Cronofy is ISO 27001, 27018 and 27701 certified, SOC 2 Type II attested, and GDPR, CCPA and HIPAA compliant. Each covers a different aspect of security and privacy.
In April 2026, Cronofy completed a full recertification audit of our Information Security Management System against ISO 27001:2022, ISO 27018:2019 and ISO 27701:2019. We also renewed our SOC 2 Type II attestation, with two additional trust service categories now in scope. Here's what changed, and how we keep it that way.
A full recertification across all three ISO standards
This year's audit was our three-year recertification, the deeper audit that ISO requires periodically alongside annual surveillance visits. Independent auditors examined our management system from the ground up, across all three standards, spanning our Nottingham headquarters and our London and Amsterdam offices.
The audit found zero major or minor nonconformities. The audit team noted minor opportunities for improvement. None affect our certified status, and each is logged and tracked to close out.
SOC 2 Type II, now covering more ground
We renewed our SOC 2 Type II attestation for the period running April 2025 through March 2026, independently audited as in previous years.
This year's report expands what it covers. Alongside Security, our SOC 2 report now includes Availability and Confidentiality as formal trust service categories. In practice:
- Availability covers the controls behind our uptime commitments and our disaster recovery and business continuity planning
- Confidentiality covers how customer data is classified, restricted and protected as confidential throughout its lifecycle
Broadening the scope means customers now get independently audited assurance across more of what they rely on us for.
The maintenance cadence
Accreditations lapse without upkeep. This is the routine that keeps ours current:
- Annual surveillance audits between the three-year ISO recertification cycles, plus annual renewal of our SOC 2 Type II attestation
- Independent internal audits, conducted annually by a third-party information security firm, separate from our external certification audits
- Quarterly Operations and Security reviews, where our CEO, COO, CTO and Information Security Manager review risk, incidents and audit progress together
- Quarterly access reviews across all systems, and quarterly vulnerability scans, alongside external penetration testing bi-annually
- Quarterly backup restoration tests and an annual disaster recovery exercise, so recovery plans are tried and tested
- Monthly security awareness training for every employee, including phishing simulations, with full completion tracked
Why this matters to Cronofy customers
Cronofy's controls are tested on a regular schedule, by our own team and by independent auditors, and have held up under consecutive years of scrutiny.
For customers in regulated industries such as healthcare, financial services and enterprise HR, that matters. The safeguards around their data are checked on a fixed schedule all year round.
Where to get proof
Certificates, audit reports and our Statement of Applicability are available through our compliance center, or by request at compliance@cronofy.com.




