Today we announced that Focal Point has achieved ISO/IEC 27001:2022 certification for our information security management system. The certification adds to our SOC 2 Type II attestation. Together, they give our customers two independent views into how we protect the information that powers their procurement work.
I spent more than 20 years in procurement, much of it as a Chief Procurement Officer. In that seat, I sat through more vendor security reviews than I can count. I remember long questionnaires, follow-up calls with information security, and promising technology that stalled for months because a provider was unable to share how it protected sensitive data. Speed in procurement can never come at the expense of data security. We built Focal Point with that lesson in mind, and these certifications are the independent proof of it.
The post below explains what ISO 27001 and SOC 2 Type II actually tell you as a customer, how security is built into Focal Points AI procurement platform, and what both mean for your next security review.
Procurement leaders know this problem from both sides
Procurement teams are regularly asking suppliers for proof of security. The need for that scrutiny continues to grow. In the World Economic Forum’s Global Cybersecurity Outlook 2026, produced in collaboration with Accenture, 65 percent of large companies identified third-party and supply-chain vulnerabilities as their greatest barrier to cyber resilience. Yet only 33 percent of organizations comprehensively mapped their supply-chain ecosystems to understand cyberthreat exposure and interdependencies. For procurement leaders, those findings reinforce the value of clear, independently verified evidence of a provider’s security practices.
That makes procurement software a special case. The platform that manages your supplier data, contracts, pricing, and risk assessments is itself one of your most important third parties. Procurement leaders should hold it to the same standard they apply to every critical supplier, and we want to make that evaluation simple.
Two frameworks, two different questions
ISO 27001 and SOC 2 are often mentioned together, yet they answer different questions. ISO 27001 shows that an organization runs a systematic, risk-based program for managing information security. SOC 2 Type II shows, with detailed evidence, that specific controls actually operated effectively over a period of time. Focal Point pursued both because enterprise buyers deserve both answers.
| ISO/IEC 27001:2022 | SOC 2 Type II | |
| Question it answers | Does the company have a disciplined system for managing information security risk? | Did the company’s controls work as designed, consistently, over time? |
| Developed by | International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) | American Institute of Certified Public Accountants (AICPA) |
| What is assessed | The full life cycle of an information security management system (ISMS), supported by 93 controls across organizational, people, physical, and technological themes | Controls mapped to the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy |
| Result | A certificate issued by an accredited certification body | A detailed attestation report from an independent auditor, which can note exceptions |
| How it is maintained | Three-year certification cycle with annual surveillance audits | Audited annually over a defined review period |
| Focal Point status | Certified by A-LIGN; covers the design, development, implementation, and operation of our AI procurement platform | Audited annually on select Trust Services Criteria |
Think of ISO 27001 as proof that the security program exists and keeps improving. Think of SOC 2 Type II as proof that the program performs in practice, day after day.
Security built into every layer
From Maxim Maximov, Chief Technology Officer
From the first line of code, security has been part of the architecture of Focal Point, not something added later. Our ISO 27001 certification and SOC 2 Type II attestation are not a checkbox for us. They are independent validation of the intentional design and discipline our team brings daily to building a platform that customers can trust.
That commitment shows up in a few core principles:
- Least privilege access. Sensitive data is available only to people with a legitimate business need.
- Defense in depth. Layered security controls, including advanced encryption, are applied consistently across the organization and refined continuously for effectiveness and auditability.
- AI interactions stay private. We do not store the inputs or outputs of AI interactions. Supplier information, pricing, and contract details cannot be reused, exposed, or mined outside of each customer’s own environment.
- Customer control of data. Customers can access, correct, or request deletion of their data. Our Data Processing Addendum aligns data handling with global privacy standards, including GDPR and CCPA.
- Continuous improvement. Annual audits for both ISO 27001 and SOC 2 keep us accountable to independent reviewers year after year.
The last point matters most to me. Our certification and attestation are not one-time achievements. Each one requires us to keep proving that our controls work while the platform, the threat landscape, and our customers’ needs continue to change.
Why AI raises the bar for trust
AI becomes more useful in procurement when it can work with the full context behind a request. That context includes supplier information, contract terms, pricing, risk assessments, and input from many teams across the business. The same context that makes AI recommendations valuable also makes the security of the platform essential.
Enterprises will not hand that context to technology they cannot trust, and they should not. AI has to be trusted to truly serve the enterprise. We see data protection as the foundation for innovation, not a barrier to it. Strong security lets procurement teams adopt AI with confidence, bring more of their work into one connected environment, and spend less time managing risk and more time creating strategic value.
What this means for your next security review
These independent reviews make evaluating Focal Point’s AI Procurement Platform faster and clearer for procurement, IT, and security leaders:
- Fewer questionnaires. Independent evidence answers many of the questions your team would otherwise send in a custom security questionnaire.
- Faster evaluations. Your information security team can review established, widely recognized standards instead of starting from scratch.
- Ongoing assurance. Annual audits mean the evidence stays current for as long as you work with us.
- Confidence for regulated industries. Organizations in legal, financial services, and other regulated sectors often require these standards before an evaluation can even begin.
To request our ISO/IEC 27001:2022 certificate or SOC 2 Type II report, contact us here.
Focal Points commitment
Procurement sits at the center of how an enterprise spends, contracts, manages risk and delivers business outcomes. Our customers rely on Focal Point to be a secure extension of their teams, and we take that responsibility seriously. Earning ISO 27001 certification and maintaining our SOC 2 Type II attestation are important milestones. Our work to protect your data will never be finished, and we would not want it any other way.
To see how our AI procurement platform brings requests, supplier information, and project activity together securely, join us in October for “3 Questions to Pressure-Test Your AI Procurement Platform.” Register here.
Anders Lillevik, Founder and CEO
Maxim Maximov, Chief Technology Officer