NANDO has achieved ISO/IEC 27001:2022 certification for information security management. The certification was issued following an audit process conducted by an accredited certification body and attests to the conformity of NANDO’s information security management system with the requirements of the international standard.
The ISO 27001 Standard
ISO/IEC 27001 is the international reference standard for information security management. It defines the requirements for identifying risks, implementing the necessary controls, and maintaining over time an information security management system that is independently verifiable by accredited third parties.
Certification goes beyond a declaration of conformity: it requires documented and verifiable demonstration of every aspect of the system, from access management to incident response, from infrastructure security to staff training, through periodic audits conducted by accredited bodies.
Relevance for Clients and Partners
NANDO operates in 17 countries with over 80 clients including large industrial groups, public service operators and organisations subject to verified ESG reporting obligations. The platform processes sensitive operational data, site-level performance, waste stream data, environmental reporting metrics, for which information security is a non-negotiable requirement.
ISO 27001 certification provides existing clients with documented, audited confirmation of the security practices already in place. For organisations evaluating NANDO as part of vendor assessment or supplier qualification procedures, the certification constitutes verifiable evidence of conformity with an internationally recognised standard.
For organisations subject to CSRD or stringent supply chain governance requirements, having technology providers certified to ISO 27001 is increasingly an explicit requirement in qualification processes. NANDO is now able to respond to that requirement with certified documentation.
Commitment to Continuous Improvement
ISO 27001 certification is not a final milestone but a structured commitment to the ongoing maintenance and improvement of the information security management system, verified through annual surveillance audits and periodic management reviews.


