What ISO 27001 Certification Actually Means for Your Data Room (And What It Doesn’t)
Almost every data room provider puts “ISO 27001 certified” somewhere on their homepage. It’s become shorthand for “trust us,” which is exactly the problem: the badge tells you almost nothing about what was actually certified, who assessed it, or whether it covers the part of the business you’re relying on.
If you’re choosing a data room for a deal involving regulated data, client-confidential information, or government work, it’s worth knowing what the certification actually commits a provider to, and what questions to ask instead of taking the logo at face value.
Key takeaways:
- ISO 27001 certifies an organisation’s information security management system, not a specific product or feature, so scope matters more than the badge itself.
- A provider should be able to name their certification body, scope, and renewal date, not just claim the standard.
- ISO 27001 alone doesn’t tell you where your data is hosted. That’s a separate question worth asking directly.
What ISO 27001 actually certifies
ISO 27001 is an international standard for an information security management system, the policies, processes, and controls an organisation uses to manage security risk. It’s not a certification of a single product, a specific server, or a feature like encryption.
Being certified means an accredited third-party auditor has reviewed the organisation’s security processes (things like access control, incident response, staff vetting, and risk assessment) against the standard, and confirmed they’re being followed consistently. It’s renewed periodically, not a one-off badge earned and kept forever.
That distinction matters. A vendor can be “ISO 27001 certified” while the certification only covers a narrow part of their business, or while the scope excludes the specific service you’re about to rely on for a live deal.
What to ask a vendor before taking the badge at face value
What’s the scope of the certification? Ask specifically whether it covers the organisation as a whole, the hosting infrastructure, or just a subset of services. A vague answer is itself an answer.
Did you check the actual certification? Check the actual certificate. Often vendors share their hosting company’s ISO 27001 and claim it as their own. Check the certificate and the scope.
Who’s the certification body, and when was it last renewed? A legitimate certification has a named, accredited certification body and a renewal date. If a vendor can’t produce this on request, that’s worth noting.
Is it just ISO 27001, or is there more? ISO 27001 is a good baseline, but it’s not the only relevant standard. Cyber Essentials (a UK government-backed scheme), GDPR compliance tooling, and staff vetting standards like BS7858 each cover different ground. Projectfusion holds all four, alongside ISO 27001, because M&A, legal, and public sector clients typically need more than one of these covered, not just the headline certification.
What ISO 27001 doesn’t tell you
Certification tells you a security management process exists and is followed. It doesn’t tell you:
- Where your data is physically hosted. ISO 27001 says nothing about jurisdiction. A provider can be certified and still host data outside the UK or EU, which matters if data sovereignty is a requirement for your deal, particularly for government, legal, or regulated financial work.
- How the specific features you’ll use are built. Redaction, watermarking, and permission controls sit on top of the certified security processes; they aren’t guaranteed by the certification itself.
- Ongoing performance. Certification confirms a process was followed at the time of audit. It’s a floor, not a guarantee of how the provider behaves day to day.
This is why “UK hosted” and “ISO 27001 certified” are two separate claims worth checking independently, not one that implies the other. Our security and compliance page sets out both, hosting location and certification status, as distinct commitments rather than folding them into a single badge.
How the main certifications compare
Vendors often list several accreditations together without explaining what each one actually adds. Here’s the practical difference:
| Standard | What it covers | Why it’s relevant to a data room |
|---|---|---|
| ISO 27001 | Information security management system, processes and controls | Baseline assurance that security risk is managed systematically, not ad hoc |
| Cyber Essentials | UK government-backed scheme covering basic technical cyber hygiene | Often a requirement for UK public sector and government-adjacent work |
| GDPR compliance tooling | Data subject rights, lawful processing, data handling practices | Relevant whenever personal data moves through the room, which is most deals |
| BS7858 | Staff vetting and background-checking standard | Confirms the people with access to your data have actually been screened, not just the systems |
No single line item on this table substitutes for another. A provider holding all four gives a more complete picture than one holding just the headline ISO 27001 badge, which is why it’s worth asking about each separately rather than treating “certified” as a single yes/no answer.
Why this matters more for some deals than others
For a straightforward small transaction, the difference between vendors on paper certification detail may not change much in practice. For deals involving government bodies, regulated financial services, legal privilege, or cross-border data, it can matter a great deal.
Public sector procurement in particular often has specific hosting and jurisdiction requirements that go beyond ISO 27001 alone. If that’s relevant to your deal, it’s worth reading our separate breakdown of what to check for in public sector data room requirements before assuming any ISO-certified provider will do.
FAQ
Does ISO 27001 mean my data is hosted in the UK? No. ISO 27001 certifies security management processes, not hosting location. Ask the provider directly where data is physically hosted, and get it in writing if it matters for your deal.
Is ISO 27001 enough on its own, or should I look for other certifications too? It’s a solid baseline, but Cyber Essentials, GDPR compliance tooling, and staff vetting (BS7858) each cover ground ISO 27001 doesn’t. For regulated or high-sensitivity deals, look for more than one.
How can I verify a vendor’s ISO 27001 claim? Ask for the certification body’s name, the certificate number, and the scope statement. A legitimate certification is a matter of public record with the issuing body, so a vendor should be able to produce this without hesitation.
Check before you commit
Projectfusion has held ISO 27001 certification since 2016, alongside Cyber Essentials, GDPR compliance, and BS7858 staff vetting, and hosts data in the UK, EU, or globally depending on the client’s requirement. See the full detail on our security and compliance page, or read more about the company’s history on about us and accreditations.