panagenda is officially ISO 27001:2022 certified, effective September 9, 2026. It’s the kind of milestone that doesn’t come with a big flashy launch moment, but it’s one of the ones I’m most proud of, because almost everyone in the company had a hand in it.
More Than a Badge
Here’s the short version of why it matters, for anyone who doesn’t spend their days thinking about information security: ISO 27001 isn’t a badge you put in a footer. It’s proof, checked by an outside auditor, that we handle customer data, partner data, and our own systems with a real, repeatable process, not just good intentions. For a company that works inside other people’s IT environments every day, building software around HCL Notes and MS Teams, that’s not a nice-to-have. It’s the whole basis of the trust customers and partners put in us.
Not a Sprint
This wasn’t a one-year project, not really. Getting to certification took close to four years, but we weren’t starting from zero. We already had a lot of the substance: security practices, technical safeguards, and know-how that had grown organically over years of running a software company responsibly. What we didn’t have was all of it written down, structured, and provable to an outside party. So a good part of those four years was learning what an ISMS formally requires and taking stock of what we already had against it. The last year is where that turned into concrete work: documenting and tightening policies, running formal risk assessments, reviewing suppliers, building out incident response plans, and doing internal audits where we went looking for our own gaps before anyone else did. It was less about building security from scratch and more about making it visible, consistent, and audit-ready. The external audit, carried out by the Österreichische Computer Gesellschaft (OCG), was the last step, and the one that mattered most. Everything we’d built either held up under scrutiny or it didn’t. It held up.
Everyone Had a Hand in It
None of this happened in one department. IT, development, HR, legal, and management all pulled their weight, answered the awkward audit questions honestly, and fixed things without being asked twice. That’s the part I’m most proud of, not the certificate itself, but that so many people took it seriously and made it real. Thanks are also due to the OCG and their auditor team. The audit itself was thorough but genuinely collaborative, and that made a demanding process a lot easier to get through. And because after the audit is before the audit: this certificate isn’t a finish line, it’s a checkpoint. The ISMS keeps running, the risks keep getting reassessed, and the next audit is already somewhere on the calendar. The work doesn’t end here, we’ll keep improving.