Categorie serviciu: Management Systems Certification

  • Quality management system

    Quality management system

    Cerere ofertă

    What is the ISO 9001 standard?

    Before beginning the process, many entrepreneurs and managers wonder what ISO 9001 means and what quality management according to this standard entails.

    ISO 9001 is the international standard that establishes the requirements for a quality management system applicable to any organization, regardless of size, field of activity, or region. In Romania, the standard is adopted as SR EN ISO 9001, the reference against which certification is conducted.

    Quality management according to ISO 9001 is based on several fundamental principles: customer focus, committed leadership, a process-based approach, risk-based thinking, and continuous improvement. In practice, an ISO 9001 quality management system helps an organization consistently deliver products and services that meet customer requirements and applicable legal requirements.

     

    ISO 9001:2015 – current edition

    Currently, certification is conducted in accordance with the ISO 9001:2015 standard (SR EN ISO 9001:2015). This version introduced the high-level structure (Annex SL), which is common to several management standards, and emphasized risk-based thinking and greater involvement of top management in the quality management system.

     

    ISO 9001:2026 – The New Edition and the Transition Period

    The standard is currently under review, and the new edition, ISO 9001:2026, is expected to be officially published in September 2026. The changes are evolutionary, not radical: the basic structure (clauses 4–10) remains the same, but there is an increased emphasis on quality culture and ethical behavior within the organization, data analysis, automation, and artificial intelligence integrated into the annex, expanded requirements regarding the supply chain and stakeholder expectations, as well as the resilience of the supply chain to climate risks. Following the publication of the new edition, organizations will have a 3-year transition period to transition from ISO 9001:2015 to ISO 9001:2026. 

    The recommendation for organizations seeking certification now is simple: there is no need to wait for the new edition. An ISO 9001:2015 certification obtained at this time is valid and provides a solid foundation for the subsequent transition to ISO 9001:2026.

     

    The Requirements of the ISO 9001 Standard

    The ISO 9001 requirements are set forth in clauses 4–10 of the standard and cover all the elements necessary for a functional quality management system:

    • the organization’s context and an understanding of stakeholders’ needs;
    • leadership and management commitment, quality policy and objectives;
    • planning, including addressing risks and opportunities;
    • documented resources, competencies, and information;
    • the conduct of operational processes and the control of products and services;
    • performance evaluation through monitoring, internal audits, and management analysis;
    • continuous improvement, through addressing nonconformities and taking corrective actions.

    These requirements are based on the PDCA cycle (Plan – Do – Check – Act), which ensures the consistent operation and continuous improvement of the quality management system.

     

    The Benefits of Implementing and Obtaining ISO 9001 Certification

    Implementing and certifying an ISO 9001 quality management system brings tangible benefits to any organization:

    • meeting the requirements of customers, business partners, and applicable legal requirements;
    • increasing credibility and confidence in the quality of the products and services offered;
    • increasing customer satisfaction and loyalty;
    • a better understanding of and greater control over internal processes, with clearly defined responsibilities and improved communication;
    • more efficient use of resources and a reduction in costs resulting from nonconformities;
    • access to public tenders and procurement, where ISO 9001 certification is frequently required;
    • strengthening its image and competitive position in the domestic and international markets.

    .

    Is ISO 9001:2015 certification mandatory?

    From a legal standpoint, ISO 9001:2015 certification is generally not mandatory. In practice, however, it becomes a de facto requirement in many situations: when participating in public tenders and procurement, in relationships with large clients or corporations, in supply chains where suppliers must demonstrate a quality management system, or when an organization wishes to differentiate itself from the competition. Thus, even if it is not required by law, ISO 9001 certification is often a prerequisite for winning contracts and accessing new markets.

     

    How can you obtain ISO 9001:2015 certification through SRAC?

    The ISO 9001 certification process with SRAC is clear and predictable. Once the quality management system has been implemented within the organization, SRAC auditors conduct a conformity assessment. SRAC provides ISO 9001 certification for organizations across all economic and social sectors (39 EA fields).

     

    The Stages of ISO 9001 Certification

    1. Submitting the request for proposal and finalizing the contract details.
    2. The two-stage certification audit: a review of documentation and an assessment of how the quality management system operates.
    3. Addressing any nonconformities and implementing corrective actions.
    4. Issuance of the ISO 9001 certificate, valid for 3 years, subject to annual surveillance audits being carried out.
    5. The recertification audit (certification renewal), to extend the validity of the certificate for a further three-year period.

     

    Why SRAC – RENAR Accreditation and International Recognition IQNET and IAF

    SRAC is accredited by RENAR—the national accreditation body (RENAR – Certificate No. SM 004)—to certify quality management systems in 39 fields across all economic and social sectors, in accordance with the reference standard SR EN ISO 9001:2015.

    The SRAC certificate is internationally recognized thanks to its accreditation by RENAR – a signatory to the international IAF-MLA agreement – and its partnership with IQNET (The International Certification Network).

    Organizations certified by SRAC receive both the SRAC certificate and the IQNET certificate at no additional cost. This assures customers and business partners that the audits were conducted to the highest standards of impartiality and professionalism, and it also facilitates access to foreign markets.

     

    Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organizations / over 25,000 certificates issued in 30 years. From top brands to major public institutions, leading companies have chosen our services. 

    Choose the leader in certification — Get certified with SRAC!

    Portofoliu clienți

     

    Frequently Asked Questions About ISO 9001 Certification

    What does ISO 9001 certification mean? 

