RateNow certified in ISO 27001: Compliance and assurance in protecting your customers' data
Protection of your customers' and patients' data. Here's what's behind the certification.
ISO 27001 is the international standard that certifies that an organisation manages information security in a systematic and audited way — not in an improvised manner. There is a real difference between being "aligned" with the standard and being certified: only certification involves an independent external audit, with a three-year validity and annual reviews. RateNow has an Information Security Management System implemented in accordance with ISO 27001 requirements, and publicly declares its certifications in ISO 9001 and ISO 27001.
Diana Bardales, 2026
6 min
In a context where every interaction with a customer or patient generates data — satisfaction surveys, ratings, comments, contact information — ensuring that this information is protected is no longer optional. ISO 27001 is the international reference standard for demonstrating this, and a growing number of companies require it from their suppliers as a condition for working together. In this article we explain exactly what the standard is, what an auditor — or a client reviewing a supplier — evaluates, and what the difference is between being "aligned" with ISO 27001 and being genuinely certified.
What is ISO 27001?
ISO/IEC 27001 is an international standard published jointly by ISO and the International Electrotechnical Commission (IEC) that specifies the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS) within an organisation.
Its objective is to guarantee three properties of information at all times:
- Confidentiality: that only authorised parties can access it.
- Integrity: that data is accurate and cannot be altered without control.
- Availability: that information is accessible when needed.
The current version is ISO/IEC 27001:2022, which updated the previous 2013 version and reduced the number of Annex A controls from 114 to 93, reorganising them into four categories: organisational, people, physical and technological.
Certification vs. alignment: the difference that matters
Many companies claim to be "aligned with ISO 27001", but that is not the same as being certified.
- Alignment: means that internal processes follow the principles of the standard, but no formal external verification has taken place.
- Certification: means that an accredited certification body has independently audited the ISMS and confirmed that it strictly meets the requirements. It has a three-year validity, with annual follow-up audits and a recertification process at the end of that period.
The real scope of certification
There is a fundamental aspect to bear in mind: some companies only certify a limited part of their business or a specific product, leaving other critical processes outside the scope.
RateNow, by contrast, certifies its entire operational flow in a comprehensive way. The RateNow certification explicitly covers:
- Survey creation
- Survey distribution channels
- Data analysis services
Always request the current certificate
When a company is about to entrust sensitive data to a supplier, the reasonable approach is to request the current certificate directly: who issues it, what scope it covers and its expiry date. A declared "alignment" does not offer the same verifiable guarantee.
Why certification is also a business decision
Beyond regulatory compliance, ISO 27001 certification has a direct and measurable impact on how a company sells and builds relationships with its customers:
| Reason | Why it matters |
|---|---|
| Purchasing requirement | A growing number of companies — especially in healthcare, banking and the public sector — require certification from their suppliers as a contractual condition |
| Customer trust | It demonstrates to clients, partners and regulators that security is managed with discipline, not improvised |
| Risk reduction | A certified ISMS reduces the likelihood and impact of security incidents compared to organisations without a formal system |
| Faster sales cycles | It eliminates security as an objection during procurement processes, especially for large or regulated accounts |
"73% of certified companies consider the cost of obtaining ISO 27001 to be fully justified by its benefits.
Source: Secureframe, "Why is ISO 27001 important?"
Source: Secureframe, "Why is ISO 27001 important?"
RateNow, as a technology company dedicated to the continuous measurement of customer and patient experience, handles sensitive information every day: ratings, comments and contact data collected in hospitals, health centres, retail environments and other regulated settings.
That is why RateNow has an Information Security Management System implemented in accordance with ISO 27001 requirements, with processes designed to ensure the confidentiality, integrity and availability of data at all times, following the standards commonly applied in the banking and healthcare sectors. RateNow publicly declares its certification in ISO 9001 and ISO 27001.
For a company working with patient and customer data in regulated sectors, ISO 27001 is not just another certificate on the wall: it is evidence that a real system exists behind every piece of data that is collected, stored and analysed.
You can openly consult RateNow's formal commitment and security guidelines in the Security Policy, and if you would like to know more, our team is available to answer your questions.
Bibliography
1. ISO — "ISO/IEC 27001:2022, Information security management systems", International Organisation for Standardisation. https://www.iso.org/es/norma/27001
2. TÜV SÜD — "New version of ISO/IEC 27001": changes to Annex A, from 114 to 93 controls in four categories.
3. Secureframe — "Why is ISO 27001 important?": survey on the cost and perceived benefits for certified companies.
Tell us about your project and get:
ⓘ No commitment
Related Articles:
Customer Experience
How to calculate NPS®: The ultimate guide on Net Promoter Score® (2026)
Read more
Go to blog
Contact us!
Enter your name and surname.
Enter your business email address.
Enter a valid business email format.
Personal emails such as @gmail.com or @hotmail.com are not allowed.
Enter a phone number.
The phone number format is not valid.
By submitting the following form you accept our Privacy policy, and you consent to your data being processed by LEAN LEMON S.L. (RateNow)
I give my consent to receive communications about news, products and services from RateNow.Start improving your Customer Experience right now!
We'll contact you in less than 24h
Leave your contact, call us or write to us directly at:
Sales support: +44 7488 864121 / sales@ratenow.cx
Sales support: +44 7488 864121 / sales@ratenow.cx
You're in good company...






We’re passionate about instant feedback
Your CX expert will contact you as soon as possible.
Your CX expert will contact you as soon as possible.
Keep browsing
×
×





