INFORMATION TECHNOLOGY
ISO certification for information technology
Define the service behind your technology.
Software, cloud interfaces, remote teams and support. Explore relevant standards and the scope information to prepare for EQRM.
ACTIVITIES TO DEFINE
01
Software delivery
02
Managed IT
03
Technical support
Illustrative activity groups. The agreed scope describes the actual organization and work assessed.
YOUR OPERATING CONTEXT
Start with your actual activities.
Technology providers may deliver software, support, managed services or internal business systems. Certification planning starts by identifying the services and organizational processes that will be in scope.
Explain the boundary between your own operation and the services supplied by cloud providers, contractors or other group entities. Include development, support, change management and customer-facing activities where they belong to the proposed scope. A product name alone rarely describes the full service arrangement.
A DEFINED MANAGEMENT SYSTEM
Make the boundary clear.
Identify the organization, activities and locations to be assessed. Explain interfaces with customers, suppliers and shared functions.
STANDARDS TO CONSIDER
Match the standard to the management need.
Use these subjects as a starting point for your enquiry. Each standard has its own requirements and may have a different scope.
QUALITY MANAGEMENT
ISO 9001
Customer requirements, delivery controls and improvement.
INFORMATION SECURITY
ISO/IEC 27001
Information risks, access and supplier interfaces.
BUSINESS CONTINUITY
ISO 22301
Critical activities, disruption and recovery arrangements.
Choose standards that align with your activities, objectives and operating sites.
SCOPE IN PRACTICE
Follow the responsibilities through the operation.
Consider a software company with a development team in one location and customer support in another. An enquiry should explain how both functions interact and where information is stored or accessed. It should not describe a narrow development scope as though it automatically covers all support operations.
Illustrative scenario, not an EQRM client case study or a prescribed control programme.
BEFORE YOU ENQUIRE
Bring the information that defines your scope.
01
Services, products and organizational functions included.
02
Remote teams, suppliers and shared infrastructure.
03
Customer information and service dependencies.
04
Existing certification and contract acceptance conditions.
Add approximate personnel numbers, a complete site list and any existing certificates. Mention planned changes such as new locations, services or operating shifts. These are enquiry prompts, not a complete audit-document checklist.
FREQUENTLY ASKED QUESTIONS
Information technology: common questions
Answers to common scope and application questions.
Which ISO standards can information technology organizations consider?
Relevant options may include ISO 9001, ISO/IEC 27001, ISO 22301, ISO/IEC 42001. They address different management subjects; select according to your activities and buyer requirements. The list does not make every standard mandatory or confirm availability for every proposed scope.
Is an ISO/IEC 27001 certificate the same as a SOC report?
No. They arise from different frameworks and assessment arrangements. Ask the customer which evidence it requires rather than describing one as an automatic substitute for the other.
Can remote teams be included in the certification scope?
Explain their activities, locations, information access and management arrangements. A distributed team can form part of the proposed scope, but the assessment arrangements depend on the actual operation and applicable programme.
Does a cloud provider’s certificate cover our software company?
No automatic coverage follows from using a certified provider. Describe your own development, configuration, access, support and customer responsibilities alongside the provider’s services.
What affects certification cost and timing for information technology?
The proposed scope, personnel, sites, operating patterns and relevant programme affect assessment planning. Readiness and the response to audit findings also affect timing. Provide this information to request a quotation; there is no universal price or guaranteed completion date.
KEEP EXPLORING
Follow the links relevant to your next decision.
Cybersecurity & data services
Managed security, hosting and data-service responsibilities.
Professional services
Assignments, associates, client information and review.
Reference: ISO’s explanation of certification. Linked standard pages provide publication references and further scope guidance.
YOUR NEXT STEP
Let’s discuss your organization.
Tell EQRM about your information technology activities, locations and the standard or customer requirement you are considering. We’ll review the proposed scope and assessment arrangements.