Normain passes its first ISO 27001 surveillance audit
Normain has passed its first annual surveillance audit for ISO/IEC 27001:2022, the international standard for information security management. Prescient Security, our certification body, carried out the audit this summer and issued our updated certificate in September.
What a surveillance audit is
We were first certified in August 2025. An ISO 27001 certificate is valid for three years, but to keep it, a company has to pass an independent audit every year in between. At each of these audits the auditor goes through evidence from the past twelve months to check that the information security management system still works in practice, for example that we keep our risk assessment up to date and act on what our own internal audit finds.
How we prepared
Earlier this year an independent firm carried out our internal audit of the information security management system, and our leadership team held its yearly management review of information security. Prescient Security then audited the full system in July. The updated certificate is valid until August 2028, as long as we keep passing the yearly audits.
What the certification covers
The certification covers the information security management system that supports the Normain platform. That includes our infrastructure on Microsoft Azure and every team in the company, from engineering to sales and customer success.
Why it matters for our customers
Our customers work in audit and assurance, GRC and M&A, and they use Normain to analyse their clients’ contracts and financial statements. Many of them have to show their own clients and regulators that the vendors handling this data meet a recognised security standard. A certificate that an independent auditor has checked again this year gives them evidence they can use directly in their vendor assessments.
“Our customers upload their clients’ most confidential documents to Normain, so they need to know that our security holds up all year round. Passing this audit a year after we were first certified shows that the whole team keeps up that work every day, and I’m really proud of them for that.”
Sara Landfors CEO and co-founder of Normain Our certificate and reports
Alongside ISO 27001, Normain has completed a SOC 2 Type 2 examination. You can view or request our ISO 27001 certificate and SOC 2 report in the Normain Trust Center. Our next surveillance audit is planned for 2027.

