ISO 27001 and SOC 2 certification

© 2026

Compliance Posture Transfer

A certificate describes their controls. It says nothing about yours.

Most compliance conversations with a cloud provider end the same way. You ask how they handle data protection, and they hand you a certificate. ISO 27001. SOC 2. Sometimes both. The conversation stops there, as if the certificate answered the question. It didn't. It answered a different question.

What a Certificate Actually Covers

An ISO 27001 or SOC 2 certification describes the provider's own internal controls: how they manage risk, how they handle their own infrastructure, how they respond to incidents on their side of the relationship. It's a real, useful thing to have. It is not a description of your compliance obligations, and it was never designed to be one.

When a regulator, an auditor, or a client asks where a specific record sits, who has accessed it, and when, a provider's certificate doesn't answer any of those questions. It answers "is this provider generally well-run," which is a different question with a different owner.

The Question a Certificate Doesn't Answer

Try asking your current provider these three questions directly:

  • Which specific jurisdiction is this record stored in, right now

  • Who, by name or role, has access to it

  • What happens to it if you terminate the contract tomorrow

For most organisations running on shared cloud infrastructure, the honest answer to at least one of these is "it depends" or "let us check." That gap, between what a certificate implies and what you can actually state with certainty, is what we mean by compliance posture transfer. The certificate creates an impression of assurance. It does not transfer the underlying facts.

What Compliance Posture Actually Means for You

Your compliance posture is the set of things you can state, directly and without needing to escalate to a vendor, about where your data lives, who can reach it, and what your recourse is if something goes wrong. It's yours, not something you inherit by paying a subscription to a certified provider.

This matters most in the moment it's tested: an audit, a client due diligence questionnaire, a regulatory inquiry. That's not the moment to discover you don't actually know the answer.

What This Looks Like in Practice

An organisation with a real compliance posture, rather than a borrowed one, can typically state plainly:

  • The named jurisdiction their data is stored in

  • Who has access, and how that access is logged

  • What their backup policy is, specifically, not generally

  • What happens to their data if the relationship with their provider ends

If you can't answer all four without checking with someone else first, that's the gap this whole conversation is about.

Final Thoughts

A certificate is a real thing, and it's not nothing. But it describes a provider's homework, not yours. The organisations that hold up best under scrutiny are the ones who built their own answer to these questions instead of borrowing one, and that starts with an architecture you can actually point to, not a badge you can show.


References

[03]

//FAQ

GOT QUESTIONS?

Curly Woman

Security. Reliability. Privacy.

Parioni

What is your typical turnaround time?

What exactly does Parioni Infra do?

How do you replace Google Workspace and Microsoft 365?

How is this different from private cloud?

Are you compliant with GDPR, UK data protection law, and sector regulations?

[03]

//FAQ

GOT QUESTIONS?

Curly Woman

Security. Reliability. Privacy.

Parioni

What is your typical turnaround time?

What exactly does Parioni Infra do?

How do you replace Google Workspace and Microsoft 365?

How is this different from private cloud?

Are you compliant with GDPR, UK data protection law, and sector regulations?

[03]

//FAQ

Curly Woman

Security. Reliability. Privacy.

Parioni

What is your typical turnaround time?

What exactly does Parioni Infra do?

How do you replace Google Workspace and Microsoft 365?

How is this different from private cloud?

Are you compliant with GDPR, UK data protection law, and sector regulations?

//CHOOSE SOVEREIGNTY OVER BIG-DATA

//CHOOSE SOVEREIGNTY OVER BIG-DATA

If "somewhere in the cloud" isn't good enough

If "somewhere in the cloud" isn't good enough

Create a free website with Framer, the website builder loved by startups, designers and agencies.