731 901 601
ISO 27001 in the IT sector – specific requirements and the most common challenges

ISO 27001 in the IT sector – specific requirements and the most common challenges

IT companies are a natural target audience for the ISO/IEC 27001 standard – they process customer data, manage critical infrastructure and provide services whose continuity is essential to their clients’ business operations. At the same time, the specific nature of the IT sector means that implementing the standard takes on a different character here than in manufacturing or service organisations – the scope of information assets is broader, the pace of technological change is faster, and the risks are more complex.

Why ISO 27001 is particularly important for IT companies

An IT company processes two types of sensitive information simultaneously: its own – strategic, commercial and HR data – and its clients’ data, which is often subject to non-disclosure agreements and regulatory requirements. This is a dual responsibility, and any breach carries a twofold risk: legal and reputational. Market pressure for ISO 27001 certification in the IT sector is stronger today than ever before. Large corporations and public institutions are increasingly requiring their IT suppliers to have a documented information security management system in place as a condition for participating in a tender or signing a contract. Certification eliminates the need to complete extensive security questionnaires and shortens the supplier qualification process.

The regulatory environment provides a further impetus. The NIS2 Directive, which came into force in October 2024, imposes an obligation on operators of essential and critical services – including many IT and telecommunications service providers – to implement specific cybersecurity risk management measures. ISO 27001 is widely recognised as one of the most effective ways of demonstrating compliance with these requirements. The DORA Regulation, which has been in force in the financial sector since January 2025, operates in a similar way – IT companies providing services to financial institutions must meet stringent requirements regarding operational resilience and ICT security.

The specific nature of the standard’s requirements in the context of an IT company

ISO/IEC 27001:2022 is a general standard – it does not prescribe specific technologies or solutions, but requires a systematic approach to identifying assets, assessing risks and selecting appropriate security measures. In an IT company, several areas require particular attention.

  • Information asset management. IT companies have an extensive and rapidly changing portfolio of assets: source code, development environments, test data, access to client systems, technical documentation and licences. The standard requires all assets to be identified, assigned to owners and classified according to their value and sensitivity. In IT organisations, where environments and projects change every few weeks, maintaining an up-to-date asset register is one of the most challenging requirements in practice.
  • Access and identity management. Controlling access to systems, code repositories, production environments and customer data is one of the key areas covered in Annex A of the standard. ISO 27001:2022 introduces a new security measure concerning identity management and authentication, and also requires the application of the principle of least privilege and the regular review of access rights. In IT companies, where staff turnover and collaboration with subcontractors are high, access management procedures must be particularly rigorous and strictly enforced.
  • Secure software development lifecycle (SDLC). Annex A of ISO 27001:2022 sets out security requirements for software development and maintenance processes. IT companies must document how security is incorporated at every stage of the development lifecycle – from requirements, through design and coding, to testing and deployment. Issues such as security code reviews, management of external dependencies (open-source libraries) and vulnerability testing must be covered by a formal management system.
  • Incident management. The standard requires documented procedures for detecting, reporting, analysing and responding to security incidents. In an IT company, a security incident can have immediate consequences for customers – a system failure, a data leak from the production environment, or the compromise of a privileged account. The procedures must specify not only internal actions, but also the rules for communicating with customers and – in the event of a personal data breach – with supervisory authorities (UODO).

The most common challenges in IT sector certification

Scope of certification – what to include and what to exclude? One of the first and most difficult decisions is to define the scope of the information security management system. An IT company may certify its entire range of activities or a selected area – for example, a specific service, product or data centre. Too broad a scope increases the complexity and costs of certification, whilst too narrow a scope may be questioned by clients or auditors. A well-defined scope is the foundation of effective certification.

Risk management in a dynamic environment. ISO 27001 requires a systematic risk assessment that is regularly updated. In IT companies, where new projects, technologies and interdependencies are constantly emerging, maintaining an up-to-date and reliable risk analysis is an organisational challenge. The ISO/IEC 27005:2022 standard, adopted in Poland as PN-EN ISO/IEC 27005:2025-01, introduces an approach whereby risk analysis is not a one-off assessment but a continuous, informed decision-making process.

Transition to ISO 27001:2022. Organisations holding a certificate issued under the 2017 version were required to update their systems to the new version of the standard. 31 October 2025 marked the final expiry date for certificates issued in accordance with ISO/IEC 27001:2017 – after this date, no organisation may retain a certificate based on the older version of the standard. Organisations planning to undergo certification from scratch must immediately take into account the requirements of the 2022 version, including the new Annex A with 93 security controls.

 

Read other posts

The benefits of implementing ISO 22000 – why food manufacturers who have it cannot imagine working without it

The benefits of implementing ISO 22000 – why food manufacturers who have it cannot imagine working without it

Ask a food manufacturer who has gone through the ISO 22000 implementation process if they regret the decision read more
AQAP – what is the quality standard for NATO suppliers and who does it apply to?

AQAP – what is the quality standard for NATO suppliers and who does it apply to?

Companies encountering the AQAP requirement for the first time often ask the same question: is it just another version of ISO 9001, or a completely different standard? read more
ISO 28000 – what a company actually gains when supply chain security is no longer left to chance

ISO 28000 – what a company actually gains when supply chain security is no longer left to chance

For years, supply chain security was treated as a cost rather than an investment. Companies reacted to incidents rather than preventing them. read more
More posts