ISO 27001 for software development companies

6 min read · Updated

If you build software for other businesses, your clients trust you with their systems, their data and often their customers' data. That's why software houses and development agencies get asked for ISO 27001 more than most: it's the quickest way for a client's procurement team to see that you manage security as a business, not just as good intentions in the dev team.

Why clients ask

  • You have access to their environments, code and sometimes production data.
  • Security questionnaires arrive with every larger contract; ISO 27001 answers most of them at once.
  • Regulated clients (finance, energy, health, the public sector) pass their own obligations down their supply chain.
  • AI work raises the stakes: clients want to know where their data goes when models are involved.

What the 2022 standard expects from a development team

ISO 27001:2022 includes specific controls for development. In practice, an auditor will look for:

Area What it looks like in a dev company
Secure development A defined lifecycle: code review, testing, security checks before release
Environments Development, test and production kept separate; client data not copied into test
Change management Changes reviewed and approved; pull requests are good evidence
Access Least privilege to client environments; access removed when people move on
Secrets API keys and credentials managed properly, never in code
Suppliers Your cloud, Git hosting, CI/CD and AI providers assessed and reviewed
Client data Clear rules for what you hold, where and for how long
Incidents A plan for a leaked key, a compromised laptop or a vulnerable dependency

The good news for software teams

Much of the evidence already exists in your tools: pull requests and reviews, CI runs, access lists, tickets and release notes. ISO 27001 mostly asks you to decide how you work, write it down briefly, assign owners, and keep the records flowing. The hard part is usually the management system around the engineering: scope, risk assessment, Statement of Applicability, internal audit and management review.

Don't slow delivery down

  • Scope sensibly: the services and teams your clients actually care about.
  • Use your existing workflow as evidence rather than inventing parallel paperwork.
  • Automate reminders for access reviews, supplier reviews and restore tests, so they happen without meetings.

How ClearIMS helps

ClearIMS is for businesses that need ISO 27001 but don't want to build a compliance team to get there. Describe your company in plain English and it drafts your scope, risk register, Statement of Applicability, policies and tasks. A named person in your business approves every record; the AI never approves anything. Then it keeps the system running with owned, dated tasks, and gives your external auditor scoped, read-only access to your approved records.

We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.

Take the 2-minute readiness check, or book a 20-minute call.

SOURCES

  1. ISO/IEC 27001:2022 (ISO)
  2. Secure development and deployment guidance (NCSC)
FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Ten organisations get the software at half price. We get to learn from them.

Start with the 30-day free trial. If ClearIMS earns its place, a founding seat locks £150 a month for 24 months, or £1,500 a year upfront. No VAT charged.

Apply for a founding placeBook a 20-minute callWe make the software. Your certification is yours, awarded by your certification body.