Revial is now ISO 27001 certified
Revial was awarded the ISO/IEC 27001:2022 certificate on 15 September 2026.
I had the privilege of leading this project from start to finish. I’m writing this text because six months ago I went looking for something like it myself, and found nothing. There seems to be a need for it, because during the process I’ve spoken with many different companies about how a certificate like this is done in practice and what it really takes.
In a situation like ours in particular there are plenty of interesting peculiarities, when your own team is relatively agile and your customers are often global, often listed companies, always giants.
Why take on an ISO project?
The idea of pursuing an ISO 27001 certificate came from a practical, everyday need. Our product is used in exactly the industries where vendor assessment is at its heaviest. Among our customers are organisations in healthcare, banking and insurance, staffing services and industry, to name a few of the most central sectors. Selling solutions like Revial’s to these companies is interesting in the sense that the decision to buy is made relatively early in the buying process. After that decision begins the longest and most complex phase, which is the various reviews of the new technology carried out by legal, IT and procurement.
Revial processes the content of sales conversations. They almost always contain various kinds of sensitive information. When a commercial decision is made to adopt Revial, IT’s and Legal’s ears prick up, and rightly so. The field is full of very different players whose information security and responsibility practices rest on shaky ground. We have to be able to demonstrate reliably that our house is in order now and in the future. You can provide that proof with a comprehensive security questionnaire filled in separately for each customer, which takes days on end. Or you can obtain a certificate that shows things are in order. Once the undersigned had spent a solid year filling in various customers’ security questionnaires, we decided it was time to get certified.
What the process was like
What makes doing an ISO 27001 certificate both interesting and, on the other hand, a little frustrating is that it is mainly about documentation and proof. Certification examines the information security management system, its coverage and the evidence for it. Our situation was that all the technical controls the certificate requires were already in place. We just had to dig up a big pile of various screenshots and other evidence with which we could show the auditor that this is genuinely true. Of course some small fixes and adjustments to practices and technologies came up, but it helped a great deal that the whole company and technology had been built security first, so that no big changes were needed.
The other half of the preparation work was then policies, policies and policies. We put down in writing every practice from the secure development lifecycle policy to the cryptography policy and everything in between. Every employee and subcontractor working at Revial went through security training that varied a little by role, more for the technical people, less for the sales and marketing crowd. Endpoint management and monitoring were implemented, and policies were approved by everyone many times over as they changed along the way.
The most laborious phase of the certification was without a doubt the non-technical parts of the preparation, namely the policies and documentation. It is heavy and rather tedious work that is also extremely detail-oriented, which is of course my very favourite and easiest kind of task (those who know me, and perhaps others too, will detect the sarcasm here). It is, however, extremely important, because only with this documentation can we show customers that these matters have genuinely been considered here and that the processes have been designed carefully, security first.
The actual two-stage audit process turned out, after all the preparation, to be straightforward and even easy. The Lead Auditor who worked with us remarked that for an ISO debutant our house was in exceptionally good order.
For an ISO debutant, your house is in exceptionally good order.
— Lead Auditor
By the time of the audit we had in place a renewed set of policies, access rights reviews, a management review, descriptions of the development processes, continuity and recovery plans, external penetration testing along with its minor remediation steps, a statement of applicability, a data protection impact assessment under Article 35 of the GDPR, as well as a statement on AI governance and a fundamental rights impact assessment, to name the most important ones.
The most important lessons
- Doing something right is not enough. You have to do it right and, on top of that, prove that it really was done in the past and will be done in the future too. The difference sounds small, but in practice it may not be so small after all.
- A small team has no separate compliance department. That meant the project competed with product development for the same weeks. I recommend thinking deeply about how your time is really best spent.
- Don’t produce documentation for documentation’s sake; actually change your ways of working where the gaps are. Without changing the ways of working you will never pass certification.
- Reserve time, and a lot of it. Reserve more than you think you’ll need, and then double it 🙂
Is this rare?
There are surprisingly few valid ISO 27001 certificates. According to ISO’s own statistics there were around 96,700 of them in 2024. Globally there are, by Dun & Bradstreet’s estimate, around 300 million companies. So roughly 0.032% of companies in the whole world hold an ISO 27001 certificate.
Rarer still, in Revial’s ISO 27001 certificate, is our timing and size. The project is usually done at the stage when a company has 50-200 people and some big customer forces the issue. We did it smaller and earlier, and that was a deliberate choice. Our customers genuinely care about information security, and more importantly, we genuinely care about information security. The certificate is one of the few things that, in a vendor assessment, is almost incontrovertible proof that things are in order. It brings peace of mind both to us and to our customer.
What this means for customers
For our customers, both current and future, the ISO 27001 certificate has several important effects, of which I would highlight the three most central:
- Vendor assessments become shorter and easier. A large share of the questions that used to be answered by hand have now been answered in advance and checked by a third party.
- Our house is genuinely in order. Incident handling, access rights reviews, continuity planning and notifying customers of subcontractor changes are processes that really exist and are actually followed.
- An outside party has audited this and will keep auditing it every year. The certificate is not a one-off; it has to be earned again, and Revial will do exactly that.
What I would do differently
- I would collect the evidence in the right format from the very beginning, as new technology is built and new processes are created. Most of the work was digging up what we had already done, from the wrong places.
- I would allocate at least one person’s time almost full-time.
- I would not write a single document that no one reads after the audit. We produced a few of those too, and they are now pointless maintenance.
If you’re in the same situation and considering certification, my message is: start. It is less glamorous and more useful than you expect.


