Verified information securityInformation
security
Six companies, one shared information security management system, certified to ISO/IEC 27001:2022 and externally audited every year.
One shared ISMS for the entire group
All companies operating under the tegosgroup brand work to the same security requirements. The scope covers the sites in Dortmund, Manchester and Breda and leaves out none of the group's companies.
An ISO 27001 certificate is always issued to a single legal entity. In this case that is tegos GmbH, because it operates the shared IT infrastructure as well as the shared HR and finance processes, and runs the ISMS.
Structure of the certified scope
Policies, roles and security controls apply equally to all companies within the scope. For customers this means a consistent level of security, regardless of which tegosgroup company delivers the engagement.
Design, development, production, distribution, implementation, support and training for software, hardware, network and communication technologies, management tools and consulting for all of the activities, in accordance with the Statement of Applicability (SoA) v3.0, dated 12.06.2026.
Certificate to ISO/IEC 27001:2022
The independent certification body MSECB has audited and certified the management system. You can obtain the original certificate directly from MSECB and verify it there at any time.
Original certificate- Certificate holder
- tegos GmbHOslostrasse 2, 44269 Dortmund, Germany
- Certified since
- 28 August 2026
- Valid until
- 27 August 2029
Implementation of the security controls
The Statement of Applicability (SoA) v3.0 dated 12 June 2026 assesses all 93 controls of Annex A. Of these, 81 are applicable and implemented. Twelve controls are classified as not applicable, with justification.
Basis: Statement of Applicability v3.0, as at 12 June 2026
A.5Organizational controlsGovernance, responsibilities and operating procedures37controls
The organizational controls form the binding framework of the ISMS. They govern responsibilities, the handling of information and access rights, and cooperation with suppliers and cloud providers. In addition, they set requirements for security incidents, business disruptions, data protection and the continual review of the management system.
Policies and roles · Asset and access management · Suppliers and cloud services · Incident management · Business continuity · Legal and data protection
A.6People controlsObligations, competence and reliable reporting channels8controls
Information security is part of the entire employment lifecycle. Depending on the role, screening takes place before employment, and contractual and confidentiality obligations are set out in writing. Regular training, rules for mobile working and a defined reporting channel for security events complement the organizational requirements.
Screening · Contractual and confidentiality obligations · Awareness · Mobile working · Reporting of security events
A.7Physical controlsProtection of workplaces, devices and equipment14controls
Clear desk and clear screen rules apply to workplaces and devices, among other requirements. Devices used off premises are protected, properly maintained and securely erased before disposal or reuse. Nine controls covering building and data centre security are classified as not applicable, because the systems within the scope are operated in the data centres of cloud providers rather than on our own premises.
Clear desk and clear screen · Devices off premises · Maintenance · Secure erasure and disposal
A.8Technological controlsTechnical protection across the entire system lifecycle34controls
The technological controls cover endpoints, identities, applications, data and networks. They include strong authentication, vulnerability and configuration management, encryption, backups, logging and monitoring. Software development follows defined security requirements, separated environments and controlled changes.
Endpoints and identities · Vulnerabilities and configuration · Cryptography · Backups · Logging and monitoring · Network security · Secure development
Certificate and further evidence
The certificate is publicly available. We provide the Statement of Applicability and further security evidence on request.
Do you need further security documentation?
For vendor assessments, the Statement of Applicability or questions about the certified scope, you can reach our security team directly.
Contact the security team