2026-09-24 · 5 min read

Is Personio ISO 27001 or SOC 2 Certified?

Quick answer. Personio holds ISO/IEC 27001:2022 certification (cert ISMS-PE-121523, issued by A-LIGN, valid through December 15, 2026), scoped to its product and development function in Munich, Madrid, and Dublin. We found no published SOC 2 report on Personio's own trust center as of this writing. Verify directly with Personio if your auditor needs one.

If you use Personio as your HRIS and you're heading into a SOC 2 or ISO 27001 audit, two questions come up fast: does Personio itself carry a certification you can point to, and what evidence does Personio actually give your auditor about your own controls?

Those are two different questions, and most vendor security pages blur them together. Here's what we verified directly.

What Personio's ISO 27001 certificate covers

Personio is certified against ISO/IEC 27001:2022. The certificate (number ISMS-PE-121523) was issued by A-LIGN Compliance and Security, Inc., one of the larger US-based ISO and SOC 2 auditors. Original certification date is December 15, 2023, the statement of applicability was re-issued January 30, 2025, and the certificate expires December 15, 2026.

The scope statement matters more than the headline claim. From the certificate:

"Personio's ISMS encompasses business activities relating to the provision, operation, maintenance and management of the Personio SaaS HR Platform and defines requirements for all Personio personnel, third party suppliers and systems that create, maintain, store, access, process or transmit information within Personio's product and development department (PTech), and limited to the main product development locations Munich (HQ), Madrid and Dublin."

Common gap

The certificate is scoped to Personio's product development function (PTech) at three locations, not every Personio office or business unit. If your auditor or a customer questionnaire asks whether Personio is "fully" ISO 27001 certified, this is the honest, precise answer: the SaaS platform's development and operations org is certified, scoped as above.

The statement of applicability also pulls in control objectives from ISO/IEC 27017:2015, the cloud-specific extension to ISO 27001. That's relevant if your own audit needs cloud-service-provider controls covered by a subservice organization.

Source: Personio ISO 27001:2022 certificate, Personio Trust Center.

Does Personio have SOC 2?

We checked Personio's public trust center directly. It lists ISO/IEC 27001:2022, ISO/IEC 27017:2015, a GDPR compliance document, and B Corp certification. No SOC 2 report, Type I or Type II, appears there as of this writing.

Some third-party vendor-risk aggregators describe Personio as "SOC 2 compliant," but we could not confirm that against Personio's own published materials, and a secondary source is not good enough for something you'll put in your own audit evidence file. If your auditor specifically needs a Personio SOC 2 report, ask Personio's security or sales team directly, or request access through the trust center, rather than citing an unverified secondary claim.

How startups use Personio as compliance evidence

Personio is HR-controls evidence, not infrastructure evidence. It shows up in the personnel-focused parts of both SOC 2 and ISO 27001, the same territory covered in our BambooHR compliance guide for teams on a different HRIS.

SOC 2 CC1.1 (background screening). If your background check workflow logs status in Personio, that's your evidence for hiring controls.

SOC 2 CC2.2 (security awareness training). Training completion records tracked in Personio, whether logged directly or synced from an LMS, are primary evidence.

SOC 2 CC6.2 (provisioning and deprovisioning). This is the highest-value control. Auditors compare the current employee roster in Personio against active accounts in your identity provider, and check that terminated employees in Personio don't still have live access. If Personio isn't connected to your IdP via SCIM or an equivalent sync, this becomes a manual, error-prone reconciliation every audit cycle.

ISO 27001 Section 6 (People controls). Personio maps to 6.1 (screening), 6.2 (terms of employment), 6.3 (security awareness), and 6.5 (return of assets, functionally equivalent to access revocation for cloud-native companies).

What auditors look for: a current employee roster export from Personio, a hire and termination event log covering the audit period, training completion records, and proof that account deprovisioning happened at or near the termination date, not days later.

The "Secureframe Personio integration" query, explained

If you searched for this, you're probably trying to figure out whether a compliance platform connects to Personio, and what that connection actually does. It does, and the mechanics are the same across Secureframe, Vanta, and Drata: a pre-built API connector pulls your employee roster, hire and termination events, and role data out of Personio automatically, so you're not manually exporting spreadsheets every quarter.

That connector automates your evidence collection. It isn't related to whether Personio itself is certified. Those are separate questions, and it's worth keeping them separate when you're briefing an auditor or answering a security questionnaire.

Gaps that show up at audit

No sync between Personio and your identity provider. Terminations get processed in Personio, but IT access revocation happens manually, sometimes days later. Auditors catch this by comparing termination dates against IdP deactivation logs.

Training tracked outside Personio. If security awareness training completions live only in an LMS or email confirmations, producing them at audit time is manual and inconsistent. Route completions into Personio or your compliance platform so they're queryable.

Citing "Personio is SOC 2 compliant" without a report in hand. If a customer questionnaire or your own auditor asks for Personio's SOC 2 report, don't repeat a claim you haven't verified. Request the actual document or point to the ISO 27001 certificate instead.

Mapping HR evidence like this to the right controls, and knowing which vendor claims to trust versus verify, is the kind of recurring work a fractional CISO handles so it doesn't land on you mid-audit. Book a call if you want a second set of eyes on your vendor evidence before your auditor asks for it.

Related reading

Frequently asked questions

Is Personio ISO 27001 certified?
Yes. Personio SE & Co. KG holds ISO/IEC 27001:2022 certificate ISMS-PE-121523, issued by A-LIGN Compliance and Security, Inc., originally certified December 15, 2023 and valid through December 15, 2026. The statement of applicability also includes ISO/IEC 27017:2015 cloud security controls.
Does Personio have a SOC 2 report?
We could not find one. Personio's own trust center (trust.personio.com) lists ISO 27001, ISO 27017, GDPR documentation, and B Corp certification, but no SOC 2 report as of this writing. If your auditor requires a SOC 2 report specifically for Personio, confirm directly with Personio's security team or your account rep rather than assuming one exists.
What does Personio's ISO 27001 certificate actually cover?
The scope is narrower than 'Personio is ISO 27001 certified' suggests. It covers Personio's product and development department (PTech) and is limited to three locations: Munich (HQ), Madrid, and Dublin. It is not a company-wide certification covering every Personio office or business function.
How do I use Personio as evidence in my SOC 2 audit?
Personio is HR-controls evidence, not infrastructure evidence. Pull hire and termination event logs for CC6.2 (provisioning and deprovisioning), background check status for CC1.1, training completion records for CC2.2, and the current employee roster for CC9.1 vendor and access reviews. Pair termination dates in Personio with deactivation dates in your identity provider.
What is the Secureframe Personio integration?
It is a pre-built connector that compliance automation platforms like Secureframe (and similarly Vanta and Drata) use to pull personnel data out of Personio automatically: employee roster, hire and termination events, and role changes. It automates evidence collection for your audit. It has nothing to do with Personio's own compliance certifications.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.