19.05.2026
ISO/IEC 27001:2022 – we are certified
We are very pleased to inform you that IT-Choice Software GmbH has successfully completed certification to ISO/IEC 27001:2022. The certification was carried out by TÜV Rheinland.
What does the certification mean?
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines how companies systematically identify, assess, and treat risks to the confidentiality, integrity, and availability of information.
The certification confirms that an independent auditor (in our case TÜV Rheinland) has verified that our ISMS meets all the requirements of the standard.
Annual surveillance audits will ensure going forward that we continuously comply with and further develop our standards.
An important step, not the finish line
We are delighted with this success. At the same time, we are aware that information security is a continuous process. New technologies, new requirements, and new risks demand ongoing adjustments and improvements. We are consistently pursuing this path.
ISO 27001 certification is part of our integrated management system (IMS), in which we also continuously develop ISO 9001 (quality management) and ISO 13485 (medical devices). For us, information security, quality, and regulatory requirements are inseparable.
Our special thanks go to all colleagues who contributed to this process.
The certificate is publicly available here:
Trust as the foundation of our work
Our customers work every day with highly sensitive data such as diagnoses, therapy histories, and study data.
Solutions such as ONKOSTAR, SURVEYSTAR, or STUDYSTAR therefore require the utmost care in handling information.
ISO 27001 certification makes visible what has long been established practice for us: a consistent and structured approach to information security.
03.11.2025
Stage 2 audit in March 2026
In March 2026, the Stage 2 audit is due. In this phase, it is assessed how we actually live our ISMS in day-to-day operations – that is, how well the defined processes are implemented in practice. This includes, among other things:
- Training and awareness among our employees
- Measures to detect and handle security incidents
- Technical and organizational safeguards
- Documented continuous improvement processes
Until then, we will continue working intensively to strengthen and further develop our system.
ISO 27001 certification: Stage 1 audit successfully passed
The Stage 1 audit is the first major milestone on the path to certification to ISO/IEC 27001, the internationally recognized standard for information security management. In this step, our ISMS was reviewed by an external auditor, in particular with regard to:
- Completeness and consistency of the documentation
- Set-up and structure of the management system
- Assessment of risk and action planning
- Maturity level of our processes
The result confirms: We are very well positioned and ready for the next step!

Image source: Thapana_Studio – stock.adobe.com
Integration into existing management systems
As communicated in the first project phase, we are pursuing a holistic approach. That is why an integrated management system is being created at IT-Choice, linking our new ISMS with the already established structures in accordance with ISO 9001 (quality management) and ISO 13485 (quality management for medical devices).
In this way, we create a solid foundation for continuous improvement, high quality, and sustainable information security – also with a view to modern technologies such as cloud services or networked software platforms.
What does this mean for our customers?
In your daily work, you rely on our software solutions – and therefore also on the fact that your sensitive data is well protected. This trust is what drives us.
With ISO 27001 certification, we underscore our commitment to data protection, information security, and quality. This makes our products even more secure for you and at the same time provides greater transparency regarding the underlying processes.
19.08.2025
Preparing for ISO 27001 certification
Our software solutions support you in working with highly sensitive information, which is why data security is particularly important to us. To continue meeting this expectation, we are consistently expanding our information security management system (ISMS).
A key milestone on this path has already been reached: We have put together an ISMS team and appointed an Information Security Officer (ISO). Together, we are driving the set-up and continuous development of our ISMS.
We are currently conducting internal audits to further optimize our processes. In the next step, we will then aim for official certification to ISO/IEC 27001, the international standard for information security management.

Image source: IDOL´foto – stock.adobe.com
We are also thinking ahead: We want to establish an integrated management system that builds on our existing systems in accordance with ISO 9001 (quality management) and ISO 13485 (quality management for medical devices).
We will be happy to keep you informed about the further progress of the project.