Zero non-conformities: In July 2026, COCUS successfully completed its first ISO 27001 surveillance audit and extended the scope of its certification to include the COCUS locations in Eschborn,Germany and Gaia, Portugal.
As digitalization accelerates and organizations grow increasingly dependent on IT infrastructure and cloud services, customers and partners are placing greater demands on proof of a robust and mature information security management system (ISMS). For technology and integration partners, a certified ISMS has become an increasingly common prerequisite for even being considered in enterprise procurement processes, particularly in regulated industries and security-critical IT infrastructure projects.
Following its initial ISO 27001 certification in October 2025, COCUS successfully completed its first surveillance audit in July 2026. The audit covered the existing certification scope and, extended to include COCUS Eschborn and Gaia locations. The certification continues to cover the management and delivery of IT infrastructure services and consulting services, including the design, implementation, support, and maintenance of IT systems.
Zero non-conformities in the audit
The audit confirmed a high level of maturity in the information security management system with zero non-conformities identified. For COCUS, this result demonstrates that information security within the company is not limited to a one-time certification exercise, but an ongoing commitment that is continuously developed and integrated into the daily work of the company across all locations.
For COCUS customers and partners, the extended certification means that IT infrastructure and consulting services are now delivered from a broader set of locations based on an audited, independently certified information security management system. This provides additional transparency and reliability for projects in which information security and data protection must be demonstrated contractually or by regulation, and it strengthens the position of COCUS as a technology partner for IT infrastructure and integration projects.
From TISAX to ISO 27001
The ISO 27001 certification builds on a multi-year development of information security standards and processes across COCUS. TISAX represented an earlier milestone in this development, followed by ISO 27001 certification as a further step in establishing and continuously strengthening a mature information security management system.
The successful surveillance audit and extended certification scope demonstrate the continued integration of information security into COCUS processes, operations, and service delivery.
This provides the COCUS customer and partner ecosystem with a consistent and independently certified framework for information security across a growing number of locations and reinforces the standards applied to the delivery of IT infrastructure and consulting services.


