SitePlan is ISO 27001 certified – what that means for your project data
20.07.2026
Baustellenfotos per WhatsApp – und trotzdem strukturiert im Projekt
14.09.2026Published: June 2026
A year ago, we announced SitePlan's certification to ISO/IEC 27001. Now, our Information Security Management System (ISMS) has achieved its first Surveillance Audit passed successfully.
Extern, only the certificate's expiration date has changed. Within the operation of the ISMS, much more has developed.
Why the Surveillance Audit is Crucial
A certificate documents a point in time. The real acid test follows in ongoing operation. In the certification cycle, an accredited certification body checks the ISMS annually in surveillance audits before recertification is due after three years. Passing the first audit proves that the security measures are not only in place but are effectively operated and continuously improved.
Further development in the past cycle
Information security is an integral part of SitePlan's operational processes – managed according to the principle of continuous improvement (CI):
- Security processes was further developed within the scope of risk management.
- Security Awareness Training take place regularly for the entire team.
- Infrastructure and Systems are continuously hardened and updated.
- Emergency and Restart Processes (Incident Response, Business Continuity) are regularly reviewed and practiced.
Relevance in Civil Engineering
Sensitive project and infrastructure data are processed daily on construction sites – sometimes with relevance to critical infrastructure. Information security is therefore not a one-time compliance requirement for us, but a permanent, process-integrated responsibility. The protection of your data exists not only at the time of certification, but continuously throughout the entire lifecycle.
We therefore invest continuously in the security of our customers' data.
Further: SitePlan is ISO/IEC 27001 certified June 2025
