{"id":99025,"date":"2026-09-29T09:00:00","date_gmt":"2026-09-29T07:00:00","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=99025"},"modified":"2026-08-06T16:22:12","modified_gmt":"2026-08-06T14:22:12","slug":"security-certificates-it-service-providers","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/security-certificates-it-service-providers\/","title":{"rendered":"What security certificates should be requested from IT service providers?"},"content":{"rendered":"<h1 class=\"wp-block-heading\">What security certificates should be requested from IT service providers?<\/h1>\n\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li>Request evidence based on risk and service. More documents do not automatically mean better evidence.<\/li><li>Check the scope, organization, service, period, exceptions, and issuing or examining body for each piece of evidence.<\/li><li>ISO\/IEC 27001, SOC reports, and BSI C5 answer different questions and are not interchangeable without context.<\/li><li>Technical tests, policies, incident processes, and BCM evidence supplement formal evidence when they fit the risk.<\/li><li>Protect confidential reports and document any outstanding issues or customer controls.<\/li><\/ul>\n<h2 class=\"wp-block-heading\">Evidence must fit the decision.<\/h2>\n<p class=\"wp-block-paragraph\">Security evidence helps to verify statements made by an IT service provider. However, they differ significantly in subject matter, depth, and currency. A certificate evaluates a management system within a defined scope. An audit report may examine control design and effectiveness for a period. A pentest summary considers a technical review area.<\/p>\n<p class=\"wp-block-paragraph\">There is no universal mandatory catalog for every service. The selection follows performance, criticality, data access, and potential impact. This article helps with the requirement and evaluation of the evidence. It does not replace a legal or data protection review.<\/p>\n<h2 class=\"wp-block-heading\">Derive evidence from risk and performance.<\/h2>\n<p class=\"wp-block-paragraph\">Start with the specific service. What data does the provider process? Do they have administrative rights? Do they develop software, operate infrastructure, or provide a standardized cloud service? Which business processes would be affected in the event of failure? These questions determine what statement needs to be substantiated.<\/p>\n<p class=\"wp-block-paragraph\">Assign each requirement to a risk. For privileged support, relevant are access sharing, strong authentication, logging, and revocation of rights. In software development, the development process, dependency management, and handling of vulnerabilities are of interest. For a cloud service, tenant separation, encryption, availability, and control of subcontractors may be key.<\/p>\n<p class=\"wp-block-paragraph\">NIST SP 1326 describes due diligence as the research of available, relevant information about suppliers or products so that decisions can be made on a sufficient basis. The guide is tailored to ICT suppliers and mentions, among other things, resilience, basic cyber practices, and supply chain levels. It does not provide a universal German evidence catalog but supports risk-based construction.<\/p>\n<p class=\"wp-block-paragraph\">Define before the request which document, summary, or confirmation will be accepted. Some reports may only be viewed under a confidentiality agreement. In other cases, an appropriately detailed management summary may suffice. If evidence is not provided, the provider should be able to explain alternative evidence.<\/p>\n<h2 class=\"wp-block-heading\">ISO\/IEC 27001: Check certificate and scope.<\/h2>\n<p class=\"wp-block-paragraph\">ISO\/IEC 27001:2022 defines requirements for an information security management system. Certification shows that the ISMS was tested against the standard within the specified scope. It does not automatically confirm every technical individual control or every performance of the company.<\/p>\n<p class=\"wp-block-paragraph\">Check the name of the certified organization, locations, activities, validity period, and certification body. The scope description is crucial: Does it cover the service, operating environment, and the company with which you are contracting? A very general scope requires further inquiries. A certificate for the corporate headquarters may exclude a separately operated service of a subsidiary.<\/p>\n<p class=\"wp-block-paragraph\">For critical services, ask for the Statement of Applicability or an appropriate summary, as far as the provider can release it. This document shows which controls were selected or excluded in the ISMS and how exclusions are justified. The specific statement must be connected to the scope and the related service.