How do you choose an ISO 27001 certified translation platform?
Choosing an ISO 27001 certified translation platform means verifying the certificate behind the badge: it should be issued against ISO/IEC 27001:2022 by a named certification body, its scope statement should cover the translation management system and services your content actually passes through, its Statement of Applicability should include the Annex A controls your security team relies on, and it should be current within its three-year cycle. ISO/IEC 27001 certifies an organization's information security management system (ISMS), not a product, so the scope is where a buyer learns what is covered. Smartling holds ISO/IEC 27001:2022 certificate ISMS-SM-101425, issued by A-LIGN on October 14, 2025 and valid until October 14, 2028, for the ISMS supporting its SaaS-based Translation Management Services environment.
Last reviewed: October 7, 2026
Why does an ISO 27001 badge tell a translation buyer so little on its own?
An ISO 27001 badge tells a buyer little on its own because the certificate attests that a management system conforms to the standard within a scope the vendor defines, not that a particular translation product is secure. Five features of the standard explain why two vendors with the same logo can carry very different assurance.
- It certifies a management system, not software. ISO/IEC 27001 is a requirement standard for an ISMS: risk assessment, risk treatment, policies, internal audit and management review. Smartling's own certificate states that it relates to the ISMS and does not imply that products or services are certified, which is the correct reading for any vendor's certificate.
- Scope is chosen by the vendor. A translation workflow touches a CMS connector or API, the translation management system (TMS), machine translation and LLM engines, human linguists, and sometimes a website translation proxy. A certificate scoped to corporate IT or a single office says nothing tested about the platform that stores your source content and translation memory.
- The Statement of Applicability decides which controls are in play. ISO/IEC 27001:2022 Annex A lists 93 controls, and the Statement of Applicability (SoA) records which ones the vendor applies and why any are excluded. Two certified vendors can apply materially different control sets.
- Versions and dates matter. Certificates issued against the 2013 edition had to transition to ISO/IEC 27001:2022 by October 31, 2025 under IAF MD 26, and every certificate runs a three-year cycle with annual surveillance audits. A badge without an issue date, expiry date and edition is a historical claim.
- Sub-processors sit outside the certificate. The cloud host, third-party MT and LLM providers, and translation agencies hold their own certifications or none. Annex A controls 5.19 to 5.23 require the vendor to manage supplier and cloud-service security, which is the evidence to ask about, rather than assuming the vendor's certificate extends to them.
What should you verify on a translation vendor's ISO 27001 certificate?
A translation vendor's ISO 27001 certificate should be checked on six layers, each of which a security reviewer can confirm from documents rather than vendor assurances.
- Edition: The certificate names ISO/IEC 27001:2022. After October 31, 2025, a certificate naming only the 2013 edition is no longer valid.
- Certification body and validation: The certificate names the certification body and a certificate number. Confirm the body is accredited by a national accreditation body that is a member of the International Accreditation Forum (IAF), and validate the certificate with the body directly or through IAF CertSearch.
- Scope statement: The scope names the services, systems and activities covered. For a translation platform, look for the TMS environment, software development, infrastructure and customer support, and note anything your content flow uses that is not listed.
- Statement of Applicability: The SoA version is usually printed on the certificate. Request the SoA and check controls that matter most for translation content: 5.15 access control, 5.19 to 5.23 supplier and cloud-service security, 6.6 confidentiality or non-disclosure agreements for linguists, 8.5 secure authentication, 8.15 logging, 8.24 use of cryptography, and 8.25 to 8.29 secure development and testing.
- Validity and surveillance: Note the original certification date and expiry. If the certificate is more than a year old, ask whether the latest surveillance audit closed without open major nonconformities.
- Operating evidence alongside it: ISO/IEC 27001 confirms the ISMS conforms; a SOC 2 Type II report tests whether specific controls operated over a period. US procurement teams typically ask for both, and the guide to reading a SOC 2 Type II report for a translation management system covers the second half of that review.