    ISO 9001 certification is confirmation by an independent bodythat the quality management system implemented within an organization complies with the requirements of the SR EN ISO 9001 standard. It attests that the organization operates based on controlled processes that are customer-focused and geared toward continuous improvement.

     

    How much does ISO 9001 certification cost? 

    The cost of ISO 9001 certification varies depending on the size of the organization, the number of employees, the complexity of the processes, and the number of locations. For an exact price, we recommend that you request a customized quote.

     

    How long does it take to obtain ISO 9001 certification? 

    The duration depends on the organization’s level of preparedness and the complexity of the quality management system. Upon successful completion of the certification audit and resolution of any nonconformities, the ISO 9001 certificate will be issued within a maximum of 10 days following review by the Technical Committee and its recommendation to grant certification.

     

    How long is the ISO 9001 certificate valid? 

    The ISO 9001 certificate is valid for three years, provided that the annual surveillance audits are passed successfully. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.

     

    Under what accreditation does SRAC issue the ISO 9001 certificate? 

    SRAC issues ISO 9001 certificates under the accreditation of RENAR (certificate no. SM 004), the national accreditation body. These certifications are also recognized internationally through a partnership with the IQNET network and RENAR’s accreditation, as a signatory to the IAF-MLA (Multilateral Recognition Arrangement). 

     

    Is ISO 9001 certification valid for public tenders?

    Yes. ISO 9001 certification is accepted in public tenders and procurement, where demonstrating a quality management system is often a mandatory requirement or a selection criterion in the SEAP/SICAP system. For the certificate to be accepted, it must be issued by a certification body accredited by RENAR (in Romania) or by an equivalent international body that is a signatory to the IAF (International Accreditation Forum) agreement.

     

    What will happen to ISO 9001:2015 certification after the release of ISO 9001:2026?

    ISO 9001:2015 certificates remain valid throughout the 3-year transition period following the publication of the new edition (expected in September 2026). Organizations will be able to transition to ISO 9001:2026 before their certificates expire.

     

    Can I combine ISO 9001 certification with other standards? 

    Yes. ISO 9001 shares a common structure (Annex SL) with other management standards, which allows for integration with standards such as ISO 14001 (environment)ISO 45001 (occupational health and safety) or ISO 27001 (information security) into an integrated management system.

  • Environmental management system

    Environmental management system

    Request a quote

     

    What is ISO 14001?

    ISO 14001 is the standard that specifies the requirements for an environmental management system (Environmental Management System). Its purpose is to provide organizations with a framework through which they can control the impact of their activities, products and services on the environment and continuously improve their environmental performance. The ISO 14001 standard is applicable to any organization, regardless of size, field of activity or location.

     

    What is an environmental management system?

    An environmental management system is a systematic approach through which an organization identifies, monitors and controls the effects of its activities on the environment. Instead of reacting to isolated problems, the organization structures its processes so as to prevent pollution, use resources efficiently and reduce the risk of environmental accidents. An environmental management system in accordance with ISO 14001 thus becomes a practical tool for managing environmental issues, integrated into day-to-day activities.

     

    Environmental aspects and compliance obligations

    Two concepts are essential to understanding the ISO 14001 standard. Environmental aspects are the elements of an organization’s activities, products or services that can interact with the environment – for example, energy and water consumption, air emissions, waste generation or discharges into water. Each environmental aspect results in an environmental impact, and the organization must identify these aspects and rank them according to the significance of their impact. These are complemented by compliance obligations – legal and other requirements that the organization must comply with in the environmental field. An effective environmental management system keeps significant environmental aspects under control and ensures compliance with applicable obligations.

     

    Versions of the ISO 14001 standard

    SR EN ISO 14001:2015 – current edition

    Currently, certification is carried out based on the ISO 14001:2015 edition, adopted in Romania as SR EN ISO 14001:2015. This version introduced the High-Level Structure (Annex SL), common to modern management standards, with an emphasis on leadership, risk-based thinking and a life-cycle perspective when assessing environmental aspects. Certificates issued under SR EN ISO 14001:2015 are valid and internationally recognized.

     

    ISO 14001:2026 and climate change

    The standard has been revised, and the new edition, ISO 14001:2026, was published in April 2026. The changes are moderate, focusing mainly on clarifying existing requirements and aligning the standard with the harmonized structure of management standards. The new edition incorporates the climate change amendment published in 2024 – which requires organizations to assess whether climate change is a relevant issue for their context – and adds further considerations regarding the use of natural resources, pollution and biodiversity. Organizations certified according to the 2015 edition have a 3-year transition period (until 2029) to move to ISO 14001:2026. For organizations seeking certification now, SR EN ISO 14001:2015 certification remains valid and provides the basis for subsequent transition.

     

    Benefits of ISO 14001 certification

    ISO 14001 certification brings tangible benefits:

    • gaining and maintaining market share by promoting a “green” organizational image;
    • demonstrating actual environmental performance to interested parties through the technical and economic management of environmental issues;
    • attracting ethical investments;
    • reducing risks and, consequently, insurance costs;
    • reducing costs through more efficient use of resources and a lower risk of environmental accidents;
    • complying with environmental legal obligations and reducing the risk of sanctions;
    • the possibility of integration with other management systems, such as ISO 9001 or ISO 45001.

    .

    Is environmental certification mandatory?

