ISO/IEC 27001:2022, ISO 27001, certifications, security, compliance P2P.org Achieves ISO/IEC 27001:2022 Certification

<h2 id="p2porgs-security-compliance-certifications">P2P.org's Security Compliance Certifications</h2><p><br>P2P.org is now certified to <a href="https://www.bsigroup.com/en-AE/products-and-services/standards/iso-iec-27001-information-security-management-system/?ref=p2p.org">ISO/IEC 27001:2022</a>, the international standard for information security management systems. The certification, audited and issued by the <a href="https://www.bsigroup.com/en-US/?ref=p2p.org">BSI Group</a> (certificate IS 845360), covers information security, customer support, business development, finance, human resources, legal, product management, engineering, operations, data management, lab, and validation functions across operations at P2P.org's Cayman-registered parent entity (P2P Staking - ISMS CF) and its Limassol, Cyprus location. It is valid through 3 August 2029, subject to annual surveillance audits.</p><p>This latest certification adds to a growing set of independently verified security and compliance credentials at <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>, including its existing <a href="https://p2p.org/economy/p2p-org-achieves-soc-2-type-ii-certification/">SOC 2 Type II attestation,</a> <a href="https://www.linkedin.com/posts/blockchain-security-standards-council_blockchainsecurity-cybersecurity-blockchain-activity-7490785453969833984-wARU?utm_source=social_share_send&utm_medium=member_desktop_web&rcm=ACoAAACZFM4BKAvTYfki7_XDYioeT_mkicu9mbQ">membership in the Blockchain Security Standards Council</a> (BSSC), and its work with <a href="https://p2p.org/economy/p2p-org-sumsub-risk-intolerant-sentinel-compliance/">SumSub Sentinel</a> on transaction monitoring and compliance screening.</p><h2 id="key-takeaways">Key Takeaways<br></h2><p>⟡ Institutions evaluating staking and digital asset infrastructure providers can use this combination of credentials- SOC 2 Type II, ISO/IEC 27001:2022, BSSC membership, and SumSub Sentinel- to reduce the diligence burden typically required before deploying capital with a new validator operator.</p><p>⟡ ISO/IEC 27001:2022 requires ongoing surveillance audits to remain valid, so the certification reflects a sustained security discipline rather than a point-in-time assessment.</p><p>⟡ The certification's scope reaches beyond technical infrastructure into the operational functions that shape the day-to-day client relationship, which is often the layer institutions scrutinize most in vendor risk reviews.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">🗣️</div><div class="kg-callout-text">"ISO 27001 certification is an important milestone for us, but what matters more is what sits behind it: how we identify risk, how we respond when things go wrong, and how we keep improving. For our institutional clients, this provides independent assurance that security at P2P.org is not a point-in-time exercise, but a discipline embedded in how we operate."<br><br><b><strong style="white-space: pre-wrap;">- Sheetal Joseph, Chief Information Security Officer, P2P.org</strong></b></div></div><h2 id="what-isoiec-270012022-certification-means-for-p2porg">What ISO/IEC 27001:2022 Certification Means for P2P.org</h2><p>ISO/IEC 27001:2022 requires organizations to build, document, and continuously improve a formal information security management system, verified through an independent audit and ongoing surveillance reviews. For institutions evaluating staking and digital asset infrastructure providers, the certification offers evidence of operational maturity that is otherwise difficult to verify externally, covering incident response, access controls, and security governance to the standard expected of regulated financial infrastructure.</p><p>An ISMS, or Information Security Management System, is the formal framework an organization uses to manage information security risk: the policies, controls, and processes that govern how data and systems are protected, monitored, and improved over time. ISO/IEC 27001:2022 is the internationally recognized standard for building and certifying one.</p><h2 id="what-the-isoiec-270012022-certification-scope-covers">What the ISO/IEC 27001:2022 Certification Scope Covers</h2><p>The certification's scope spans the operational functions that touch client relationships directly, including customer support, business development, product management, and engineering, alongside the technical infrastructure functions of data management, lab, and validation. It applies company-wide at P2P.org, reflecting controls maintained consistently across its global footprint.