
IT companies are a natural target audience for the ISO/IEC 27001 standard – they process customer data, manage critical infrastructure and provide services whose continuity is essential to their clients’ business operations. At the same time, the specific nature of the IT sector means that implementing the standard takes on a different character here than in manufacturing or service organisations – the scope of information assets is broader, the pace of technological change is faster, and the risks are more complex.
An IT company processes two types of sensitive information simultaneously: its own – strategic, commercial and HR data – and its clients’ data, which is often subject to non-disclosure agreements and regulatory requirements. This is a dual responsibility, and any breach carries a twofold risk: legal and reputational. Market pressure for ISO 27001 certification in the IT sector is stronger today than ever before. Large corporations and public institutions are increasingly requiring their IT suppliers to have a documented information security management system in place as a condition for participating in a tender or signing a contract. Certification eliminates the need to complete extensive security questionnaires and shortens the supplier qualification process.
The regulatory environment provides a further impetus. The NIS2 Directive, which came into force in October 2024, imposes an obligation on operators of essential and critical services – including many IT and telecommunications service providers – to implement specific cybersecurity risk management measures. ISO 27001 is widely recognised as one of the most effective ways of demonstrating compliance with these requirements. The DORA Regulation, which has been in force in the financial sector since January 2025, operates in a similar way – IT companies providing services to financial institutions must meet stringent requirements regarding operational resilience and ICT security.

ISO/IEC 27001:2022 is a general standard – it does not prescribe specific technologies or solutions, but requires a systematic approach to identifying assets, assessing risks and selecting appropriate security measures. In an IT company, several areas require particular attention.
Scope of certification – what to include and what to exclude? One of the first and most difficult decisions is to define the scope of the information security management system. An IT company may certify its entire range of activities or a selected area – for example, a specific service, product or data centre. Too broad a scope increases the complexity and costs of certification, whilst too narrow a scope may be questioned by clients or auditors. A well-defined scope is the foundation of effective certification.
Risk management in a dynamic environment. ISO 27001 requires a systematic risk assessment that is regularly updated. In IT companies, where new projects, technologies and interdependencies are constantly emerging, maintaining an up-to-date and reliable risk analysis is an organisational challenge. The ISO/IEC 27005:2022 standard, adopted in Poland as PN-EN ISO/IEC 27005:2025-01, introduces an approach whereby risk analysis is not a one-off assessment but a continuous, informed decision-making process.
Transition to ISO 27001:2022. Organisations holding a certificate issued under the 2017 version were required to update their systems to the new version of the standard. 31 October 2025 marked the final expiry date for certificates issued in accordance with ISO/IEC 27001:2017 – after this date, no organisation may retain a certificate based on the older version of the standard. Organisations planning to undergo certification from scratch must immediately take into account the requirements of the 2022 version, including the new Annex A with 93 security controls.