    From a legal perspective, ISO 14001 environmental certification is generally not mandatory. However, it should be distinguished from the environmental permit, which is a separate legal requirement for certain activities. In practice, ISO 14001 certification often becomes a de facto requirement: in tenders and public procurement, in relationships with major clients or clients in regulated sectors, in supply chains that impose environmental standards on suppliers, and when an organization wants to strengthen its reputation and environmental responsibility. Thus, although it is not required by law, ISO 14001 certification is frequently a condition for winning contracts and accessing new markets.

     

    How to obtain ISO 14001 certification with SRAC

    The ISO 14001 certification process involves auditing the environmental management system against the requirements of the standard.

     

    Certification stages

    1. Submission of the quotation request and establishment of the contractual details.
    2. Two-stage certification audit: review of the documentation and on-site assessment of how the environmental management system operates.
    3. Addressing any nonconformities and implementing corrective actions.
    4. Issuance of the ISO 14001 certificate, valid for 3 years, subject to successful completion of annual surveillance audits.
    5. Recertification audit (renewal of certification) to extend the validity of the certificate for a new 3-year cycle.

    .

    Cost of ISO 14001 certification

    The cost of ISO 14001 certification depends on the size of the organization, number of employees, complexity of processes and number of locations. To find out the exact price for ISO 14001 certification, the best solution is to request a customized quotation.

     

    Why SRAC

    SRAC is accredited by RENAR – the national accreditation body (certificate no. SM 004) for the certification of environmental management systems in 39 fields covering all economic and social sectors, in accordance with the reference standard SR EN ISO 14001:2015. In addition, the SRAC certificate is internationally recognized through RENAR accreditation, as a signatory to the international IAF-MLA agreement, as well as through SRAC’s partnership with IQNET (The International Certification Network). Certified organizations receive, at no additional cost, both the SRAC certificate and the IQNET certificate, and are entitled to use the conformity marks for promotional purposes.

     

    Join the most important companies and institutions in Romania that have chosen the SRAC mark: over 10,000 certified organizations / over 25,000 certificates awarded in 30 years. From top brands to major public institutions, leading companies have chosen our services.

    Choose the leader in certification – Get certified with SRAC!

    SRAC client portfolio

     

    ISO 14001 within an integrated management system

    One of the major advantages of ISO 14001 is that it shares the High-Level Structure (Annex SL) with other management standards, such as ISO 9001 (quality management system) and ISO 45001 (occupational health and safety management system). This enables the development of an integrated management system in which quality, environmental and occupational health and safety are managed coherently, with common procedures and combined audits. For organizations that already hold ISO 9001 certification, adding ISO 14001 is generally a natural and efficient step.

     

    Who is ISO 14001 intended for?

    ISO 14001 is intended for any organization that wants to responsibly manage its environmental impact, regardless of size or field of activity. It is particularly relevant for companies in manufacturing, construction, energy, transport, services or public administration, as well as for any organization that participates in tenders, works with environmentally demanding clients or wants to reduce its environmental footprint and operating costs.

     

    Frequently asked questions

    What does ISO 14001 certification mean?

    ISO 14001 certification is confirmation, by an independent accredited certification body, that an organization’s environmental management system complies with the requirements of the ISO 14001 standard. It confirms that the organization controls its environmental impact and pursues continuous improvement of its environmental performance.

     

    Do I need an environmental permit to obtain ISO 14001 certification?

    An environmental permit and ISO 14001 certification are two different things. An environmental permit is a legal requirement for certain activities, whereas ISO 14001 certification is voluntary and confirms the existence of an environmental management system. Compliance with legal obligations, including holding the necessary permits, is nevertheless part of the requirements of the standard.

     

    What is new in ISO 14001:2026 and do I need to transition now?

    ISO 14001:2026, published in April 2026, incorporates the climate change amendment and clarifies a number of requirements, with an emphasis on context, life cycle and leadership. Organizations certified according to the 2015 edition have a 3-year transition period (until 2029), meaning that the transition can be planned within the regular audit cycle.

     

    How long is an ISO 14001 certificate valid?

    The ISO 14001 certificate is valid for 3 years, subject to successful completion of annual surveillance audits. If the validity of the certificate is to be extended, a recertification audit (renewal of certification) is carried out at the end of the period.

     

    What is the difference between ISO 14001 and ISO 9001?

    ISO 9001 is the standard for a quality management system, focused on customer satisfaction and the organization’s processes, while ISO 14001 concerns the environmental management system, namely the organization’s impact on the environment. The two standards have a common structure and can be implemented together as part of an integrated system.

     

    How much does ISO 14001 certification cost?

    The price varies depending on the size of the organization, number of employees, complexity of processes and number of locations. For an exact price, we recommend requesting a customized quotation.

     

    Is environmental management system certification mandatory for public tenders?

    It is not mandatory by law, but it is frequently requested in the specifications of tenders and public procurement procedures as evidence of responsible environmental management. Authorities may use it either as an eligibility requirement for participation or to award additional points within the technical and economic evaluation of the tender. In many cases, ISO 14001 certification thus becomes a condition for participating in or winning a tender.

     

    What do I need to do to get started?

    Obtaining certification for an environmental management system (ISO 14001) involves two major phases: internal implementation and an external certification audit carried out by an accredited certification body.

    Choose a certification body (e.g. SRAC), which verifies whether your organization is ready for the two-stage certification audit:

    • Stage 1 (Document Review Audit): The auditor verifies whether the documents and procedures comply with the ISO 14001 standard.
    • Stage 2 (On-site Audit): The auditor visits the company’s sites (factories, offices, warehouses) to verify on site how the environmental procedures are being applied. Waste management, equipment condition and response to emergency situations (e.g. accidental spills) are checked, and interviews are conducted with personnel.