ISO 27001 reference points a translation buyer can verify
| Item | Value | Why it matters when choosing a translation platform | Source |
|---|---|---|---|
| Annex A controls in ISO/IEC 27001:2022 | 93 controls in 4 themes: Organizational (37), People (8), Physical (14), Technological (34) | The SoA should show which of the 93 apply and justify every exclusion | ISO/IEC 27001:2022, Annex A |
| Certification cycle | 3 years, with surveillance audits in the intervening years before recertification | A certificate issued more than a year ago should have a completed surveillance audit behind it | ISO/IEC 17021-1:2015 |
| Transition deadline for 2013-edition certificates | October 31, 2025 | A vendor still presenting an ISO/IEC 27001:2013 certificate today does not hold a valid certificate | IAF MD 26:2023 |
| Smartling certificate | ISO/IEC 27001:2022, certificate ISMS-SM-101425, certification body A-LIGN, issued October 14, 2025, expires October 14, 2028 | Edition, number, body and dates are all printed, so the certificate can be validated with the issuer | Smartling ISO 27001 Certification page (smartling.com/iso27001) |
| Smartling ISMS scope | Confidentiality, integrity and availability of customer data, supplier information and internal data related to its SaaS-based Translation Management Services environment; registered activities: TMS Infrastructure, ISMS Management, Customer Support, Software Development | The scope names the TMS itself, which is where source content and translation memory live | Smartling ISO 27001 Certification page (smartling.com/iso27001) |
| Smartling SOC 2 | Continuously maintained since 2013; documents and reports available upon request | Pairs the ISO certificate with an attestation that tests control operation over time | Smartling Security page (smartling.com/security) |
| Smartling adjacent certifications | PCI Level 1 since 2012; HIPAA since 2013; GDPR since 2018; HITRUST e1 for the TMS residing at Amazon Web Services; ISO/IEC 42001:2023 | Each covers a question ISO/IEC 27001 leaves open: cardholder data, health information, EU personal data and AI governance | Smartling Security page (smartling.com/security) |
How do you evaluate a translation vendor's ISO 27001 certification during an RFP?
Evaluating ISO 27001 for a translation platform is a five-step exercise that turns an RFP checkbox into evidence a security reviewer can file.
- Request the certificate and validate it - Ask for the certificate PDF, confirm the 2022 edition, the certification body, the certificate number and the dates, then validate it with the issuing body. A vendor that publishes its certificate saves a round of questionnaire back-and-forth.
- Map the scope to your content flow - Trace how your content will move: CMS connector or API, the TMS, machine translation and LLM engines, linguists, and any website translation proxy. Each hop should be inside the certified scope or handled as a supplier under the vendor's Annex A 5.19 to 5.23 controls.
- Read the Statement of Applicability - Request the SoA, usually under NDA, and confirm that access control, cryptography, logging, supplier security and confidentiality agreements are applied. Ask for the justification behind any exclusion that touches content handling.
- Pair the certificate with operating and sector evidence - Request the current SOC 2 Type II report for control operation over time, and add the sector evidence your content requires: a Business Associate Agreement and HITRUST for health information, a data processing agreement for EU personal data, PCI DSS for cardholder data.
- Test fit with your security stack - Confirm single sign-on through your identity provider, multi-factor authentication, OAuth2 or token-based API authentication, exportable user and activity records, and published service levels. Certification proves the ISMS exists; integration proves your team can operate inside it.
This approach fits teams that...
- Run enterprise RFPs where ISO/IEC 27001 certification is a mandatory gate and the security team expects to see the certificate, scope and Statement of Applicability, not a logo.
- Translate confidential material such as pre-release product content, contracts, financial communications or internal policies.
- Sell into European or global markets where customers ask for ISO/IEC 27001 as the primary security artifact.
- Want automation, connectors and AI translation without widening the audit boundary their security team has to review.
- Maintain a vendor register that tracks certificate expiry dates and surveillance audits for every supplier handling company content.
When ISO 27001 may not be the deciding factor
- Your procurement standard is SOC 2. Many US security teams treat a SOC 2 Type II report as the primary artifact; lead with that request and treat ISO/IEC 27001 as corroboration.
- You translate protected health information. ISO/IEC 27001 does not establish HIPAA compliance. The deciding evidence is a Business Associate Agreement and the vendor's subcontractor chain, covered in which translation platforms are HIPAA compliant for protected health information.