</p><h2 id="how-isoiec-270012022-complements-soc-2-type-ii">How ISO/IEC 27001:2022 Complements SOC 2 Type II</h2><p>ISO/IEC 27001:2022 certification sits alongside P2P.org's existing SOC 2 Type II attestation. Where SOC 2 Type II evaluates the operating effectiveness of security controls over a sustained period, ISO/IEC 27001:2022 verifies the management system that governs those controls. Institutions increasingly request both frameworks as part of vendor risk assessments, and holding both reduces the burden on institutional compliance teams conducting that review.</p><p>P2P.org operates non-custodial staking infrastructure across 35+ proof-of-stake networks, and client assets always remain under institutional control.</p><h2 id="frequently-asked-questions-faq">Frequently Asked Questions (FAQ)</h2><h3 id="what-is-isoiec-270012022"><br>What is ISO/IEC 27001:2022?</h3><p>ISO/IEC 27001:2022 is the current version of the international standard for information security management systems, jointly developed by the International Organization for Standardization and the International Electrotechnical Commission. It requires organizations to build and continuously improve a formal information security management system and to pass an independent audit confirming compliance.</p><h3 id="what-does-p2porgs-isoiec-270012022-certification-cover">What does P2P.org's ISO/IEC 27001:2022 certification cover?</h3><p>The certification covers information security, customer support, business development, finance, human resources, legal, product management, engineering, operations, data management, lab, and validation functions, spanning P2P.org's blockchain token staking and white-label blockchain node operations across its Cayman Islands and Cyprus entities.</p><h3 id="how-is-isoiec-270012022-different-from-soc-2-type-ii">How is ISO/IEC 27001:2022 different from SOC 2 Type II?</h3><p>SOC 2 Type II evaluates whether an organization's security controls operated effectively over a sustained review period. ISO/IEC 27001:2022 certifies the management system that governs those controls on an ongoing basis and is verified through periodic surveillance audits. Institutions often request both as part of vendor risk assessments.</p><h3 id="how-long-is-p2porgs-isoiec-270012022-certification-valid">How long is P2P.org's ISO/IEC 27001:2022 certification valid?</h3><p>The certification is valid through August 2029, subject to ongoing surveillance audits conducted by BSI to confirm the information security management system continues to meet the standard.</p><h3 id="does-this-certification-affect-how-p2porg-handles-client-assets">Does this certification affect how P2P.org handles client assets?</h3><p>No. P2P.org operates non-custodial staking infrastructure, meaning client assets remain under the client's own control throughout. ISO/IEC 27001:2022 certification applies to the way P2P.org manages information security across its operations and systems.</p><hr><p><strong>About P2P.org</strong></p><p>Founded in 2018, P2P.org helps institutional capital protect digital asset yield across non-custodial staking infrastructure and curated DeFi strategies. With over $10B in assets secured and operating on 35+ proof-of-stake networks, P2P.org maintains a zero-slashing-incident track record, is trusted by over 190 institutional clients and is SOC 2 Type II attested and ISO/IEC 27001:2022 certified. To explore how P2P.org can support your institution's staking or DeFi infrastructure needs, <a href="https://p2p.org/contact?ref=p2p.org">get in touch with our team</a>.</p><hr><p><strong>Disclaimer</strong></p><p>This material is provided for informational purposes only and does not constitute investment, financial, legal, or tax advice. <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> accepts no liability for any actions taken based on it. Latency and performance figures referenced are estimates based on internal benchmarks and may vary depending on network conditions, geography, and client infrastructure. Past performance is not indicative of future results.</p>

Fito Benitez

from p2p validator

compliance, certifications P2P.org Earns Sumsub Risk Intolerant Sentinel Recognition: What It Means for Our Partners