    If no major nonconformities are identified (or after the identified ones have been corrected), the certification body issues the ISO 14001 certificate, valid for 3 years.

    In years 1 and 2, surveillance audits are conducted to confirm continued compliance with the standard and the effective operation of the system.

    At the end of the cycle, to continue the certification, a recertification audit is carried out.

  • Occupational health and safety management system

    Occupational health and safety management system

    • developing a work system with lower risks of injury and/or professional disease
    • achieving a better control of the injury and/or professional disease
    • transparency and effectiveness of the occupational health and safety management system by transposing the outputs of the risk assessments, audits, inspections etc. into action plans to minimize the risk of accidents
    • achieving improved employee performances by ensuring a “state of well-being” in the workplace
    • favorable perception from suppliers, beneficiaries and society in general

    Why SRAC?

    SRAC is accredited for the occupational health and safety management systems certification by:
    • RENAR – The national accreditation body (Certificate SM 004), in compliance with SR ISO 45001:2018 reference standard.
     
    SRAC certifications are recognized at an international level through SRAC partnership in IQNet (The International Certification Network).
    To that extent, the organizations certified by SRAC receive, together with SRAC Certificate, also the IQNet Certificate, without any additional costs.
    Upon the certification process successfully completed, SRAC certified organizations:
    • have the right to use SRAC and IQNet conformity marks for advertising purposes;
    • are regularly informed on the evolutions in the occupational health and safety and certification areas, by accessing SRAC website, events organized by SRAC.

     

    Why certification?

    In the modern society, promoting the health and safety conditions in the workplace and ensuring a comfortable work environment, observing the normative requirements and maintaining a good business reputation are key aspects which should be considered by every successful organization.
    The implementation and certification of an occupational health and safety management system is an effective tool for organizing and focusing the efforts of an organization towards a better control and management of the work-related hazards (accidents, incidents and occupational diseases) and a significant improvement of the professional performances.
  • Information security management system

    Information security management system

    What is the ISO 27001 standard?

    Before embarking on the implementation and certification process, many organisations wonder what ISO 27001 is and what, exactly, an information security management system entails. ISO/IEC 27001 is the international standard that sets out the requirements for establishing, implementing, maintaining and continuously improving an information security management system, applicable to any organisation that processes or stores information, regardless of its field of activity.

    The ISO 27001 standard is based on three properties that define information security: confidentiality (the property of information not being accessible to or disclosed to unauthorised entities), integrity (the property of information being accurate and complete) and availability (the property of information to be accessible and usable on demand by an authorised entity). In practice, ISO 27001 helps organisations to identify security risks, assess them and manage them, thereby demonstrating to stakeholders that sensitive data is protected.

     

    ISO/IEC 27001:2022 – current edition

    Certification is currently carried out in accordance with ISO/IEC 27001:2022, the third edition of the standard, published in October 2022. In Romania, this has been adopted as SR EN ISO/IEC 27001:2023, the European version transposed at national level. ISO/IEC 27001:2022 retains the high-level structure (Harmonised Structure) common to management standards, which facilitates integration with other systems, such as the ISO 9001 quality management system.

     

    What has changed compared with ISO/IEC 27001:2013

    The main change in the ISO/IEC 27001:2022 standard concerns Annex A: the number of security controls has been reduced from 114 to 93 and reorganised into four categories – organisational, personnel, physical and technological. Eleven new controls have also been introduced, focusing on current threats (cyber security, cloud services, data protection). The transition period from ISO/IEC 27001:2013 ended on 31 October 2025; consequently, only certificates issued in accordance with the 2022 edition are currently valid, and organisations seeking certification now do so directly against ISO/IEC 27001:2022.

     

    The requirements of the ISO 27001 standard

    The requirements of ISO 27001 are set out in clauses 4–10 of the standard and define the framework for a functional information security management system:

    • the organisation’s context and the identification of stakeholders;
    • leadership and management commitment, information security policy;
    • assessing and addressing information security risks;
    • setting security objectives and planning how to achieve them;
    • resources, skills, awareness and documented information;
    • implementing security controls and drawing up the Statement of Applicability;
    • performance assessment through monitoring, internal audits and management analysis;
    • continuous improvement, through the resolution of non-conformities and corrective actions.

    The controls used to manage information security risks are selected from Annex A of the standard, depending on the risks identified and the specific characteristics of the organisation.

     

    The benefits of implementing and obtaining ISO 27001 certification

    The implementation and certification of an information security management system bring tangible benefits to any organisation:

    • to instil credibility and confidence in customers, employees, contractual partners and owners that the company’s information and IT systems are protected;
    • proof, for the authorities, that the laws and regulations in force are being complied with, including the requirements relating to the protection of personal data;
    • a business continuity and incident recovery plan appropriate to the organisation;
    • increasing productivity by reducing operational risks and improving the availability of IT systems;
    • strategic differentiation from the competition, both in public procurement procedures and in commercial contracts involving access to sensitive data or state secrets;
    • reducing the likelihood and impact of security incidents, such as cyber-attacks, fraud or data breaches.

     

    Is ISO 27001 certification compulsory?

