ISO/IEC 27001:2022
First formal targetInformation Security Management System (ISMS): scope, risk management, Statement of Applicability, controls, evidence, internal audit, management review and continual improvement.
Qavirio does not currently claim ISO, SOC 2 or ANSSI certification. For serious enterprise and public-sector work, independent assurance is nevertheless a concrete business objective. We publish both the path and the current boundary.
Technical practices can align with standards without constituting certification. A certificate is only stated after it has actually been issued by a competent independent certification body.
Information Security Management System (ISMS): scope, risk management, Statement of Applicability, controls, evidence, internal audit, management review and continual improvement.
Privacy Information Management System (PIMS) for organisations processing personal data as controller and/or processor.
Quality management for consistent delivery, customer expectations, processes and continual improvement. Qavirio will use the edition current at certification time.
External penetration testing, vulnerability response and remediation evidence are separate production gates and do not replace management-system certification.
Define legal entity, products, information assets, responsibilities and management-system purpose.
Assess current technical and organisational controls against the selected standard.
Build asset inventory, risk register, treatment plan and acceptance criteria.
Document and operate security, access, suppliers, incidents, change, backup, continuity, privacy and secure development.
Test evidence, record findings and execute corrective actions.
Formal review of risks, incidents, performance, suppliers and improvement actions.
Select an accredited certification body and complete Stage 1 and Stage 2 audits.
Treat surveillance audits, pentests, vulnerability handling and product evidence as ongoing work.
CRA is regulation, not a certification badge. Each product needs scope analysis covering secure development, vulnerability handling, support period, technical documentation and applicable reporting obligations. Qavirio treats this as product and governance work, not as a marketing claim.
NIS2 is not a Qavirio certificate. Relevance depends on sector, organisation and supply-chain role. Qavirio still needs to provide security and supplier information customers require for their own governance and supply-chain risk.
SecNumCloud qualifies a specific cloud service or offering. Hosting a Qavirio application on a qualified service does not automatically make the application itself SecNumCloud-qualified. Hosting assurance and application assurance remain separate claims.
ISO itself does not certify organisations. Certification is performed by external certification bodies. Qavirio will publish scope, certificate number, validity and certification body only after independent issuance.