- Q01Has Bubble ever been ISO 27001 certified?
- No. Bubble lists ISO 27001 in their Other Frameworks page as a description of the standard, with no certificate, no certification body, no scope. AWS — Bubble's infrastructure provider — is ISO 27001 certified at the cloud-infrastructure layer, but that certificate covers AWS's ISMS, not Bubble's. The certificate does not transfer.
- Q02Will SOC 2 satisfy an EU buyer asking for ISO 27001?
- Sometimes — but doing a SOC 2 audit does not give you an ISO 27001 certificate. There's roughly 70% control overlap between SOC 2 and ISO 27001:2022 Annex A, so the evidence reuses, but they're different artefacts: SOC 2 is a CPA attestation over a window (typically 3–12 months), ISO 27001 is an accredited certification of a continuously operating ISMS. US buyers usually accept SOC 2 alone; EU and UK enterprise buyers increasingly insist on the ISO certificate itself. Many SaaS hold both for exactly that reason.
- Q03Can I certify my organisation while staying on Bubble?
- Yes. ISO 27001 certifies an organisation's ISMS, not a product. You scope your ISMS around your team and processes, document Bubble as an inherited platform in your Statement of Applicability, and certify against the 93 Annex A controls. You'll need to ship logs off Bubble for monitoring controls — that's the main operational change.
- Q04How long does ISO 27001 actually take?
- Fast-track engagements complete Stage 1 and Stage 2 audits in 3–6 months; typical first-time certification runs 12+ months. After certification, surveillance audits happen annually and recertification every three years. If you already hold a current SOC 2, you can reuse most of the control evidence and shave the readiness phase materially.
- Q05My 2013-era certificate — is it still valid?
- No. The transition deadline from ISO/IEC 27001:2013 to the 2022 edition was October 31, 2025. After that date all 2013-version certificates expired and the 2022 edition with its 93 Annex A controls (11 new) became mandatory. If you or a sub-processor are showing a 2013 cert in 2026, treat that as expired and ask for the 2022-equivalent.
- Q06Does Bubble sign anything that helps my ISO audit?
- Bubble signs a GDPR-compliant DPA with Standard Contractual Clauses and the EU-US Data Privacy Framework. That DPA is what you reference in your ISO scope as the contract with your platform provider. Bubble does not sign BAAs. For ISO purposes the DPA is the relevant artifact; for HIPAA it's not enough.
- Q07Should I use an accredited certification body?
- Yes. EU and UK enterprise procurement frequently rejects non-accredited certificates outright. Look for bodies accredited under ISO/IEC 17021-1 by UKAS in the UK, ANAB in the US, or your national accreditation body. The cost difference between accredited and non-accredited audits is small — the rejection cost downstream is not.