<p>P2P Certified | Compliance</p><h2 id="introduction">Introduction</h2><p>Compliance claims are easy to make. In an industry where regulatory expectations are rising faster than most firms realise, the difference between a compliance page and genuine compliance practice is measured not in words but in independent validation.</p><p>At <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>, we have built our customer due diligence (CDD) framework as a living system, one designed for where regulation is heading rather than where it has been. That commitment recently received external recognition from Sumsub in the form of their Risk Intolerant Sentinel designation, a badge awarded to organisations that demonstrate proactive, comprehensive standards across KYC, AML monitoring, fraud prevention and identity verification.</p><p>This post explains what that recognition means, how it was earned, and what it signals to the institutions and regulated businesses that partner with P2P.org.</p><h2 id="key-learnings-for-busy-readers">Key learnings for busy readers</h2><p>If you are short on time, here is what this article covers:</p><p>P2P.org has been awarded the <a href="https://sumsub.com/risk-intolerant/?ref=p2p.org" rel="noreferrer">Sumsub Risk Intolerant Sentinel</a> designation, an independent recognition awarded by a globally trusted compliance and identity verification platform operating across 220+ countries. The designation is not self-reported. It is the result of a third-party assessment of P2P.org's use of Sumsub's verification and monitoring infrastructure across our compliance operations. For institutional partners and regulated businesses, this is a concrete, externally verified signal of the compliance standards they are dealing with when they work with <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>. Our CDD framework was reviewed against current AMLR expectations as a deliberate investment in partnership quality, not as a reactive compliance exercise.</p><h2 id="independent-recognition-in-an-industry-where-it-matters-most">Independent recognition in an industry where it matters most</h2><p>Recognition of compliance standards is only meaningful when it comes from outside the organisation. Anyone can write a compliance page. Third-party validation from a globally recognised authority is a different kind of signal.</p><p><a href="https://sumsub.com/about/?ref=p2p.org" rel="noreferrer">Sumsub</a> is a global compliance and identity verification platform trusted by thousands of regulated businesses across fintech, crypto, traditional financial institutions and digital asset businesses worldwide. Their infrastructure spans KYC, KYB, AML monitoring, transaction screening and fraud prevention across more than 220 countries and territories.</p><p>The Risk Intolerant initiative was created specifically to address what Sumsub describes as a gap in the industry: compliance work is largely invisible until something goes wrong. The project shifts that dynamic by publicly recognising organisations that manage risk proactively, turning otherwise unseen compliance efforts into verifiable, public proof.</p><p>The Sentinel designation is awarded following Sumsub's assessment of a company's KYC, AML, fraud prevention and compliance systems. It goes to organisations whose risk mitigation practices are comprehensive, current and effective. Importantly, it is not a self-reported badge. It requires assessment against Sumsub's global client base and the standards they apply across their entire platform.</p><p><a href="http://p2p.org/?ref=p2p.org">P2P.org</a> has received this designation based on our use of Sumsub's verification and monitoring infrastructure across our compliance operations. For our partners, it means one thing practically: your counterpart at <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> has been independently evaluated by a recognised global compliance authority.</p><p>You can read more about the Risk Intolerant initiative directly at <a href="https://sumsub.com/risk-intolerant/?ref=p2p.org">sumsub.com/risk-intolerant</a>.</p><h2 id="the-thinking-behind-our-compliance-approach">The thinking behind our compliance approach</h2><p>Compliance is not a static checklist at <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>. It is a framework we treat as an ongoing investment in the quality of our partnerships.