<\/p>\n<p class=\"wp-block-paragraph\">Also consider currency and changes. A valid certificate may come from an audit that occurred before a major acquisition or product change. Clarify significant changes and open findings in a supplier discussion. Certification remains important evidence, but not an automatic approval.<\/p>\n<h2 class=\"wp-block-heading\">Use SOC reports and BSI C5 in the appropriate context.<\/h2>\n<p class=\"wp-block-paragraph\">SOC reports stem from the US auditing framework of the AICPA. SOC 1 addresses controls that are relevant for the internal financial reporting of the user organization. SOC 2 considers controls of a service organization in relation to security, availability, processing integrity, confidentiality, or privacy. Therefore, not every SOC report is equally suitable for a general security review.<\/p>\n<p class=\"wp-block-paragraph\">When reviewing SOC 2, check the system description, included Trust Services Criteria, period, audit result, exceptions, and Complementary User Entity Controls. These customer controls must be implemented by the using organization to achieve the considered control objectives. A report with a good result may lose its significance if the customer does not implement the assumed secure configuration.<\/p>\n<p class=\"wp-block-paragraph\">The Cloud Computing Compliance Criteria Catalogue C5 of the BSI is focused on the information security of cloud services. The BSI clarifies that a C5 certification is conducted by external auditors and is not a BSI certification. Therefore, check the report, audit subject, and usage instructions. A C5 report is particularly relevant when the cloud service in question is within scope.<\/p>\n<p class=\"wp-block-paragraph\">C5 distinguishes between Type 1 and Type 2 reporting. According to BSI, Type 1 assesses the description as well as design and implementation of controls at a single point in time. Type 2 additionally includes testing procedures for effectiveness over a period of time. BSI considers Type 2 necessary for adequate reliability; however, special circumstances may still justify a Type 1 report.<\/p>\n<figure class=\"wp-block-table\"><table><thead><tr><th>Proof<\/th><th>Primary Statement<\/th><th>Important Checkpoints<\/th><\/tr><\/thead><tbody><tr><td>ISO\/IEC 27001 Certificate<\/td><td>Certified ISMS in Defined Scope<\/td><td>Company, Service, Location, Validity, Certification Body<\/td><\/tr><tr><td>SOC 2 Report<\/td><td>Controls of a Service Organization According to Selected Criteria<\/td><td>Type, Period, System Description, Exceptions, Customer Controls<\/td><\/tr><tr><td>C5 Report<\/td><td>Controls of a Cloud Service According to BSI Criteria<\/td><td>Service, Type, Audit Period, Findings, Additional Customer Controls<\/td><\/tr><tr><td>Pentest Summary<\/td><td>Technical Review of a Defined Scope<\/td><td>Date, Methodology, Scope, Severity, Open Findings, Retest<\/td><\/tr><tr><td>Process Evidence<\/td><td>Implementation of a Specific Organizational Control<\/td><td>Responsibility, Sample, Timeliness, Relation to Performance<\/td><\/tr><\/tbody><\/table><\/figure>\n<h2 class=\"wp-block-heading\">Technical and Operational Evidence Supplement<\/h2>\n<p class=\"wp-block-paragraph\">A penetration test examines an agreed technical scope with human expertise. Do not necessarily request the complete raw report. A summary may include date, methodology, tested systems, excluded areas, findings by severity, open risks, and status of retesting. A test without a clear scope or retest says little about the current state of the service in question.<\/p>\n<p class=\"wp-block-paragraph\">For vulnerability management, process description, responsibilities, sources, prioritization logic, and evidence of closed findings are relevant. Specific internal scan results can be highly sensitive. Therefore, agree on a format that provides sufficient evidence and does not create unnecessary attack surface through document distribution. An external <a href=\"https:\/\/locaterisk.com\/en\/landing\/it-risk-analysis\/\">Security Rating<\/a> can additionally assess currently reachable systems and visible features.<\/p>\n<p class=\"wp-block-paragraph\">In incident management, the reporting process, accessibility, classification, investigation, customer information, and follow-up are verifiable. Suitable evidence may include a process description, a drill log, or an anonymized case summary. Do not request real personal or customer-related incident data if it is not necessary for your decision.<\/p>\n<p class=\"wp-block-paragraph\">For business continuity and recovery, defined responsibilities, dependencies, recovery objectives, and tests are counted. A policy provides the mandate; a current test log shows whether a scenario has been practiced and evaluated. Check whether the tested scenario includes the service in question and essential subcontractors.