     

    From a legal perspective, ISO 27001 certification is not, in general, mandatory. In practice, however, it is increasingly becoming a requirement. Article 32 of the GDPR requires appropriate technical and organisational measures for the security of personal data – this aspect is addressed in ISO 27001 and elaborated on in detail in ISO 27701. Added to these are the requirements of public tenders and procurement, contracts with large clients or those in regulated sectors, and supply chains where suppliers must demonstrate a high level of information security. Thus, although it is not explicitly required by law in most cases, ISO 27001 certification is often a prerequisite for securing contracts and accessing new markets.

     

    How can you obtain ISO 27001 certification with SRAC?

    The ISO 27001 certification process with SRAC is clear and predictable. Once the information security management system has been implemented, SRAC’s auditors carry out a conformity assessment. SRAC provides ISO 27001 certification for organisations in Romania across all sectors.

     

    The stages of ISO 27001 certification and auditing

    1. Auditul ISO 27001 de certificare, include umătoarele etape:
    • analiza documentelor sistemului de management (inclusiv a Declarației de aplicabilitate).
    • etapa 1 in care se evaluează condițiile specifice locației clientului; analizarea stadiului SMSI al solicitantului şi a înţelegerii de către acesta a cerinţelor standardului; evaluarea nivelului de implementare a SMSI etc.
    • etapa 2 în care se determină eficacitatea sistemului de management pentru a asigura faptul că organizația, pe baza evaluarii riscului, a implementat controale aplicabile și a atins obiectivele stabilite de securitatea informațiilor; confirmarea că organizaţia client aderă la politicile, obiectivele şi procedurile proprii și că SMSI este conform cu toate cerinţele standardului ISO/IEC 27001.
    1. Tratarea eventualelor neconformități și implementarea acțiunilor corective.
    2. Emiterea certificatului ISO 27001, valabil 3 an, cu condiția realizării auditurilor anuale de supraveghere.
    3. Auditul de recertificare (reînnoirea certificării), pentru prelungirea valabilității certificatului pentru un nou ciclu de 3 ani.

     

    Why SRAC: RENAR accreditation and international recognition by IQNET and IAF

    SRAC is accredited by RENAR – the national accreditation body (certificate no. SM 004) – to certify information security management systems in accordance with the reference standard SR EN ISO/IEC 27001:2023.

    The SRAC certificate is internationally recognised thanks to its RENAR accreditation – a signatory to the international IAF-MLA agreement and its partnership with IQNET (The International Certification Network).

    Organisations certified by SRAC receive both the SRAC certificate and the IQNET certificate at no extra cost. This reassures customers and business partners that the audits have been carried out to the highest standards of impartiality and professionalism, and also facilitates access to foreign markets.

     

    Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organizations / over 25,000 certificates issued in 30 years. From top brands to major public institutions, leading companies have chosen our services.

    Choose the leader in certification—Get certified with SRAC!

    Portofoliu clienți

     

    Frequently Asked Questions about ISO 27001 certification

    What does ISO 27001 certification mean?

    ISO 27001 certification is confirmation, by an independent accredited body, that an organisation’s information security management system complies with the requirements of the ISO/IEC 27001 standard. It attests that the organisation manages security risks in a structured manner and protects the confidentiality, integrity and availability of information.

     

    How much does ISO 27001 certification cost?

    The cost of ISO 27001 certification varies depending on the size of the organisation, the number of employees, the complexity of the IT infrastructure and the scope of the system. For an exact price, we recommend that you request a personalised quote.

     

    How long does it take to obtain ISO 27001 certification?

    The duration depends on the organisation’s level of preparedness and the complexity of the information security management system. Following the successful completion of the certification audit and the resolution of any non-conformities, the ISO 27001 certificate will be issued within a maximum of 10 days after review by the SRAC Technical Committee and its recommendation to grant certification.

     

    How long is the ISO 27001 certificate valid for?

     

    The ISO 27001 certificate is valid for three years, provided that certification is maintained by successfully passing annual surveillance audits. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.

     

    Under what accreditation does SRAC issue the ISO 27001 certificate?

    SRAC issues ISO 27001 certificates under the accreditation of RENAR (certificate no. SM 004), the national accreditation body, in accordance with SR EN ISO/IEC 27001:2023.

    The SRAC certificate is internationally recognised thanks to its accreditation by RENAR – a signatory to the international IAF-MLA agreement – and its partnership with IQNET (The International Certification Network).

     

    Are ISO/IEC 27001:2013 certificates still valid?

    No. The transition period for ISO/IEC 27001:2022 ended on 31 October 2025, and certificates issued under the 2013 edition are no longer valid. Certification is now carried out exclusively in accordance with ISO/IEC 27001:2022.

     

    Is ISO 27001 certification mandatory?

    From a legal perspective, certification is not generally mandatory. However, ISO 27001 covers the security measures required by regulations such as the GDPR (Article 32) and is frequently required in tenders, public procurement and contracts involving access to sensitive data.

     

    Can ISO 27001 certification be integrated with other standards?

    Yes. ISO 27001 shares a high-level structure with other management standards, which allows for integration with standards such as ISO 9001 (quality management), ISO 27701 (privacy information management) or ISO 22301 (business continuity) within an integrated management system.

     

    What is the current situation regarding ISO 27001 certification in Romania and globally?

