September 25, 2026

How Cronofy maintains its security accreditations

A full recertification across ISO 27001:2022, ISO 27018 and ISO 27701, plus an expanded SOC 2 Type II report, and the routine behind keeping them current.
3 min read
Profile photo of Robert Gosling
Robert Gosling
Information Security Manager
Blog post Hero Image

Cronofy is ISO 27001, 27018 and 27701 certified, SOC 2 Type II attested, and GDPR, CCPA and HIPAA compliant. Each covers a different aspect of security and privacy.

In April 2026, Cronofy completed a full recertification audit of our Information Security Management System against ISO 27001:2022, ISO 27018:2019 and ISO 27701:2019. We also renewed our SOC 2 Type II attestation, with two additional trust service categories now in scope. Here's what changed, and how we keep it that way.

A full recertification across all three ISO standards

This year's audit was our three-year recertification, the deeper audit that ISO requires periodically alongside annual surveillance visits. Independent auditors examined our management system from the ground up, across all three standards, spanning our Nottingham headquarters and our London and Amsterdam offices.

The audit found zero major or minor nonconformities. The audit team noted minor opportunities for improvement. None affect our certified status, and each is logged and tracked to close out.

SOC 2 Type II, now covering more ground

We renewed our SOC 2 Type II attestation for the period running April 2025 through March 2026, independently audited as in previous years.

This year's report expands what it covers. Alongside Security, our SOC 2 report now includes Availability and Confidentiality as formal trust service categories. In practice:

  • Availability covers the controls behind our uptime commitments and our disaster recovery and business continuity planning
  • Confidentiality covers how customer data is classified, restricted and protected as confidential throughout its lifecycle

Broadening the scope means customers now get independently audited assurance across more of what they rely on us for.

The maintenance cadence

Accreditations lapse without upkeep. This is the routine that keeps ours current:

  • Annual surveillance audits between the three-year ISO recertification cycles, plus annual renewal of our SOC 2 Type II attestation
  • Independent internal audits, conducted annually by a third-party information security firm, separate from our external certification audits
  • Quarterly Operations and Security reviews, where our CEO, COO, CTO and Information Security Manager review risk, incidents and audit progress together
  • Quarterly access reviews across all systems, and quarterly vulnerability scans, alongside external penetration testing bi-annually
  • Quarterly backup restoration tests and an annual disaster recovery exercise, so recovery plans are tried and tested
  • Monthly security awareness training for every employee, including phishing simulations, with full completion tracked

Why this matters to Cronofy customers

Cronofy's controls are tested on a regular schedule, by our own team and by independent auditors, and have held up under consecutive years of scrutiny.

For customers in regulated industries such as healthcare, financial services and enterprise HR, that matters. The safeguards around their data are checked on a fixed schedule all year round.

Where to get proof

Certificates, audit reports and our Statement of Applicability are available through our compliance center, or by request at compliance@cronofy.com.

Card Image
Blog Post • July 22, 2026
Creativity from compliance
Compliance work has a reputation for box-ticking. Our Information Security Manager on why ISO 27001 is a canvas, not a checklist - and how creative implementation delivers real security value.
Card Image
Blog Post • November 13, 2025
Give every user a way to schedule: Introducing new Calendar Access Modes
Cronofy is excited to introduce Calendar Access Modes, giving product teams new ways to offer secure scheduling with flexible permissions that meet strict privacy and compliance needs.
Card Image
Case Study
Pinpoint added AI notetaking to its Cronofy scheduling in four weeks and unlocked new revenue
An ATS for multi-stream hiring that turned every interview into clean, timestamped data, owned inside its own product and ready to power its agentic layer.