<\/p>\n<h2 class=\"wp-block-heading\">Evaluate Timeliness, Exceptions, and Confidentiality<\/h2>\n<p class=\"wp-block-paragraph\">Every piece of evidence needs a data status. Define for each risk class how old documents can be and what events trigger a new review. Significant product changes, a security incident, a change of critical subcontractors, or a new operational region may necessitate an update of a formally valid piece of evidence.<\/p>\n<p class=\"wp-block-paragraph\">Read Exceptions and Limitations. An audit report may contain controls with findings, cover a short audit period, or exclude parts of the service. Inquire about management response, treatment status, and compensating measures. A finding is not an automatic reason for rejection; its significance depends on risk and treatment.<\/p>\n<p class=\"wp-block-paragraph\">Handle sensitive reports according to a need-to-know principle. Use protected transmission, role-based access, defined retention, and regulated deletion. Store evaluation and reference in the supplier file if possible, without creating unnecessary copies. Contractual confidentiality rules must be observed.<\/p>\n<p class=\"wp-block-paragraph\">Data protection remains a separate examination area. When a service provider processes personal data on behalf, roles, contracts, and requirements according to applicable data protection laws must be examined separately. An ISO certificate, SOC report, or C5 certification does not replace this examination. Similarly, a data protection agreement does not prove the effectiveness of all security controls.<\/p>\n<h2 class=\"wp-block-heading\">Derive a documented decision from evidence.<\/h2>\n<p class=\"wp-block-paragraph\">Do not create a pure document checklist. For each risk, compile the service provider's statement, the relevant evidence, its limitations, and open questions. Evaluate evidence based on relevance, origin, timeliness, and depth of examination. Multiple weak documents do not automatically result in a strong statement.<\/p>\n<p class=\"wp-block-paragraph\">The service provider should be able to explain deviations and offer alternative evidence. A small provider may not have a SOC or C5 report but can provide targeted process and test evidence. The decision is based on risk and not on company size or notoriety. For critical services, the absence of independent evidence may still require additional examination.<\/p>\n<p class=\"wp-block-paragraph\">Document accepted evidence, data status, findings, measures, deadlines, and residual risk. Link expiration dates with follow-ups. For ongoing services, external signals may trigger an earlier examination. The <a href=\"https:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> provides an additional external view but does not replace evidence evaluation.<\/p>\n<p class=\"wp-block-paragraph\">LocateRisk supports the technical perspective on identified or reachable systems and their changes. For organizational evidence, documents, interviews, and internal examination remain necessary. You can find guidance on integrating into the supplier portfolio at the <a href=\"https:\/\/locaterisk.com\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management<\/a>.<\/p>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What security evidence is useful for IT service providers?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">That depends on the service and risk. Possible evidence includes ISO\/IEC 27001 certificates, SOC or C5 reports, pentest summaries, policies, process evidence, and evidence of incident management and recovery. Each piece of evidence must cover the relevant service in an appropriate scope.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What must you check for an ISO\/IEC 27001 certificate?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Check the certified organization, locations, activities, validity, and certification body. The scope must cover the relevant service and the applicable operating environment.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is BSI C5 a certification from BSI?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. BSI clarifies that C5 certifications are conducted by external auditors and are not BSI certifications. What matters are the specific report, its subject of examination, and the findings.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Must the service provider release the complete pentest report?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Not necessarily. Depending on the risk, a protected, sufficiently detailed summary with scope, date, methodology, findings, open risks, and retest status may suffice. Confidentiality and decision-making needs must be balanced.