Security you can actually verify.
Aesir Srl operates a management system certified by Perry Johnson Registrars for quality (ISO 9001) and information security (ISO/IEC 27001), extended to security controls for cloud services (ISO/IEC 27017) and to the protection of personal data in the cloud (ISO/IEC 27018).
Reference numbers, dates and the original document.
Below you will find the reference details of each certificate together with the original document. If your procurement team needs anything further, write to us: we reply within one working day.
ISO 9001:2015 — Quality management system
Certificate no. C2026-02419-R1
Perry Johnson Registrars, Inc.
Issued 16 April 2026 · Expires 15 April 2029
IAF sectors 33, 34, 29
ISO/IEC 27001:2022 — Information security management system
Certificate no. C2026-02420
Perry Johnson Registrars, Inc.
Issued 16 April 2026 · Expires 15 April 2029
Statement of Applicability Ed. 0, Rev 1.0 of 08/06/2025
ISO/IEC 27017:2015 — Security controls for cloud services
Statement of conformity to the guidelines no. C2026-02420-j
Perry Johnson Registrars, Inc.
Issued 26 May 2026 · Expires 15 April 2029
Valid in combination with ISO/IEC 27001:2022 certificate no. C2026-02420
ISO/IEC 27018:2019 — Protection of personal data (PII) in the cloud
Statement of conformity to the guidelines no. C2026-02420-a
Perry Johnson Registrars, Inc.
Issued 26 May 2026 · Expires 15 April 2029
Valid in combination with ISO/IEC 27001:2022 certificate no. C2026-02420
Design, Implementation and Delivery of Software Solutions, Management of IT Infrastructure, Technology Consulting and Cloud Services for the Digitalisation and Optimisation of Business Processes. Resale of IT and Software Licences.
Certificate holder: Aesir Srl — Via Giuseppe Saragat 2, 20834 Nova Milanese (MB), Italy.
The validity of the certificates is subject to successful periodic surveillance audits.
Certification body: Perry Johnson Registrars, Inc. — 755 West Big Beaver Road, Suite 1340, Troy, Michigan 48084.
NIS2 is not certified. It is governed.
NIS2 does not provide for a certification: it sets obligations on governance, risk management, business continuity and incident notification. Aesir supports the companies in scope on those obligations, starting from an assessment of where they stand today. Our ISO/IEC 27001 certified management system is the foundation we build that work on.
- Assessment of the current position against the requirements of the directive
- Governance and allocation of responsibilities
- Risk management and technical measures
- Business continuity and recovery
- Incident notification procedure
- Ongoing oversight, not a one-off exercise
The same rules across every service we deliver.
The scope covers design, delivery and management: the same procedures apply to managed IT, to our own cloud, to application projects and to bespoke development. No part of what we offer sits outside the management system.
Managed IT and security
Continuous oversight, incident management and a full audit trail of the work carried out, inside the ISO/IEC 27001 perimeter.
Cloud and infrastructure
Security controls for cloud services (ISO/IEC 27017) and protection of personal data in the cloud (ISO/IEC 27018).
Applications and development
Design and delivery of software solutions inside the same quality management system.
Does your procurement team already know who answers in the event of an incident?
Send us your vendor assessment checklist: we will complete it with the certificate details and the procedures we actually follow.