ISO/IEC certifications
stepping stone AG has been certified according to ISO/IEC 27001:2013 since October 2019.In fall 2024, the transition audit to ISO/IEC 27001:2022 has been successfully completed. In October 2025, stepping stone AG was successfully recertified by ATTESTA Swiss Certification Company AG.
In autumn 2026, stepping stone AG will extend its existing ISO/IEC 27001:2022 certification to include the additional standards ISO/IEC 27017 and ISO/IEC 27018. The external audit will take place on 22 October 2026. With these extensions, we are underlining our commitment to the highest standards in cloud security and the protection of personal data.
The ISO/IEC 27001 standard relates to information security management and sets requirements for an information security management system (ISMS).
To ensure that the processes of stepping stone AG continue to apply to the ISO/IEC 27001:2022 standard in the future, regular reviews and recertification audits take place.
What is ISO/IEC 27001?
The ISO/IEC 27001 certification guarantees the use of the information security management system (ISMS). In addition to the one-time certification, an external audit takes place every year and a recertification every third year.
As our customer, you can be sure that the security of your data and the availability of your systems are at the forefront of our work.
For ISO/IEC 27001 certification attests that the certified company operates an information security management system, ISMS for short. An ISMS is a systematic approach for the management of sensitive company information. It encompasses people, processes and IT systems using a risk management process. This ISMS serves as the centre for everything related to IT security and is continuously monitored, maintained and improved.
Furthermore, the standard includes the identification and assessment of risks as well as the definition, development, implementation and monitoring of appropriate measures to minimise these risks in the area of application.
Information security is built on the three pillars of confidentiality, integrity and availability.
ISO/IEC 27017 and ISO/IEC 27018
By extending our certification to include the ISO/IEC 27017 and ISO/IEC 27018 standards, we are specifically strengthening our information security management system in the areas of cloud computing and data protection.
ISO/IEC 27017 – Cloud security
ISO/IEC 27017 supplements the ISO/IEC 27001 standard with additional security measures and best practices for cloud service providers (CSPs). The standard helps cloud providers to clearly define security responsibilities and to deliver cloud services in accordance with recognised international standards.
ISO/IEC 27018 – Protection of personal data
ISO/IEC 27018 extends ISO/IEC 27001 to include specific requirements for the protection of personal data (Personally Identifiable Information, PII) in cloud environments. The aim is to ensure transparency in the handling of personal data and to consistently strengthen data protection and privacy.
Why do we rely on ISO/IEC 27001?
Information security is an important quality of our services.
With the ISO/IEC certification we commit to our customers the use of an information security management system (ISMS) with regular review of risks and processes.
The guidelines of the information security management system (ISMS) apply to all employees of stepping stone AG, to all third parties who carry out tasks or perform services for stepping stone AG and to all customers or visitors of stepping stone AG.
With the ISO/IEC 27001 certification, the stepping stone AG team wants to guarantee that our processes comply with international standards.
Download as PDF: stepping stone AG ISO/IEC 27001 Certificate (english version).