
2 December 2025
OPTIMAL SYSTEMS has been certified as compliant with the ISO/IEC 27001:2022 security standard following a comprehensive auditing process. This means that the company offers certified information security management for hosting and SaaS.
ISO 27001: the standard for information security
ISO/IEC 27001:2022 is the internationally recognized standard for information security management systems (ISMS). It specifies requirements to systematically protect the confidentiality, integrity, and availability of information. ISO 27001 certification confirms that a company has implemented a comprehensive information security policy and that this is regularly audited by independent testing bodies such as TÜV SÜD.

ISO 27001:2022 “[...] helps organizations effectively identify and manage risks regarding the confidentiality, integrity, and availability of information.”
(Source: TÜV SÜD)
For ISO 27001 certification, companies must introduce an ISMS that covers all relevant processes, responsibilities, and security measures. This includes a systematic risk analysis, the documentation of guidelines and procedures, regular employee training sessions, and internal audits and management reviews. The effectiveness of the ISMS is determined by an external audit by an independent certification body. Companies are also obliged to continuously develop the system and adapt it to new requirements in the future.
Certificate for hosting and SaaS
The certification according to ISO/IEC 27001:2022 covers the scope of hosting, operation, and support of information processing/document processing solutions in lift-and-shift and software-as-a-service (SaaS) operation as well as the administration and operation of the supporting systems.
“OPTIMAL SYSTEMS has been offering hosting and SaaS services for a long time and will continue to expand this department in the future,” says Raphael Eismann, Information Security Manager at the company, explaining the scope of the certification. “A certified security policy is essential in order to meet the high demands of customers from industry and the public sector. In times when data leaks and cyber terrorism are regularly reported, users want to know that their information is secure.”
Comprehensive safety concept involving all employees
OPTIMAL SYSTEMS has a comprehensive concept designed to protect the information hosted and processed in companies in the long term in order to meet the requirements for certification. This concept includes:

“With its ISO 27001 certification, OPTIMAL SYSTEMS demonstrates a strong and lasting commitment to information security and trust.”
—Björn Grabe, COO of OPTIMAL SYSTEMS
An information security concept also places an important focus on raising awareness among all employees. “Security is not only a technical task, it also requires everyone involved to be alert and proactive in order to identify relevant challenges at an early stage,” explains Eismann.
Certification by TÜV SÜD needs to be renewed regularly and is initially valid for three years. This is accompanied by the obligation to continuously improve the ISMS. “With its ISO 27001 certification, OPTIMAL SYSTEMS demonstrates a strong and lasting commitment to information security and trust,” says Björn Grabe, Chief Operating Officer of OPTIMAL SYSTEMS, summarizing the process. “Customers can be sure that their data is protected to the highest standards – not only today but also in the future. Information security remains an ongoing process that requires continuous development.”
Do you have any further questions?