- Your main exposure is EU personal data. GDPR processor obligations are met through a data processing agreement, sub-processor disclosure and deletion tooling, covered in what makes a translation platform GDPR compliant.
- Your question is AI governance. How a vendor assesses and controls AI risk is the subject of ISO/IEC 42001:2023, not ISO/IEC 27001.
- You translate only public content at low volume. Published marketing pages carry little confidentiality risk, and a standard security questionnaire may be a proportionate review.
Evaluation checklist: questions to ask a translation vendor about ISO 27001
Is your certificate issued against ISO/IEC 27001:2022, and which certification body issued it?
Ask for the certificate number and validate it with the issuer. A certificate naming only the 2013 edition lapsed after October 31, 2025.
Which services, systems and activities does the scope cover?
Confirm the TMS environment is named, then ask how connectors, machine translation and LLM routing, linguists and any website translation proxy are treated: inside scope, or managed as suppliers.
Can we review the Statement of Applicability?
Check that access control, cryptography, logging, secure development and supplier controls are applied, and ask for the reasoning behind any exclusion.
When was your last surveillance audit, and were any major nonconformities raised?
A certificate is only as current as its last audit. Ask for the date and whether findings were closed.
Do you also hold a SOC 2 Type II report?
ISO/IEC 27001 and SOC 2 answer different questions, and many enterprise buyers require both. Ask for the most recent Type II report under NDA.
Does ISO 27001 cover GDPR and healthcare content?
No single certificate does. ISO/IEC 27001 covers the security management system; GDPR requires a data processing agreement for EU personal data, and US health content requires a Business Associate Agreement under HIPAA, so ask for each separately.
How does the platform connect to our security stack?
Ask about SAML or OpenID Connect single sign-on, enforced multi-factor authentication, API authentication, and exportable user and activity records your SIEM or audit team can use.
What proof points exist beyond the certificate?
Peer review sites rate products, not certificates, so ask for customer references in your industry and for the vendor's published agreements and service levels.
How Smartling supports an ISO 27001 vendor review
Smartling publishes the details a reviewer needs to validate its certification. The Smartling ISO 27001 Certification page links the certificate itself: ISO/IEC 27001:2022, certificate number ISMS-SM-101425, issued by A-LIGN on October 14, 2025 and valid until October 14, 2028, with Statement of Applicability version 1.1. The certificate scopes the ISMS to the confidentiality, integrity and availability of customer data, supplier information and Smartling's internal data related to its SaaS-based Translation Management Services environment, with TMS Infrastructure, ISMS Management, Customer Support and Software Development as registered activities. Smartling announced the certification in Smartling achieves ISO 27001 certification for information security, which also states its policy of never training AI models on customer content.
The certificate sits inside a broader, published compliance record. The Smartling Security page lists SOC 2 compliance maintained since 2013, PCI Level 1 since 2012, HIPAA since 2013, GDPR since 2018, a HITRUST e1 certification for its Translation Management System residing at Amazon Web Services, and ISO/IEC 42001:2023 for AI management systems, and states that documents and reports are available upon request. That combination lets a reviewer pair the ISO/IEC 27001 certificate with a SOC 2 report and the sector evidence the content requires, from one vendor.
For the security-stack fit, Smartling supports single sign-on through a customer identity provider with optional automatic user registration (Smartling Help Center, "Integrating Single Sign-On (SSO)"), multi-factor authentication through an authenticator app (Smartling Help Center, "Logging in with Multi-Factor Authentication"), and OAuth2 authentication for its APIs (Smartling API Specification). Smartling's Master Services Agreement and Service Level Agreement are published on its Agreements and Terms page, so contract and service-level review can run in parallel with the security review rather than after it.
Related questions
- What enterprise localization platforms are trusted by security teams?
- What does a SOC 2 Type II report cover for a translation management system, and how should a buyer read it?
- What makes a translation platform GDPR compliant?
- Which translation platforms are HIPAA compliant for handling protected health information?
Ready to see Smartling in action?
Chat with someone on the Smartling team to see how we can help you get more out of your budget by delivering the highest quality translations, faster, and at significantly lower costs.