OAW SE

Trust isn't certified. It's verified.

Written by OAW SE-EN | Jul 21, 2026 2:31:28 pm

Information security has become one of the defining criteria in software procurement. As organizations entrust suppliers with increasingly sensitive employee data, from sick leave management and occupational health to rehabilitation and employee wellbeing, they are no longer evaluating software alone. They are deciding whether a supplier can be trusted to protect information that employees rightfully expect will remain confidential.

Recent cyber incidents across Europe have only reinforced that responsibility. Procurement teams are asking more detailed questions about data protection, incident response, business continuity, supplier governance and operational resilience. That shift is both necessary and welcome. Yet amid these increasingly sophisticated discussions, one familiar procurement requirement continues to appear:

"The supplier must be certified according to ISO 27001 or equivalent."

The principle behind this requirement is entirely reasonable. Public procurement should remain open, proportionate and competitive. Suppliers that can demonstrate an equivalent level of information security should not automatically be excluded simply because they rely on different forms of assurance.

The challenge, however, lies in determining what equivalent means in practice.

 The principle behind this requirement is entirely reasonable. Public procurement should remain open, proportionate, and competitive. Suppliers that can demonstrate an equivalent level of information security should not automatically be excluded simply because they rely on different forms of assurance.

The challenge, however, lies in determining what equivalent actually means in practice.

Looking beyond the certificate

The debate surrounding ISO 27001 is often framed as though it were about certification itself. It is about something far more fundamental: objective verification.

Information security cannot be assessed by looking at technical controls in isolation, nor can it be reduced to a collection of policies or compliance documents. Mature information security is the result of governance, risk management, clearly defined responsibilities, supplier oversight, secure development practices, business continuity planning and a culture of continuous improvement. These elements work together as a management system that evolves alongside an organization's technology, people and risk landscape.

That is precisely the purpose of ISO/IEC 27001. It does not certify that an organization is immune to cyber incidents, no standard can make such a promise. Instead, it provides independent assurance that information security is managed systematically, reviewed regularly and improved continuously within a clearly defined scope.

For buyers, that distinction matters. There is a meaningful difference between a supplier stating that they work in line with ISO 27001 and an accredited certification body independently verifying that those practices are embedded throughout the organization. 

When "equivalent" becomes difficult to assess

The phrase "or equivalent" is not problematic. In fact, procurement legislation rightly allows suppliers to demonstrate equivalent levels of assurance through alternative means.

The practical challenge arises when equivalence is accepted without clearly defining how it should be assessed.

If a supplier does not hold an independent certification, what evidence should be evaluated? Which controls should be reviewed? How can buyers determine that governance, access management, incident response and business continuity are not only documented, but demonstrably effective over time?

These are not trivial questions.

Answering them requires expertise, time and objective evidence. A meaningful assessment extends well beyond reviewing policy documents or completed security questionnaires. It requires insight into how security is governed, how risks are identified and mitigated, how controls are monitored, and how an organization demonstrates continuous improvement as technologies and threats evolve.

In many respects, such an assessment begins to resemble an independent audit.

This is not an argument against accepting alternative forms of assurance. It is an argument for ensuring that any claim of equivalence can be substantiated through evidence that is transparent, objective and proportionate to the sensitivity of the information being protected.

Shifting the procurement conversation

Perhaps the most valuable evolution in procurement is not to ask different suppliers for different certificates, but to ask every supplier better questions.

  • How is information security governed across the organization?

  • Which independent assessments validate that governance?

  • What evidence demonstrates that security controls operate effectively over time?

  • How are customer environments separated?

  • How is resilience maintained when systems, suppliers and threat landscapes inevitably change?

Questions such as these move the conversation beyond compliance. They encourage organizations to evaluate the maturity of a supplier's security capabilities rather than the presence of a single certificate.

Ultimately, that leads to better procurement decisions.

Confidence is built through independent evidence

At Otherside Software, we view ISO/IEC 27001 not as an endpoint, but as the foundation of a broader commitment to information security.

Our Information Security Management System is independently certified according to ISO/IEC 27001, providing objective assurance that security is embedded in the way we govern our organization, manage risk and continuously improve our processes.

To complement this, we undergo an annual SOC 2 Type II audit. While ISO 27001 assesses the design and governance of our management system, SOC 2 Type II independently verifies that key security controls operate effectively over an extended period. Together, these independent assessments provide customers with confidence that our approach to information security is not only well designed but consistently executed.

That philosophy extends into our technology as well. Xpert Suite operates within a private cloud architecture using dedicated customer tenants, strengthening data isolation and limiting the potential impact of security incidents across environments. No architecture can eliminate every risk, but thoughtful design choices can significantly improve resilience and reduce exposure.

From compliance to confidence

As digital ecosystems become increasingly interconnected and employee data grows ever more sensitive, organizations require more than assurances that security has been considered. They need confidence that it has been independently validated, continuously monitored and demonstrably maintained.

For that reason, the most important question in procurement is no longer whether a supplier possesses a particular certificate.

The more meaningful question is whether the supplier can provide objective evidence that its information security framework continues to perform, adapt and improve over time.

Certificates undoubtedly play an important role in answering that question. But they are most valuable when they represent something greater than compliance alone.

They represent a commitment to transparency. To accountability. And ultimately, to earning trust through evidence rather than promises.

Want to sharpen your security questions? 

Buying software that handles your people’s sensitive data is a huge responsibility. If you want to know which questions you should really be asking suppliers to look past the paper illusion, reach out. We’re happy to think along and show you how we prove our security every single day. 

Contact us!