Qavirio Software · Systems · Digital solutions
ASSURANCE & CERTIFICATION

Assurance is evidence, not a marketing label.

Qavirio does not currently claim ISO, SOC 2 or ANSSI certification. For serious enterprise and public-sector work, independent assurance is nevertheless a concrete business objective. We publish both the path and the current boundary.

Current statusNO CERTIFICATION CLAIMED

Technical practices can align with standards without constituting certification. A certificate is only stated after it has actually been issued by a competent independent certification body.

Assurance roadmap
01

ISO/IEC 27001:2022

First formal target

Information Security Management System (ISMS): scope, risk management, Statement of Applicability, controls, evidence, internal audit, management review and continual improvement.

02

ISO/IEC 27701:2025

Privacy target after/alongside ISMS

Privacy Information Management System (PIMS) for organisations processing personal data as controller and/or processor.

03

ISO 9001

Quality-management target

Quality management for consistent delivery, customer expectations, processes and continual improvement. Qavirio will use the edition current at certification time.

04

Independent pentest

Product assurance

External penetration testing, vulnerability response and remediation evidence are separate production gates and do not replace management-system certification.

Path to demonstrable maturity
1

Scope & governance

Define legal entity, products, information assets, responsibilities and management-system purpose.

2

Gap assessment

Assess current technical and organisational controls against the selected standard.

3

Risk management

Build asset inventory, risk register, treatment plan and acceptance criteria.

4

Policies & evidence

Document and operate security, access, suppliers, incidents, change, backup, continuity, privacy and secure development.

5

Internal audit

Test evidence, record findings and execute corrective actions.

6

Management review

Formal review of risks, incidents, performance, suppliers and improvement actions.

7

Independent certification

Select an accredited certification body and complete Stage 1 and Stage 2 audits.

8

Continuous assurance

Treat surveillance audits, pentests, vulnerability handling and product evidence as ongoing work.

EU / PRODUCT SECURITY

EU Cyber Resilience Act

CRA is regulation, not a certification badge. Each product needs scope analysis covering secure development, vulnerability handling, support period, technical documentation and applicable reporting obligations. Qavirio treats this as product and governance work, not as a marketing claim.

EU / SUPPLY CHAIN

NIS2 & customer context

NIS2 is not a Qavirio certificate. Relevance depends on sector, organisation and supply-chain role. Qavirio still needs to provide security and supplier information customers require for their own governance and supply-chain risk.

FRANCE / CLOUD TRUST

SecNumCloud / hosting assurance

SecNumCloud qualifies a specific cloud service or offering. Hosting a Qavirio application on a qualified service does not automatically make the application itself SecNumCloud-qualified. Hosting assurance and application assurance remain separate claims.

Important nuance

ISO itself does not certify organisations. Certification is performed by external certification bodies. Qavirio will publish scope, certificate number, validity and certification body only after independent issuance.

Official references