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://p2p.org/economy/content/images/2026/04/-p2p-org-sumsub-compliance-validation-flow.png" class="kg-image" alt="Diagram showing how P2P.org compliance operations connect through Sumsub's verification platform to the Risk Intolerant Sentinel designation, resulting in independently verified partner trust for institutions and regulated businesses." loading="lazy" width="1600" height="900" srcset="https://p2p.org/economy/content/images/size/w600/2026/04/-p2p-org-sumsub-compliance-validation-flow.png 600w, https://p2p.org/economy/content/images/size/w1000/2026/04/-p2p-org-sumsub-compliance-validation-flow.png 1000w, https://p2p.org/economy/content/images/2026/04/-p2p-org-sumsub-compliance-validation-flow.png 1600w" sizes="(min-width: 720px) 720px"><figcaption><i><em class="italic" style="white-space: pre-wrap;">How </em></i><span style="white-space: pre-wrap;">P2P.org</span><i><em class="italic" style="white-space: pre-wrap;">'s CDD framework and Sumsub's global platform combine to produce independent compliance validation.</em></i></figcaption></figure><p>As the <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> Compliance team put it:</p><blockquote>"Compliance in this industry is moving faster than most firms realise. We made the decision early on to treat our CDD framework as a living system, one that needs to be built for where regulation is going, not where it has been. The AMLR review was not a defensive move. It was a deliberate investment in the quality of the partnerships we want to maintain."</blockquote><p>The EU Anti-Money Laundering Regulation (AMLR) is reshaping expectations for regulated and high-risk sectors across financial services, crypto and digital assets. Rather than waiting to react, <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> reviewed and aligned our CDD processes against AMLR requirements as a deliberate, proactive step.</p><p>The diagram above illustrates how our internal compliance operations connect through Sumsub's platform infrastructure to the independent assessment process, culminating in the Sentinel designation that now represents verified partner trust for the institutions and funds working with us.</p><h2 id="what-the-sentinel-designation-means-in-practice">What the Sentinel designation means in practice</h2><p>The Risk Intolerant project structures recognition across tiers based on assessment results. The Sentinel designation reflects a proactive, best-in-class approach to fraud prevention, AML screening, identity verification and customer onboarding. It is not awarded by request alone. It follows Sumsub's evaluation of how a company's systems are designed, operated and updated.</p><p>For institutions evaluating staking infrastructure providers or digital asset service partners, compliance validation from a recognised global platform provides a layer of due diligence assurance that internal claims cannot offer. When P2P.org's compliance standards are assessed by the same platform that serves thousands of regulated businesses globally, the result carries a weight that self-certification does not.</p><p>This is particularly relevant given the direction regulatory frameworks are moving. FATF's 2025 guidance and the EU's broader AML package are pushing regulated industries toward a unified, risk-based approach where continuous monitoring and adaptive controls are the expectation, not the exception. P2P.org's investment in a living CDD framework, validated independently through Sumsub, places us ahead of that curve rather than behind it.</p><h2 id="why-independent-validation-matters-for-institutional-partners">Why independent validation matters for institutional partners</h2><p>Institutions choosing infrastructure partners in the staking and digital asset space carry compliance obligations of their own. They are not just choosing a technology provider. They are choosing a counterparty whose compliance posture either supports or complicates their own regulatory standing.</p><p>A self-reported compliance page provides limited assurance. What institutions need is a signal they can actually rely on: an assessment conducted by a third party with the global reach and technical authority to evaluate compliance infrastructure objectively.</p><p>The Sumsub Risk Intolerant Sentinel designation provides exactly that. It is a third-party determination, applied consistently across a global client base, that P2P.org's approach to risk management meets the standard Sumsub sets for comprehensive, proactive compliance.</p><p>When you partner with <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> for staking infrastructure across our 40+ supported networks, you are working with a business that has been independently evaluated, not just one that has declared its own compliance. That distinction matters increasingly in the regulatory environment we are all operating in.