if you’re a business that needs to demonstrate strong supply-chain security to your own customers, using an ISO 27001-certified provider for your infrastructure removes one of the harder questions from that conversation.
MyHostingSpace, as part of DSM Group, holds ISO/IEC 27001:2022 certification issued by BSI, a UKAS-accredited certification body — you can see the certification detail on our security and compliance page. If you need certification detail or scope confirmation for your own vendor due diligence process, our team can provide that directly.

