Back to blog
Compliance7 min read

Implora Is ISO 27001 Certified: What It Means for Your Vendor File

Implora is ISO/IEC 27001:2022 certified with zero nonconformities. What certified means versus compliant, what the scope covers, and what changes for IT teams.

Jonas Bøgvad·
Implora Is ISO 27001 Certified: What It Means for Your Vendor File

On 25 August 2026, Intercert issued ISO/IEC 27001:2022 certificate IC-IS-2608276 to sky made simple ApS, the company behind Implora. The audit closed with zero nonconformities.

TL;DR: Implora's entire lifecycle, from development to support, is now covered by an independently audited information security management system. For the IT team that has to answer "is this tool safe to connect to our tenant", that turns an essay into an attachment: a certificate number anyone can verify, a scope statement, and an external auditor who re-checks every year. This post explains what certified means as opposed to compliant, what the scope covers, how the evidence was collected, and what it does not promise.

Compliant is a claim, certified is a checked fact

Any vendor can write "we are ISO 27001 compliant" on a website. It means they believe they meet the standard. Nobody checked.

Certified means a certification body sent auditors, spent days going through the management system, the risk register, the controls and the evidence, and put their name on a certificate they can withdraw. It is re-checked every year. A surveillance audit is due by August 2027 and full recertification in 2029.

That difference is the whole point. When legal, your manager or a customer's auditor asks about a tool with read access into your Microsoft 365 tenant, "the vendor says so" is a paragraph you have to write and defend. A certificate number that can be verified with the certification body is a PDF you attach.

What the scope covers

The certified scope, in the auditor's words:

The Information Security Management System at sky made simple ApS covering the design, development, operation, delivery, and support of the Implora Software-as-a-Service (SaaS) platform for cloud security and compliance management, hosted on Microsoft Azure (EU), including the functions of Software Development, Cloud Platform Operations, Information Security, Customer Support, and Sales.

In plain terms: everything. Not just the datacenter, which is Microsoft's certification and not ours, and not just a security function. The whole lifecycle of the product sits inside the management system. Of the 93 controls in the 2022 version of the standard, 83 apply. The ten that do not are documented with a justification, mostly physical security controls inherited from Azure because the platform has no premises of its own.

Policies that point at mechanisms

The thing we did not expect when this started was how much the standard would change the product rather than just document it. ISO 27001 forces every organisational promise to point at something real, and the real thing to point back at a written policy. When the two disagree, one of them is wrong and gets fixed.

A few examples of what that looked like:

  • Offboarding. The policy says customer data is deleted when a tenant or an organisation leaves. In the platform, that promise is enforced automatically: adding a new place where tenant data lives without covering its deletion fails before it can ship. The auditor asked for the policy. We could also show the enforcement.
  • Access control. The policy says every request is validated against the caller's tenant. In the platform, that is a structural rule that new code cannot bypass, not a guideline developers are asked to remember.
  • Change management. Every production change goes through review, automated build and test, and a deployment pipeline with no manual path into production. The evidence was the pipeline itself, not a form describing it.
  • Backups and retention. Backups exist and are restore-tested, and every retention figure in the policy was verified against the live configuration before it went to the auditor. Policies that describe the system and a system that matches the policy are the same artefact viewed from two sides.

Once the policy and the platform describe the same thing, the audit stops being a performance and becomes a review of something that is already true. That is the part worth getting excited about, and it is the same principle behind Implora's compliance module: readiness measured from what the tenant actually does, not from what someone remembered to tick.

Continuous evidence, not an audit-week scramble

The controls are continuously monitored through connectors into the cloud platform, the source repositories and device management. Failing checks show up as failing checks, with history the auditor could read week by week across the whole observation period. Evidence was collected by the platform as it ran, not assembled in the weeks before the audit, which is the difference between proving a practice and staging one.

The honest version includes the imperfect parts. The internal audit earlier in the year found three minor nonconformities: a scope document missing the company address, no corrective-action register, and one control missing evidence. All three were fixed and disclosed. The certification audit recorded three opportunities for improvement, every one of them something we had raised ourselves. Disclosure turned findings into improvement notes. That is a habit worth keeping regardless of the standard.

What this changes for you

If Implora touches your environment, whether you run it for your own organisation, for the tenants you manage, or you are the customer of someone who does:

  • The vendor question has a verifiable answer. Certificate number, scope statement and certification body, all checkable without trusting us.
  • Someone is answerable for the tool with read access into your tenant. With a self-hosted script, that someone is you. Now it is a certified vendor with a documented incident process, tested backups, a risk-assessed supplier list, and an external auditor checking every year.
  • NIS2 supply chain requirements have a document. If your organisation is in scope for NIS2, Article 21 asks you to assess the security of your suppliers. For this supplier, the certificate is the answer.
  • The open source scanners stay. Implora's assessments build on well-known open source and Microsoft tooling. They are excellent and this does not replace them. It is the certified operating environment around them, so the credentials and the results do not live on a laptop.

Two things it does not do. It is not a guarantee against a breach, and it is not a substitute for a contract. Liability comes from the agreement and the data processing addendum, not from the certificate.

What comes next

SOC 2 Type II is in progress with the same auditor. The management system that produced this certificate is the one every new Implora feature is built inside, so next year's surveillance audit checks an ongoing practice, not a second project.

Need the certificate or the scope statement for a vendor review? Request it from the legal page and it is yours.

Frequently Asked Questions

Does the EU Cyber Resilience Act apply to Implora?

No. The Cyber Resilience Act covers products with digital elements that customers install and run. Implora is delivered as a service, which the regulation leaves to NIS2 instead. The short onboarding scripts Implora generates are one-shot helpers with no standalone function. This assessment is recorded in our legal requirements register and is revisited if Implora ever ships an installable component.

Does the certificate cover Microsoft Azure itself?

No, and it does not need to. Microsoft holds its own ISO 27001 and SOC 2 certifications for the Azure infrastructure. Implora's certificate covers what is built and operated on top of it: the platform, its development, its operations and its support. Together the two certifications cover the full stack, and the split is documented in the Statement of Applicability.

What happens if Implora stops meeting the standard?

The certification body can suspend or withdraw the certificate at the annual surveillance audit, and any customer can verify its current status with the certification body directly. That consequence is what separates a certificate from a self-declared statement of compliance.

iso-27001compliancevendor-securitymicrosoft-365nis2