    According to the latest official global statistics compiled by IAF CertSearch (The IAF CertSearch Database), the number of active certificates for the main international standards is as follows:

    • ISO 9001 (quality): 474,118 certificates worldwide, of which 12,065 are in Romania and 3,375 were issued by SRAC.
    • ISO 14001 (environment): 232 certificates worldwide, 7,103 in Romania, 2,000 issued by SRAC.
    • ISO 45001 (occupational health and safety): 527 certificates worldwide, 3,639 in Romania, 1,213 issued by SRAC.
    • ISO/IEC 27001 (information security): 709 certificates worldwide, 792 in Romania, 285 issued by SRAC (36% market share).
  • Energy management system

    Energy management system

    • the evidence that the legal and regulatory requirements in the field are observed;
    • gaining and maintaining the market share by promoting an image of energy efficiency of products and services;
    • obtaining real performances regarding energy and showing these performances to interested parties, by the aid of an economic and technical management of significant aspects regarding energy;
    • reducing the insurance costs;
    • attracting investments;
    • reducing costs by a more efficient use of resources.

    Why SRAC?

    SRAC is accredited for the energy management systems certification by:

    • RENAR – The national accreditation body (Certificate SM 004), in compliance with SR EN ISO 50001:2019 reference standard.

    SRAC certifications are recognized at international level through SRAC partnership in IQNet (The International Certification Network). To that extent, the organizations certified by SRAC receive, together with SRAC Certificate, also the IQNet Certificate, without any additional costs.

    Upon the certification process successfully completed, SRAC certified organizations:

    • have the right to use SRAC conformity mark for advertising purposes;
    • are regularly informed on the evolutions in the energy management area, by accessing the SRAC website, events organized by SRAC.

     

    Why certification?

    The implementation and certification of an energy management system helps your organization to:

    • make significant savings due to of the increased energy efficiency;
    • reduce the greenhouse gas emissions (monthly monitoring and tracking of compliance with normative-regulated consumption limits);
    • identify the variables that impact on the use and consumption of energy.

    An organization can choose to integrate the energy management system with others, including those related to quality, environment and occupational safety.

    This international standard can be applied regardless of the types of energy used.

  • Quality for medical devices management system

    Quality for medical devices management system

    • meeting the customer and business partners requirements and the legal requirements
    • evidence of adherence to legal and regulatory or contractual requirements 
    • minimize and manage risks in the organization’s processes
    • preventing errors in making products and / or services
    • improved performance quality
    • transparency and clarity of internal processes
    • time and cost savings

    This standard is addressed to:

    • companies operating in the field of medical devices: designers, producers, distributors / suppliers;
    • organizations performing installation, maintenance, service and training in the field of medical devices;
    • companies that produce subassemblies for medical devices

     

    Why SRAC?

    Upon the certification process successfully completed, SRAC certified organizations:

    • have the right to use SRAC and IQNet conformity marks for advertising purposes;
    • are regularly informed on the evolutions in the quality for medical devices and certification areas, by accessing SRAC website, events organized by SRAC.

     

    Why certification?

    Every successful organization should:

    • identify and satisfy the needs and expectations of its customers, as well as of its stakeholders, respectively employees, suppliers, owners, society, in order to obtain a competitive advantage, and to achieve this in an effective way;
    • obtain, maintain and improve its general performances and capabilities on a continuous basis and the strong commitment to achieve the quality is the key. 
  • Anti-bribery management system

    Anti-bribery management system

    ISO 37001 is designed to help your organization implement an anti-bribery management system or enhance the controls you currently have. It requires implementing a series of measures such as:

    • adopting an anti-bribery policy;
    • appointing someone to oversee compliance with that policy, vetting and training employees;
    • undertaking risk assessments on projects and business associates;
    • implementing financial and commercial controls;
    • instituting reporting and investigation procedures.
    Implementing an anti-bribery management system requires leadership and input from top management, and the policy and program must be communicated to all staff and external parties such as contractors, suppliers and joint venture partners.
    In this way, it helps to reduce the risk of bribery occurring and can demonstrate to your management, employees, owners, funders, customers and other business associates that you have put in place internationally recognized good-practice anti-bribery controls. It can also provide evidence in the event of a criminal investigation that you have taken reasonable steps to prevent bribery.

    What is an anti-bribery management system?

    An anti-bribery management system is designed to impose an anti-bribery culture in an organization and to implement appropriate controls, which will increase the chance of detecting bribery and reducing its incidence.

    The anti-bribery management system, which is based on a number of measures and means of control, including support guidelines, specifies requirements on the following aspects:

    • Anti-bribery policy and procedures;
    • Management leadership, commitment and responsibility;
    • Training in the spirit of fighting bribery;
    • Designation of a person to oversee compliance with this policy;
    • Due diligence on projects and business associates;
    • Financial, commercial and contractual controls, as well as in the field of acquisitions;
    • Reporting, monitoring, investigation and review actions, as well as audits;
    • Corrective actions and continual improvement.

     

  • Business continuity management system

    Business continuity management system

    • identifying and managing current and future threats to your business;
    • proactive approach to minimize the impact of incidents;
    • reducing the costs of business interruption;
    • increases confidence in the organization’s ability to continue operations during a business interruption;
    • protects reputation;
    • helps meet legislative requirements;
    • contributes to organizational resilience.

     

    Why SRAC?

    SRAC is accredited for the certification of Business Continuity Management Systems by IAS (International Accreditation Service, Inc.) – certificate no. MSCB-353

    Upon the certification process successfully completed, SRAC certified organizations:

    • have the right to use SRAC conformity mark for advertising purposes;
    • are informed about certification developments, training courses, events organized by SRAC.

    Why certification?

    ISO 22301, the world’s first international standard for Business Continuity Management (BCM), has been developed to help organizations minimize the risk of such disruptions. This standard will replace the current British standard BS 25999-2.

