731 901 601
ISO 27001 in the IT sector – specific requirements and the most common challenges

ISO 27001 in the IT sector – specific requirements and the most common challenges

IT companies are a natural target audience for the ISO/IEC 27001 standard – they process customer data, manage critical infrastructure and provide services whose continuity is essential to their clients’ business operations. At the same time, the specific nature of the IT sector means that implementing the standard takes on a different character here than in manufacturing or service organisations – the scope of information assets is broader, the pace of technological change is faster, and the risks are more complex.

Why ISO 27001 is particularly important for IT companies

An IT company processes two types of sensitive information simultaneously: its own – strategic, commercial and HR data – and its clients’ data, which is often subject to non-disclosure agreements and regulatory requirements. This is a dual responsibility, and any breach carries a twofold risk: legal and reputational. Market pressure for ISO 27001 certification in the IT sector is stronger today than ever before. Large corporations and public institutions are increasingly requiring their IT suppliers to have a documented information security management system in place as a condition for participating in a tender or signing a contract. Certification eliminates the need to complete extensive security questionnaires and shortens the supplier qualification process.

The regulatory environment provides a further impetus. The NIS2 Directive, which came into force in October 2024, imposes an obligation on operators of essential and critical services – including many IT and telecommunications service providers – to implement specific cybersecurity risk management measures. ISO 27001 is widely recognised as one of the most effective ways of demonstrating compliance with these requirements. The DORA Regulation, which has been in force in the financial sector since January 2025, operates in a similar way – IT companies providing services to financial institutions must meet stringent requirements regarding operational resilience and ICT security.

The specific nature of the standard’s requirements in the context of an IT company

ISO/IEC 27001:2022 is a general standard – it does not prescribe specific technologies or solutions, but requires a systematic approach to identifying assets, assessing risks and selecting appropriate security measures. In an IT company, several areas require particular attention.

  • Information asset management. IT companies have an extensive and rapidly changing portfolio of assets: source code, development environments, test data, access to client systems, technical documentation and licences. The standard requires all assets to be identified, assigned to owners and classified according to their value and sensitivity. In IT organisations, where environments and projects change every few weeks, maintaining an up-to-date asset register is one of the most challenging requirements in practice.
  • Access and identity management. Controlling access to systems, code repositories, production environments and customer data is one of the key areas covered in Annex A of the standard. ISO 27001:2022 introduces a new security measure concerning identity management and authentication, and also requires the application of the principle of least privilege and the regular review of access rights. In IT companies, where staff turnover and collaboration with subcontractors are high, access management procedures must be particularly rigorous and strictly enforced.
  • Secure software development lifecycle (SDLC). Annex A of ISO 27001:2022 sets out security requirements for software development and maintenance processes. IT companies must document how security is incorporated at every stage of the development lifecycle – from requirements, through design and coding, to testing and deployment. Issues such as security code reviews, management of external dependencies (open-source libraries) and vulnerability testing must be covered by a formal management system.
  • Incident management. The standard requires documented procedures for detecting, reporting, analysing and responding to security incidents. In an IT company, a security incident can have immediate consequences for customers – a system failure, a data leak from the production environment, or the compromise of a privileged account. The procedures must specify not only internal actions, but also the rules for communicating with customers and – in the event of a personal data breach – with supervisory authorities (UODO).

The most common challenges in IT sector certification

Scope of certification – what to include and what to exclude? One of the first and most difficult decisions is to define the scope of the information security management system. An IT company may certify its entire range of activities or a selected area – for example, a specific service, product or data centre. Too broad a scope increases the complexity and costs of certification, whilst too narrow a scope may be questioned by clients or auditors. A well-defined scope is the foundation of effective certification.

Risk management in a dynamic environment. ISO 27001 requires a systematic risk assessment that is regularly updated. In IT companies, where new projects, technologies and interdependencies are constantly emerging, maintaining an up-to-date and reliable risk analysis is an organisational challenge. The ISO/IEC 27005:2022 standard, adopted in Poland as PN-EN ISO/IEC 27005:2025-01, introduces an approach whereby risk analysis is not a one-off assessment but a continuous, informed decision-making process.

Transition to ISO 27001:2022. Organisations holding a certificate issued under the 2017 version were required to update their systems to the new version of the standard. 31 October 2025 marked the final expiry date for certificates issued in accordance with ISO/IEC 27001:2017 – after this date, no organisation may retain a certificate based on the older version of the standard. Organisations planning to undergo certification from scratch must immediately take into account the requirements of the 2022 version, including the new Annex A with 93 security controls.

 

Read other posts

Risk management without ISO 31000 – how many decisions in your company are made in the dark?

Risk management without ISO 31000 – how many decisions in your company are made in the dark?

Every company manages risk. It’s just that most do so unconsciously — through experience, intuition and reacting to what has already happened. read more
IFS Broker – a standard that clarifies the responsibilities of importers and commercial agents

IFS Broker – a standard that clarifies the responsibilities of importers and commercial agents

Within the food supply chain, there is a category of operators who never see the product with their own eyes, do not manage warehouses or a transport fleet, and yet bear real responsibility for its safety and quality. read more
How much does not having ISO 27001 cost? A bill that makes an impression

How much does not having ISO 27001 cost? A bill that makes an impression

Most companies that do not have ISO 27001 do not have it for one reason: the cost of implementation seems too high. read more
More posts