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Do security evidence replace data protection examination?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. Data protection roles, contractual requirements, and the specific processing of personal data must be examined separately. Security evidence can demonstrate technical and organizational aspects but do not replace a legal classification.<\/p><\/div><\/div><\/div><\/div>\n\n<p class=\"wp-block-paragraph\">Do you want to supplement formal evidence with an external technical perspective? <a href=\"https:\/\/locaterisk.com\/en\/landing\/free-rating\/\">Request a free security rating<\/a> and assign the results to your examination scope.<\/p>","protected":false},"excerpt":{"rendered":"<p>Select and review security evidence for IT service providers: certificates, SOC, C5, tests, policies, incidents, and disaster recovery.<\/p>","protected":false},"author":6,"featured_media":0,"template":"","wissen_thema":[820],"class_list":["post-99025","wissen","type-wissen","status-publish","hentry","wissen_thema-lieferantenrisiko-tprm"],"yoast_head":"<title>Sicherheitsnachweise f\u00fcr IT-Dienstleister \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"Sicherheitsnachweise von IT-Dienstleistern pr\u00fcfen: ISO 27001, SOC, BSI C5, Pentests, Richtlinien, Vorfall- und BCM-Evidenz.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/know\/security-certificates-it-service-providers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sicherheitsnachweise f\u00fcr IT-Dienstleister \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"Sicherheitsnachweise von IT-Dienstleistern pr\u00fcfen: ISO 27001, SOC, BSI C5, Pentests, Richtlinien, Vorfall- und BCM-Evidenz.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/know\/security-certificates-it-service-providers\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/sicherheitsnachweise-it-dienstleister\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/sicherheitsnachweise-it-dienstleister\\\/\",\"name\":\"Sicherheitsnachweise f\u00fcr IT-Dienstleister \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-09-29T07:00:00+00:00\",\"description\":\"Sicherheitsnachweise von IT-Dienstleistern pr\u00fcfen: ISO 27001, SOC, BSI C5, Pentests, Richtlinien, Vorfall- und BCM-Evidenz.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/sicherheitsnachweise-it-dienstleister\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/sicherheitsnachweise-it-dienstleister\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/sicherheitsnachweise-it-dienstleister\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Welche Sicherheitsnachweise sollte man von IT-Dienstleistern verlangen?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>","yoast_head_json":{"title":"Security Certificates for IT Service Providers \u2013 LocateRisk","description":"Check security evidence from IT service providers: ISO 27001, SOC, BSI C5, pentests, policies, incident and BCM evidence.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/know\/security-certificates-it-service-providers\/","og_locale":"en_US","og_type":"article","og_title":"Sicherheitsnachweise f\u00fcr IT-Dienstleister \u2013 LocateRisk","og_description":"Sicherheitsnachweise von IT-Dienstleistern pr\u00fcfen: ISO 27001, SOC, BSI C5, Pentests, Richtlinien, Vorfall- und BCM-Evidenz.","og_url":"https:\/\/locaterisk.com\/en\/know\/security-certificates-it-service-providers\/","og_site_name":"LocateRisk","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/wissen\/sicherheitsnachweise-it-dienstleister\/","url":"https:\/\/locaterisk.com\/wissen\/sicherheitsnachweise-it-dienstleister\/","name":"Security Certificates for IT Service Providers \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-09-29T07:00:00+00:00","description":"Check security evidence from IT service providers: ISO 27001, SOC, BSI C5, pentests, policies, incident and BCM evidence.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/wissen\/sicherheitsnachweise-it-dienstleister\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/wissen\/sicherheitsnachweise-it-dienstleister\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/wissen\/sicherheitsnachweise-it-dienstleister\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"Welche Sicherheitsnachweise sollte man von IT-Dienstleistern verlangen?"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/6"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99025\/revisions"}],"predecessor-version":[{"id":99033,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99025\/revisions\/99033"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=99025"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=99025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}