    ISO 22301 was developed so that compatibility with other management systems like ISO 9001 (quality management), ISO 14001 (environmental management) and ISO/IEC 27001 (information security management) etc. can be ensured, and this led to some differences of terminology in comparison to BS 25999-2.

  • Service management system

    Service management system

    • services that can satisfy clients’ expectations;
    • it guarantees that the people, processes and technologies are in constant interaction and that they are coordinated towards the established objectives;
    • it increases the stakeholders’ trust and it improves the organization’s image.

     

    To whom is it useful?

    • an organization seeking services from service providers and requiring assurance that their service requirements will be fulfilled;
    • an organization that requires a consistent approach by all its service providers, including those in a supply chain;
    • a service provider that intends to demonstrate its capability for the design, transition, delivery and improvement of services that fulfill service requirements;
    • a service provider to monitor, measure and review its service management processes and services.

     

    Why SRAC?

    SRAC is accredited for certification of Service Management Systems by IAS (International Accreditation Service, Inc.) – certificate no. MSCB-353
    Upon the certification process successfully completed, SRAC certified organizations:

    • have the right to use SRAC conformity marks for advertising purposes;
    • have access to the training courses offer;
    • are regularly informed on the evolutions in the IT service management areas, by accessing SRAC website, events organized by SRAC.

     

    Why certification?

    In order for an organization to function efficiently, it has to identify and manage several correlated activities. An activity that consumes resources and which is managed in such a way that the inputs are transformed in outputs is considered a process. Many times, the outputs of a process become the inputs of another one. The coordinated integration and the implementation of the service management guarantees the continual control, an increased effectiveness and opportunities for continual improvement.

  • Privacy information management system

    Privacy information management system

    Cerere ofertă

     

    What does ISO/IEC 27701 mean?

    ISO/IEC 27701 is the international standard that sets out the requirements for a privacy information management system. It was developed by ISO in response to organisations’ need to protect the personally identifiable information they collect, store and process, providing a structured framework for managing privacy risks.

     

    What is a Privacy Information Management System (PIMS)?

    A privacy information management system, known as a PIMS (Privacy Information Management System), is the set of policies, procedures and controls through which an organisation manages personal data. In practice, a PIMS extends the principles of information security to a specific area: the protection of the privacy and personal data of data subjects.

     

    From an extension of ISO 27001 to a stand-alone standard

    Initially, in the 2019 edition, the ISO 27701 standard functioned as an extension of ISO/IEC 27001 and ISO/IEC 27002 – which meant that an organisation had to already have an ISO 27001 information security management system in place in order to be certified. With the publication of the ISO/IEC 27701:2025 edition (October 2025), the standard has become a stand-alone management standard: it adopts the common high-level structure (clauses 4–10), aligns with ISO 9001, ISO/IEC 27001:2022 and ISO/IEC 42001, and can be implemented and certified independently. Organisations certified under the 2019 edition benefit from a three-year transition period, until October 2028.

     

    Who is the ISO 27701 standard aimed at?

    The ISO 27701 standard is aimed at both data controllers (those who determine the purposes and means of processing) and data processors (those who process data on their behalf). It applies to organisations of any size and from any sector that collect or process personal data and wish to demonstrate, through a risk-based approach, that they comply with data protection requirements.

     

    ISO 27701 and GDPR compliance

    One of the most significant advantages of the ISO 27701 standard is the direct support it provides for compliance with the General Data Protection Regulation (GDPR). ISO 27701 provides a practical framework through which an organisation can assess, manage and mitigate the risks associated with the processing of personal data, translating legal requirements into concrete controls. ISO 27701 certification does not automatically equate to GDPR compliance, but it does provide strong evidence that the organisation has implemented appropriate technical and organisational measures – exactly what Article 32 of the GDPR requires.

     

    The benefits of ISO 27701 certification

    Certification of a confidential information management system brings tangible benefits:

    • provides confidence and a competitive advantage by protecting the personal information of customers and consumers;
    • demonstrates and supports efforts to comply with privacy laws and regulations, including the GDPR;
    • identifies and mitigates risks by implementing rigorous confidentiality controls;
    • demonstrates a genuine commitment to the continuous improvement of the privacy management system;
    • strengthens relationships with partners and customers who process or transfer personal data;
    • facilitates integration with other management systems, such as ISO 27001 (information security) or ISO 9001 (quality management).

     

    Is ISO 27701 certification compulsory?

    ISO 27701 certification is not, in itself, required by law. However, compliance with the GDPR is mandatory for any organisation that processes the personal data of individuals in the European Union, and ISO 27701 is one of the most effective tools an organisation can use to structure and demonstrate its compliance. Furthermore, ISO 27701 certification is increasingly sought after in contractual relationships, data processing chains and tenders, as evidence of responsible management of personal data.

     

    How do you obtain ISO 27701 certification?

    The ISO 27701 certification process with SRAC follows clear stages. Once the information security management system has been implemented, the organisation undergoes a conformity assessment by SRAC’s auditors.

     

    The stages and the certification audit

    1. Submission of the request for quotation and finalisation of the contractual details.
    2. The ISO 27701 certification audit comprises the following stages:
      1. review of the management system documentation (including the Statement of Applicability).
      2. Stage 1, in which the specific conditions at the client’s site are assessed; analysis of the stage of implementation of the applicant’s management system and their understanding of the standard’s requirements; assessment of the level of implementation of the PIMS, etc.
      3. Stage 2, in which a practical check is carried out within the company to verify whether the written procedures are actually applied in day-to-day operations.
    3. Addressing any non-conformities and implementing corrective actions.
    4. Issuance of the ISO 27701 certificate, valid for 3 years, subject to annual surveillance audits being carried out.
    5. The recertification audit (certification renewal), to extend the validity of the certificate for a further three-year period.

