ISO/IEC 27001:2022 certified

Information security to international standards

Tvimenning is certified to ISO 27001The international standard for information security management systems. It sets requirements for how security is governed, not for which products are used. - the globally recognised standard for information security management systems. The certificate confirms that we handle your data with structured processes, documented procedures and independent audit.

What is ISO 27001?

ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. is the international standard for information security management systems (ISMSThe management system - policies, roles, risk assessments and procedures - that ISO 27001 sets requirements for. The certification proves the ISMS actually works.). It specifies requirements for establishing, implementing, maintaining and continually improving a management system that protects an organisation's information assetsPhysical equipment owned and used over time - transformer, cable, breaker. It has both a technical and an accounting side, and the two rarely agree..

For an energy SaaSSoftware as a Service - software delivered as subscription service over the internet. company like Tvimenning, this means that all data handling - from power market data and meter readings to customer contracts and personal data - is subject to systematic security controls reviewed by an independent certification body.

Certification is not a one-time stamp - it requires annual surveillance audits and full recertification every three years, ensuring the security level is maintained over time.

Certified

Tvimenning AS is certified to ISO/IEC 27001:2022, certified by Insight Assurance. The certification covers our information security management system (ISMS) and confirms that we have documented, audited routines for how we handle data, access and risk across the entire business. It is not a product certification, but the management system governs how the software comes about: code review, separated development, test and production environments, and traceable approval before anything goes live.

StandardISO/IEC 27001:2022
ScopeTvimenning’s information security management system (ISMS)
CertifiedJune 2026
iso.org/standard/27001

Security domains we control

ISO 27001 Annex A defines 93 controls across four domains. Here are the key measures we have in place.

Organisational controls

  • Information security policy approved by management
  • Roles and responsibilities documented for all staff
  • Risk assessments carried out regularly
  • Supplier security assessed at all procurements

People controls

  • Background check and NDA on hiring
  • Mandatory security training for all employees
  • Procedure for handling and reporting security incidents
  • Revocation of access rights on termination of employment

Physical controls

  • Infrastructure hosted in ISO 27001-certified data centres
  • No server infrastructure of our own - physical security is handled by certified hosting providers
  • Secure destruction of information and storage media

Technological controls

  • Encryption of data at rest and in transit (TLS 1.3 / AES-256)
  • Multi-factor authentication on all critical systems
  • Automated vulnerability scanning and patch management
  • Logging, monitoring and incident response plan
  • Penetration testing and code reviews
  • Separate environments for development, test and production
  • Change management with traceable approval before deployment
  • Backups with regular restore testing

The certification journey

Completed
April 2026

Gap analysis and scoping

Mapping of existing security posture against ISO 27001The international standard for information security management systems. It sets requirements for how security is governed, not for which products are used. requirements. Defined scope, risk appetite and project plan.

Completed
April–May 2026

Implementation of management system

Establishing the ISMSThe management system - policies, roles, risk assessments and procedures - that ISO 27001 sets requirements for. The certification proves the ISMS actually works.: policies, procedures, risk assessments, risk treatment plan and Statement of ApplicabilityThe document listing which of ISO 27001's security controls an organisation actually applies - and justifying every one that has been excluded. (SoA).

Completed
May 2026

Internal audit and management review

Internal audit of all control domains. Closure of non-conformities. Management review and approval of ISMS.

Completed
June 2026

External certification audit (Stage 1 + 2)

Independent audit by certification body. Stage 1: document review. Stage 2: operational on-site audit.

Completed
June 2026

Certificate received

Tvimenning AS is ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. certified. The certificate is valid for three years with annual surveillance audits.

What does this mean for you as a customer?

When you choose Tvimenning as your technology partner, ISO 27001 certification means we meet a recognised international standard for information security - independently confirmed, not merely claimed.

For your compliance function and IT security team, it means Tvimenning can document its security posture, risk assessments and controls - simplifying your own supplier assessments and GDPRGeneral Data Protection Regulation - EU's data protection regulation, applicable in Norway via the EEA Agreement. documentation.

01

Documented security

Access to security summaries, processing grounds and risk assessments for your supplier documentation.

02

GDPR-simplified

ISO 27001 covers many of the requirements in GDPRGeneral Data Protection Regulation - EU's data protection regulation, applicable in Norway via the EEA Agreement. Article 32 on technical and organisational security measures.

03

Continuous improvement

Certification requires ongoing audit - not a one-time stamp. Security posture is actively maintained.

04

Independently confirmed

An accredited certification body - not Tvimenning itself - confirms that controls are in place and operational.

Questions about information security?

Contact us for security summaries, DPA (data processing agreementThe data processing agreement GDPR Article 28 requires between a controller and a processor - regulates what the vendor is allowed to do with personal data.) or questions related to your vendor assessment of Tvimenning.