- Job title
- Front office accounting
- Sector
- Healthcare services
- Organization type
- chain store
- Joined
- May 2023
- Message
- 205
We are a 9-person software agency based in Barcelona, developing custom e-commerce integrations and microservices architectures for fintech and retail. We were negotiating an annual software development and maintenance contract worth 120,000 euros with a major retail chain operating across Spain. Yesterday, their procurement team sent over a vendor security questionnaire asking whether we hold an ISO 27001 certification, and if not, by when we plan to obtain it.
When we told them we don't have the certificate, they stated that this standard is an internal requirement for all external vendors accessing customer data and building integrations, and that otherwise the contract cannot be approved. Internally, we do use two-factor authentication, encrypted databases, and version control, but we have never been through a formal audit process like this before.
What exactly is ISO 27001, and is it strictly about technical server infrastructure? Is getting certified feasible for a small team of 9, how long does it take, and what would it cost? Is there an interim solution we could propose to the client without losing this deal?