<h2 id="p2porgs-security-compliance-certifications">P2P.org's Security Compliance Certifications</h2><p><br>P2P.org is now certified to <a href="https://www.bsigroup.com/en-AE/products-and-services/standards/iso-iec-27001-information-security-management-system/?ref=p2p.org">ISO/IEC 27001:2022</a>, the international standard for information security management systems. The certification, audited and issued by the <a href="https://www.bsigroup.com/en-US/?ref=p2p.org">BSI Group</a> (certificate IS 845360), covers information security, customer support, business development, finance, human resources, legal, product management, engineering, operations, data management, lab, and validation functions across operations at P2P.org's Cayman-registered parent entity (P2P Staking - ISMS CF) and its Limassol, Cyprus location. It is valid through 3 August 2029, subject to annual surveillance audits.</p><p>This latest certification adds to a growing set of independently verified security and compliance credentials at <a href="http://p2p.org/?ref=p2p.org">P2P.org</a>, including its existing <a href="https://p2p.org/economy/p2p-org-achieves-soc-2-type-ii-certification/">SOC 2 Type II attestation,</a> <a href="https://www.linkedin.com/posts/blockchain-security-standards-council_blockchainsecurity-cybersecurity-blockchain-activity-7490785453969833984-wARU?utm_source=social_share_send&utm_medium=member_desktop_web&rcm=ACoAAACZFM4BKAvTYfki7_XDYioeT_mkicu9mbQ">membership in the Blockchain Security Standards Council</a> (BSSC), and its work with <a href="https://p2p.org/economy/p2p-org-sumsub-risk-intolerant-sentinel-compliance/">SumSub Sentinel</a> on transaction monitoring and compliance screening.</p><h2 id="key-takeaways">Key Takeaways<br></h2><p>⟡ Institutions evaluating staking and digital asset infrastructure providers can use this combination of credentials- SOC 2 Type II, ISO/IEC 27001:2022, BSSC membership, and SumSub Sentinel- to reduce the diligence burden typically required before deploying capital with a new validator operator.</p><p>⟡ ISO/IEC 27001:2022 requires ongoing surveillance audits to remain valid, so the certification reflects a sustained security discipline rather than a point-in-time assessment.</p><p>⟡ The certification's scope reaches beyond technical infrastructure into the operational functions that shape the day-to-day client relationship, which is often the layer institutions scrutinize most in vendor risk reviews.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">🗣️</div><div class="kg-callout-text">"ISO 27001 certification is an important milestone for us, but what matters more is what sits behind it: how we identify risk, how we respond when things go wrong, and how we keep improving. For our institutional clients, this provides independent assurance that security at P2P.org is not a point-in-time exercise, but a discipline embedded in how we operate."<br><br><b><strong style="white-space: pre-wrap;">- Sheetal Joseph, Chief Information Security Officer, P2P.org</strong></b></div></div><h2 id="what-isoiec-270012022-certification-means-for-p2porg">What ISO/IEC 27001:2022 Certification Means for P2P.org</h2><p>ISO/IEC 27001:2022 requires organizations to build, document, and continuously improve a formal information security management system, verified through an independent audit and ongoing surveillance reviews. For institutions evaluating staking and digital asset infrastructure providers, the certification offers evidence of operational maturity that is otherwise difficult to verify externally, covering incident response, access controls, and security governance to the standard expected of regulated financial infrastructure.</p><p>An ISMS, or Information Security Management System, is the formal framework an organization uses to manage information security risk: the policies, controls, and processes that govern how data and systems are protected, monitored, and improved over time. ISO/IEC 27001:2022 is the internationally recognized standard for building and certifying one.</p><h2 id="what-the-isoiec-270012022-certification-scope-covers">What the ISO/IEC 27001:2022 Certification Scope Covers</h2><p>The certification's scope spans the operational functions that touch client relationships directly, including customer support, business development, product management, and engineering, alongside the technical infrastructure functions of data management, lab, and validation. It applies company-wide at P2P.org, reflecting controls maintained consistently across its global footprint.</p><h2 id="how-isoiec-270012022-complements-soc-2-type-ii">How ISO/IEC 27001:2022 Complements SOC 2 Type II</h2><p>ISO/IEC 27001:2022 certification sits alongside P2P.org's existing SOC 2 Type II attestation. Where SOC 2 Type II evaluates the operating effectiveness of security controls over a sustained period, ISO/IEC 27001:2022 verifies the management system that governs those controls. Institutions increasingly request both frameworks as part of vendor risk assessments, and holding both reduces the burden on institutional compliance teams conducting that review.</p><p>P2P.org operates non-custodial staking infrastructure across 35+ proof-of-stake networks, and client assets always remain under institutional control.</p><h2 id="frequently-asked-questions-faq">Frequently Asked Questions (FAQ)</h2><h3 id="what-is-isoiec-270012022"><br>What is ISO/IEC 27001:2022?</h3><p>ISO/IEC 27001:2022 is the current version of the international standard for information security management systems, jointly developed by the International Organization for Standardization and the International Electrotechnical Commission. It requires organizations to build and continuously improve a formal information security management system and to pass an independent audit confirming compliance.</p><h3 id="what-does-p2porgs-isoiec-270012022-certification-cover">What does P2P.org's ISO/IEC 27001:2022 certification cover?</h3><p>The certification covers information security, customer support, business development, finance, human resources, legal, product management, engineering, operations, data management, lab, and validation functions, spanning P2P.org's blockchain token staking and white-label blockchain node operations across its Cayman Islands and Cyprus entities.</p><h3 id="how-is-isoiec-270012022-different-from-soc-2-type-ii">How is ISO/IEC 27001:2022 different from SOC 2 Type II?</h3><p>SOC 2 Type II evaluates whether an organization's security controls operated effectively over a sustained review period. ISO/IEC 27001:2022 certifies the management system that governs those controls on an ongoing basis and is verified through periodic surveillance audits. Institutions often request both as part of vendor risk assessments.</p><h3 id="how-long-is-p2porgs-isoiec-270012022-certification-valid">How long is P2P.org's ISO/IEC 27001:2022 certification valid?</h3><p>The certification is valid through August 2029, subject to ongoing surveillance audits conducted by BSI to confirm the information security management system continues to meet the standard.</p><h3 id="does-this-certification-affect-how-p2porg-handles-client-assets">Does this certification affect how P2P.org handles client assets?</h3><p>No. P2P.org operates non-custodial staking infrastructure, meaning client assets remain under the client's own control throughout. ISO/IEC 27001:2022 certification applies to the way P2P.org manages information security across its operations and systems.</p><hr><p><strong>About P2P.org</strong></p><p>Founded in 2018, P2P.org helps institutional capital protect digital asset yield across non-custodial staking infrastructure and curated DeFi strategies. With over $10B in assets secured and operating on 35+ proof-of-stake networks, P2P.org maintains a zero-slashing-incident track record, is trusted by over 190 institutional clients and is SOC 2 Type II attested and ISO/IEC 27001:2022 certified. To explore how P2P.org can support your institution's staking or DeFi infrastructure needs, <a href="https://p2p.org/contact?ref=p2p.org">get in touch with our team</a>.</p><hr><p><strong>Disclaimer</strong></p><p>This material is provided for informational purposes only and does not constitute investment, financial, legal, or tax advice. <a href="http://p2p.org/?ref=p2p.org">P2P.org</a> accepts no liability for any actions taken based on it. Latency and performance figures referenced are estimates based on internal benchmarks and may vary depending on network conditions, geography, and client infrastructure. Past performance is not indicative of future results.</p>
from p2p validator