Blog - Wirtek

Wirtek strengthens EU compliance credentials with ISO/IEC 27001:2022 and ISO 9001:2015 certification

Written by Wirtek | 7 Aug 2026

Wirtek's Romanian operations have been certified to ISO/IEC 27001:2022 for information security management and ISO 9001:2015 for quality management. Both certificates were issued on 27 July 2026 by SYSTEMA Certificări, an IAS-accredited certification body, and remain valid until 26 July 2029. The certified scope covers Wirtek's full engineering offering, including custom software, IoT, embedded firmware, electronic equipment and testing, as well as its cybersecurity services: OT security, application security, penetration testing and security operations.

Why the scope matters

Most ISO certificates held by software companies cover software development and stop there. Wirtek's cover more.

The scope of both certificates spans custom software development, including enterprise software, mobile applications and IoT solutions, plus verification, validation and testing of software, software components embedded in electronic equipment (firmware), and electronic equipment itself. It also covers cybersecurity services: application security (AppSec), operational technology security (OT), governance, risk and compliance (GRC), penetration testing, identity and access management, device and network security, and security operations (SecOps).

That breadth reflects how Wirtek's clients actually buy. A company modernising an industrial control system or bringing a connected product to market rarely separates the software work from the security work, and increasingly cannot: the NIS2 Directive and the Cyber Resilience Act place obligations on operators and manufacturers that extend down into their supply chains. When a client's own compliance depends partly on its vendors, an independently audited management system stops being a nice-to-have and becomes a qualification requirement.

What ISO/IEC 27001:2022 covers

ISO/IEC 27001 is the international standard for information security management systems. Certification means an accredited third party has audited how an organisation identifies information security risks, selects and implements controls against them, and monitors and improves those controls over time. The 2022 revision restructured the control set around four themes and sharpened its focus on cybersecurity and privacy.

For clients, the practical effect is evidentiary. Instead of relying on a vendor's self-assessment or a questionnaire, they can point to an accredited certificate when documenting their own due diligence, whether under GDPR processor obligations, NIS2 supply chain requirements, or a customer's security review.

Wirtek's Statement of Applicability, the document recording which controls apply and why, is dated 11 May 2026.

What ISO 9001:2015 covers

ISO 9001 is the international standard for quality management systems. Wirtek has maintained ISO 9001 certification since 2006, and the new certificate continues that record under SYSTEMA while extending the certified scope to the company's current service portfolio.

The two standards share a common structure, which allowed both systems to be audited and certified together as one integrated management system rather than two parallel ones.

What happens next

Certification is not a one-off event. The certificates are subject to annual surveillance audits, scheduled for 26 July 2027 and 26 July 2028, with recertification before expiry on 26 July 2029. Wirtek is also assessing the value of extending its certified management systems to further standards as client and regulatory requirements evolve.

Certificate details

  ISO 9001:2015 ISO/IEC 27001:2022
Management system Quality Information security
Certified entity Wirtek SRL, Cluj-Napoca, Romania Wirtek SRL, Cluj-Napoca, Romania
Registration number C260462/01/EN I260462/01/EN
Issued 27 July 2026 27 July 2026
Valid until 26 July 2029 26 July 2029
Certification body SYSTEMA Certificări SRL SYSTEMA Certificări SRL
Accreditation IAS (MSCB-173), IAF MLA signatory IAS (MSCB-173), IAF MLA signatory