     

    The cost of ISO 27701 certification

    The cost of ISO 27701 certification is not fixed, but depends on the size of the organisation, the number of employees, the volume and complexity of data processing operations, the number of sites and the scope of the system. To find out the exact cost of ISO 27701 certification, the best option is to request a personalised quote.

     

    Validity and renewal of the certificate

    The ISO 27001 certificate is valid for three years, provided that certification is maintained by successfully passing annual surveillance audits. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.

     

    The transition to ISO/IEC 27701:2025

    Organisations certified to the ISO/IEC 27701:2019 standard have a three-year transition period (until October 2028) to migrate to the new ISO/IEC 27701:2025 standard. The transition can be incorporated into the next surveillance or recertification audit to minimise costs and effort. Organisations seeking certification for the first time may do so directly under the new edition.

    Find out from the attached article HERE what the main changes are compared with the previous edition of the standard.

    Author: Dr Cristian Roncea, Eng., Technical Director, SRAC CERT

     

    Why SRAC – IQNET international recognition

    SRAC enjoys international recognition through its partnership with IQNET (The International Certification Network). Certified organisations receive, at no additional cost, both the SRAC certificate and the IQNET certificate, which ensures genuine recognition of ISO 27701 certification both on the domestic market and internationally.

    Join the leading companies and institutions in Romania that have chosen the SRAC brand: over 10,000 certified organisations, with more than 25,000 certificates awarded over the past 30 years. From top brands to major public institutions, leading companies have chosen our services.

    Choose the leader in certification – Get certified with SRAC!

    Portofoliu clienți

     

    The principles and roles set out in ISO 27701

    Like ISO 27001, the ISO 27701 standard is based on a risk-based approach, but tailored to personal data. The standard makes a clear distinction between the two main roles in data processing: the data controller, who determines the purposes and means of processing, and the data processor, who processes the data on behalf of the controller. For each role, ISO 27701 sets out specific controls and responsibilities, so that the organisation can demonstrate that it handles personal identifiable information responsibly, regardless of its position in the processing chain.

     

    The requirements of the ISO 27701 standard

    The requirements of ISO 27701 cover both the elements of a management system (organisational context, leadership, planning, performance evaluation and continuous improvement) and specific confidentiality controls. These include identifying the legal bases for processing, managing consent, ensuring the rights of data subjects, keeping records of processing activities and managing relationships with data processors. In the ISO/IEC 27701:2025 edition, the controls are organised in a dedicated annex, structured according to the roles of controller and processor, and aligned with ISO/IEC 27001:2022 and ISO/IEC 27002:2022.

     

    Frequently Asked Questions (FAQ)

    What is ISO 27701 and what is it used for?

    ISO 27701 is the international standard for privacy information management (PIMS). It is used to structure the way in which an organisation protects personally identifiable information and to demonstrate, through certification, compliance with privacy requirements, including the GDPR.

     

    What is the difference between ISO 27001 and ISO 27701?

    ISO 27001 covers information security in general (the information security management system), whilst ISO 27701 focuses on the protection of personal data (the privacy information management system). ISO 27701 began as an extension of ISO 27001, and from the 2025 edition onwards it can also be implemented as a stand-alone standard.

     

    Is ISO 27001 still required in order to obtain ISO 27701?

    In the 2019 edition, ISO 27701 could only be certified by organisations that already held ISO 27001. From the ISO/IEC 27701:2025 edition onwards, the standard has become a stand-alone standard, meaning it can be implemented and certified independently, without the prior requirement to hold ISO 27001 certification.

     

    How does ISO 27701 help ensure compliance with the GDPR?

    ISO 27701 translates confidentiality requirements into specific controls and provides a framework for assessing and mitigating risks associated with the processing of personal information. Certification does not automatically equate to GDPR compliance, but it does provide strong evidence of the appropriate technical and organisational measures required by the Regulation.

     

    How much does ISO 27701 certification cost?

    The cost of ISO 27701 certification varies depending on the size of the organisation, the volume of data processing operations, the number of sites and the scope of the system. For an exact price, we recommend that you request a personalised quote.

     

    How long is the ISO 27701 certificate valid for?

    The ISO 27701 certificate is valid for 3 years, provided that certification is maintained by successfully passing annual surveillance audits. At the end of this period, if the organisation wishes to extend the validity of the certificate, a recertification audit (certification renewal) is carried out.

     

    What has changed in ISO/IEC 27701:2025?

    The most significant change is that ISO/IEC 27701:2025 has become a stand-alone management standard, rather than merely an extension of ISO 27001. It adopts the high-level structure (clauses 4–10), aligns with ISO/IEC 27001:2022 and ISO/IEC 27002:2022, and includes updated controls. Organisations certified to the 2019 edition have until October 2028 to transition to the 2025 version.

     

    Who is ISO 27701 certification aimed at?

    The certification is aimed at any organisation that collects or processes personal data, whether as a data controller or a data processor, regardless of its size or sector of activity.

     

    What do I need to do to get started?

    The first step is to submit a request for a quote to SRAC. You will receive a personalised quote and the details you need to begin the ISO 27701 certification process.