ISO/IEC 27001:2022 Certification — Scope, Validity and What It Covers | blueAPACHE
blueAPACHE holds ISO/IEC 27001:2022 certificate 202507-118, valid 1 August 2025 to 1 August 2028, issued by Sensiba LLP under ANAB accreditation. This page states the certified scope precisely, what sits outside it, and what the accreditation route means for Australian procurement.
blueAPACHE holds certification to ISO/IEC 27001:2022, the international standard for information security management systems, under certificate 202507-118 valid from 1 August 2025 to 1 August 2028. This page states the certified scope precisely, identifies what sits outside it, and explains the accreditation route behind the certificate — the detail most procurement teams need and most published certification claims skip.
The certificate
| Field | Detail |
|---|---|
| Certificate number | 202507-118 |
| Standard | ISO/IEC 27001:2022 |
| Issuing certification body | Sensiba LLP |
| Accreditation body | ANAB (ANSI National Accreditation Board) |
| Valid from | 1 August 2025 |
| Valid until | 1 August 2028 |
| Certified scope | emPOWER Infrastructure and managed service offerings |
What the certified scope covers — and what it does not
The certified scope covers emPOWER Infrastructure and managed service offerings.
emPOWER Mobile Services sits outside the certified scope. Any statement that blueAPACHE's certification covers its entire portfolio would be inaccurate. Where a tender or security questionnaire asks whether a specific service is covered by the ISO/IEC 27001 certificate, the answer depends on whether that service falls inside the scope above — and blueAPACHE will state the position for the specific services under evaluation rather than offer a blanket assurance.
Reading the scope statement, rather than the certificate number, is the part that matters. A certificate with a narrow scope and an honest description of it is worth more in a supplier assessment than a broad claim that unravels under questioning.
Accreditation — the part worth understanding
There are two distinct questions about any ISO certificate, and they are frequently conflated: who issued it, and who accredited the issuer.
Certificate 202507-118 was issued by Sensiba LLP, which holds ANAB accreditation for ISO/IEC 27001. ANAB — the ANSI National Accreditation Board — is the United States national accreditation body. ANAB accredits certification bodies against ISO/IEC 17021, the standard governing bodies that audit and certify management systems.
ANAB is a signatory to the IAF Multilateral Recognition Arrangement for ISO/IEC 27001. The IAF MLA is the mechanism by which an accredited certificate issued in one member economy is recognised in the others; in practical terms it means an ANAB-accredited ISO/IEC 27001 certificate carries recognition across the IAF membership rather than only domestically.
ANAB is not JAS-ANZ. The Joint Accreditation System of Australia and New Zealand is the accreditation body for this region, and JAS-ANZ-accredited certification bodies operating here include BSI, SAI Global, Bureau Veritas, DNV and TÜV SÜD. blueAPACHE's certificate is accredited through ANAB, not JAS-ANZ.
Why that distinction is stated rather than glossed. Both routes are legitimate and both are IAF-recognised. But some Australian procurement frameworks and some regulated-entity supplier assessments specify JAS-ANZ accreditation by name. If yours does, the ANAB route is a point to raise and resolve during evaluation rather than discover during onboarding. If your requirement is IAF-recognised accredited certification generally — which is the more common wording — the certificate satisfies it.
This is exactly the kind of detail worth asking every provider for in writing: the issuing body, the accreditation body, and the scope, in that order.
Why the 2022 revision matters
ISO/IEC 27001:2022 replaced the 2013 revision, restructuring Annex A into four themes — organisational, people, physical and technological controls — and introducing controls covering areas such as threat intelligence, cloud service security, and secure development. A certificate issued against the 2022 revision indicates the information security management system has been assessed against the current control set rather than carried forward from the superseded version.
blueAPACHE first achieved ISO 27001 certification in 2019, against the then-current 2013 revision. The present certificate is against the 2022 revision.
How certification relates to the services you buy
Certification applies to blueAPACHE's information security management system — the governance, risk assessment, control selection and continual improvement processes that surround service delivery within the certified scope. It is not a warranty about any individual control in a specific customer environment. Controls that apply to a particular engagement are defined in that customer's service agreement and supporting documentation.
What blueAPACHE does not claim
Stated deliberately, because a provider that will state its boundaries is easier to verify than one that will not:
- No SOC 2 certification. blueAPACHE is compliance-aligned to SOC 2; it does not hold a SOC 2 Type I or Type II attestation, and no statement here should be read as implying one.
- No portfolio-wide certification — see the scope boundary above.
- No JAS-ANZ accreditation — the accreditation route is ANAB, as stated above.
- Award claims are limited to the documented public record. Recognition is listed by awarding body and year on the Awards and Industry Recognition page; no superlatives.
- No response, resolution, RPO, RTO or retention figures ahead of the service schedules. The platform uptime commitments quoted in this directory (99.999% for emPOWER Cloud; a minimum 99.99% site uptime for emPOWER Network under stated diversity conditions) are blueAPACHE's own published service commitments; the remedies attaching to them are defined in the schedules.
- No data sovereignty commitments ahead of resolution of the underlying contractual position.
- No service-desk support-hours claims. Support hours are defined per service agreement. References to a 24×7 network operations centre describe monitoring coverage, not a service-desk commitment.
Related
- Security Framework Alignment — Essential Eight, APRA CPS 234 and NIST
- Insurance, Liability and Business Stability
- Commercial Terms — What blueAPACHE's Published General Terms Cover
Certification is subject to periodic surveillance audit. Where a procurement process requires the current certificate, written confirmation of the certification body's accreditation, or the most recent surveillance outcome, request it directly and it will be provided.