Envision IT has achieved ISO/IEC 27001:2022 certification. Here’s what that means for you.

|
Published

Envision IT is ISO 27001 Certified


We’re proud to have earned ISO/IEC 27001:2022 certification, which is a leading international standard for information security management. MHM granted us this status on September 18, 2026, after a thorough two-stage independent audit.

Need our certificate for a vendor review? Envision IT Inc. ISO 27001:2022 Certificate.


What is ISO/IEC 27001?

ISO/IEC 27001 is like a global rulebook for keeping information secure. It’s the world’s best-known standard for information security management systems (ISMS) and sets out the requirements organizations must meet to establish, maintain, and continually improve an ISMS.

An ISMS is a structured way for organizations to identify, manage, and reduce risks to the information they have or use. This standard gives organizations of any size or industry a framework to build, run, maintain, and keep improving their system.

Certification confirms that an organization:

  • Manages information security risk. This includes risks to its own information and information it handles for clients.
  • Meets a recognized international standard. Its ISMS conforms to ISO/IEC 27001 requirements.
  • Has been independently assessed. An accredited certification body audited the ISMS rather than relying on the organization’s own claims.
  • Commits to continual improvement. The organization must monitor, review, maintain, and continually improve its ISMS, with ongoing audits assessing continued conformity.
  • Takes a systematic, organization-wide approach. The ISMS brings people, processes, and technology together within a defined scope, rather than treating information security as only an IT responsibility.

You can learn more on the ISO website: https://www.iso.org/standard/27001.


How we formalized our risk management

Managing risk has always been part of how we work. Our clients trust us with access to their Microsoft 365 environments, and we've always taken that responsibility seriously. ISO/IEC 27001 provided a framework to formalize what we were already doing, measure it consistently, and have it independently verified.

In September 2025, we built our own Policy Centre in SharePoint Online to bring our information security program into one structured, accessible place. It transformed our 17 existing security policy documents into managed policy pages and connected those policies to the controls they support and the reviews used to assess them. This gave everyone at Envision IT a central place to find current policies, understand the related controls, and keep reviews on schedule. From there, we formalized our ongoing risk management by:

  1. Formally documenting our risks. We established a consistent process for assessing threats to the confidentiality, integrity, and availability of information, including cloud misconfigurations, identity threats, and third-party risks in our Microsoft environment. 
  2. Making ownership official. We rate each risk for likelihood and impact and assign a named owner to manage it. 
  3. Planning how to treat each risk. Each risk has a documented treatment plan setting out the planned actions, responsible owner, and timeline. Our Statement of Applicability documents which ISO/IEC 27001 controls apply to our ISMS and how we address them.
  4. Measuring how our security program performs. We monitor our security program through annual penetration testing, annual incident response and disaster recovery exercises, and quarterly access reviews.
  5. Making formal training a requirement. Everyone completes security awareness training, acknowledges our policies, and repeats the training each year.
  6. Auditing ourselves before certification. In November 2025, an internal audit conducted independently of the activities being audited found no major nonconformities.
  7. Completing the certification audit. In 2026, MHM reviewed our documentation, interviewed our team, and assessed whether our ISMS and controls conformed to ISO/IEC 27001 requirements.

Want a closer look at how we built our Policy Centre? In an upcoming article, we’ll explore how we used SharePoint Online to connect policies, controls, risks, and reviews in one centralized solution and how we keep everything current over time.


Acknowledgements

We did not complete this journey alone. Support from the National Research Council of Canada Industrial Research Assistance Program (NRC IRAP) helped us invest in strengthening our information security program. Through the support of IRAP funding, we engaged WatSec for valuable guidance and assistance with internal audits as we developed and prepared our ISMS for certification. MHM conducted the independent audit that confirmed our conformity with ISO/IEC 27001. We appreciate the expertise and support each organization brought to the process.


What our certification means when you work with us

  • We maintain controlled access to your data. Access to production client data, including Extranet User Manager and Tenant Dashboard for Microsoft 365 storage, must be approved based on need. It is not enabled by default, and access is logged for audit purposes.
  • We proactively identify and manage risks. Regular penetration testing and quarterly access reviews help us identify weaknesses and take action to address them.
  • We test and improve our recovery plans. We regularly exercise our incident response and recovery processes, including simulated ransomware recovery, to validate our preparedness and identify improvements.
  • We can support your vendor review. You can share our certificate with your procurement team as independent evidence of our ISO/IEC 27001-certified ISMS, which may help streamline its security review.
  • Our ISMS has been independently assessed. An accredited certification body has audited our ISMS against the requirements of ISO/IEC 27001, so you do not have to rely solely on our own claims.


The journey doesn’t stop here

Threats, technologies, and regulatory requirements keep evolving. We therefore treat certification as an ongoing commitment rather than something we earn once and then forget.

We review a subset of our controls each quarter, with all controls covered over the course of each year. These reviews help us assess whether controls are operating effectively and identify opportunities for improvement. We also hold quarterly management reviews, reassess risks when significant changes occur, and conduct annual internal audits. MHM conducts annual surveillance audits to assess our continued conformity with the standard.

Thank you to our team for their hard work and to our clients for the trust they place in us.


About Envision IT

Envision IT is a Canadian Microsoft 365 consulting and solutions company. We help public sector, non-profit, and private organizations make their digital workplaces simpler through consulting, custom development, governance, and our own products, like Extranet User Manager and the Tenant Dashboard for Microsoft 365.

Need evidence for a vendor review?

Download our Envision IT Inc. ISO 27001:2022 Certificate.

Subscribe to Modern Work Monthly


Get the latest Microsoft 365 + Copilot insights to help your teams work smarter, faster.

We respect your inbox. Unsubscribe anytime.
Latest Articles