Verified information securityInformation
security

Six companies, one shared information security management system, certified to ISO/IEC 27001:2022 and externally audited every year.

One shared ISMS for the entire group

All companies operating under the tegosgroup brand work to the same security requirements. The scope covers the sites in Dortmund, Manchester and Breda and leaves out none of the group's companies.

An ISO 27001 certificate is always issued to a single legal entity. In this case that is tegos GmbH, because it operates the shared IT infrastructure as well as the shared HR and finance processes, and runs the ISMS.

Structure of the certified scope

Policies, roles and security controls apply equally to all companies within the scope. For customers this means a consistent level of security, regardless of which tegosgroup company delivers the engagement.

tegos GmbH is responsible for the shared information security management system covering six companies of the tegosgroup.
Six companies within the certified scope
Shared information security management systemISO/IEC 27001:2022
Shared foundationIT infrastructure · HR and finance processes
Operated by tegos GmbH
Certified scopeOriginal wording of the certificate
Design, development, production, distribution, implementation, support and training for software, hardware, network and communication technologies, management tools and consulting for all of the activities, in accordance with the Statement of Applicability (SoA) v3.0, dated 12.06.2026.

Certificate to ISO/IEC 27001:2022

The independent certification body MSECB has audited and certified the management system. You can obtain the original certificate directly from MSECB and verify it there at any time.

Original certificate
Certificate validCertification bodyMSECB
Information security management systemISO/IEC 27001:2022Certificate number: CERT-002037
Certificate holder
tegos GmbHOslostrasse 2, 44269 Dortmund, Germany
Certified since
28 August 2026
Valid until
27 August 2029

Implementation of the security controls

The Statement of Applicability (SoA) v3.0 dated 12 June 2026 assesses all 93 controls of Annex A. Of these, 81 are applicable and implemented. Twelve controls are classified as not applicable, with justification.

Controls in Annex A93across four themes
Distribution of controls
81 applicable and implemented; 12 not applicable, with justification81controls87.1%12controls12.9%
Applicable and implemented81
Not applicable, with justification12

Basis: Statement of Applicability v3.0, as at 12 June 2026

A.5Organizational controlsGovernance, responsibilities and operating procedures37controls

The organizational controls form the binding framework of the ISMS. They govern responsibilities, the handling of information and access rights, and cooperation with suppliers and cloud providers. In addition, they set requirements for security incidents, business disruptions, data protection and the continual review of the management system.

Key areas

Policies and roles · Asset and access management · Suppliers and cloud services · Incident management · Business continuity · Legal and data protection

A.6People controlsObligations, competence and reliable reporting channels8controls

Information security is part of the entire employment lifecycle. Depending on the role, screening takes place before employment, and contractual and confidentiality obligations are set out in writing. Regular training, rules for mobile working and a defined reporting channel for security events complement the organizational requirements.

Key areas

Screening · Contractual and confidentiality obligations · Awareness · Mobile working · Reporting of security events

A.7Physical controlsProtection of workplaces, devices and equipment14controls

Clear desk and clear screen rules apply to workplaces and devices, among other requirements. Devices used off premises are protected, properly maintained and securely erased before disposal or reuse. Nine controls covering building and data centre security are classified as not applicable, because the systems within the scope are operated in the data centres of cloud providers rather than on our own premises.

Key areas

Clear desk and clear screen · Devices off premises · Maintenance · Secure erasure and disposal

A.8Technological controlsTechnical protection across the entire system lifecycle34controls

The technological controls cover endpoints, identities, applications, data and networks. They include strong authentication, vulnerability and configuration management, encryption, backups, logging and monitoring. Software development follows defined security requirements, separated environments and controlled changes.

Key areas

Endpoints and identities · Vulnerabilities and configuration · Cryptography · Backups · Logging and monitoring · Network security · Secure development

Certificate and further evidence

The certificate is publicly available. We provide the Statement of Applicability and further security evidence on request.

Do you need further security documentation?

For vendor assessments, the Statement of Applicability or questions about the certified scope, you can reach our security team directly.

Contact the security team