</p><h2 id="p2porg-compliance-as-part-of-a-broader-standard">P2P.org compliance as part of a broader standard</h2><p>The Sumsub recognition sits alongside P2P.org's existing compliance achievements. We achieved SOC 2 Type II certification in 2025, confirming that our security and operational frameworks meet the standards institutional clients require. Our infrastructure supports more than $10 billion in assets under management across 40+ blockchain networks, with a zero-slashing incident record and 99.9% uptime across all validator infrastructure.</p><p>Compliance and operational excellence are not separate tracks at P2P.org. They are part of the same commitment to being a partner that regulated institutions can rely on.</p><p>If you would like to explore our institutional staking products and understand how our compliance framework supports the businesses we work with, visit <a href="https://www.p2p.org/products/staking-as-a-business?ref=p2p.org">P2P.org Staking-as-a-Business</a>.</p><p>For more compliance coverage and updates from the P2P Certified series, explore the <a href="https://www.p2p.org/economy/?ref=p2p.org">P2P.org blog</a>.</p><h2 id="key-takeaways">Key takeaways</h2><p>P2P.org has received the Sumsub Risk Intolerant Sentinel designation following an independent third-party assessment of our compliance and verification infrastructure. The designation reflects a proactive, comprehensive approach to KYC, AML, fraud prevention and CDD, aligned with where regulation is heading under AMLR and broader global AML frameworks. For institutional partners and regulated businesses, this is a verifiable external signal of the compliance standards P2P.org operates to, not a self-declared claim. Our CDD framework is built as a living system, designed to evolve ahead of regulatory expectations rather than react to them.</p><h2 id="frequently-asked-questions-faqs">Frequently Asked Questions (FAQs)</h2><h3 id="what-is-the-sumsub-risk-intolerant-sentinel-designation"><br><strong>What is the Sumsub Risk Intolerant Sentinel designation?</strong> </h3><p>The Risk Intolerant Sentinel is a recognition awarded by Sumsub as part of their Risk Intolerant initiative, which publicly identifies companies that demonstrate comprehensive, proactive standards in KYC, AML, fraud prevention and identity verification. It is based on a third-party assessment of a company's compliance systems, not a self-reported application.</p><h3 id="is-this-the-highest-designation-in-the-risk-intolerant-programme"><strong>Is this the highest designation in the Risk Intolerant programme?</strong> </h3><p>The Risk Intolerant project has three tiers: Vanguard, Sentinel and Titan. The Sentinel designation is awarded to companies that demonstrate a proactive, best-in-class approach to compliance and fraud prevention, going beyond baseline requirements.</p><h3 id="what-is-sumsub-and-why-does-its-recognition-matter"><strong>What is Sumsub, and why does its recognition matter?</strong> </h3><p>Sumsub is a global compliance and identity verification platform operating in 220+ countries, trusted by thousands of regulated businesses, including traditional financial institutions, fintech companies and digital asset businesses. Their assessment reflects global compliance benchmarks, which is why their recognition carries weight beyond the digital asset sector.</p><h3 id="what-is-the-amlr-and-why-did-p2porg-review-its-cdd-framework-against-it"><strong>What is the AMLR, and why did P2P.org review its CDD framework against it?</strong> </h3><p>The EU Anti-Money Laundering Regulation (AMLR) is reshaping compliance expectations across financial services and digital assets. P2P.org reviewed and aligned our CDD framework against AMLR as a proactive investment in compliance quality and partnership standards, not as a reactive measure to regulatory pressure.</p><h3 id="does-p2porg-hold-any-other-compliance-certifications"><strong>Does P2P.org hold any other compliance certifications?</strong> </h3><p>Yes. P2P.org achieved SOC 2 Type II certification in 2025, confirming that our security and operational control frameworks meet institutional standards. The Sumsub Sentinel designation adds an independent layer of compliance-specific validation to that foundation.</p><h3 id="how-does-this-affect-institutional-partners-working-with-p2porg"><strong>How does this affect institutional partners working with P2P.org?</strong> </h3><p>Institutional partners carry their own compliance obligations when selecting counterparties. The Sumsub Sentinel designation gives them an independently verified signal of P2P.org's compliance standards, one assessed by a globally recognised authority rather than declared internally.</p>

Fito Benitez

from p2p validator