Talk to sales
← Company Security

Security you can verify, not just trust.

Next Communications operates an Information Security Management System certified to ISO/IEC 27001:2022 by an accredited third party. Enterprise buyers, banks and card networks can validate our certification independently — the registration number and verification route are published below.

27001
ISO/IEC 27001:2022 certified ISMS
2029
Certificate valid until 19 July 2029
EU
Netherlands-domiciled, EU data residency available
3rd
Independently audited by an accredited certification body
Certification 01
ISO/IEC 27001:2022

Certified against the international standard.

ISO/IEC 27001 is the international standard for information security management. Certification means an accredited external auditor has examined our controls, policies and operating practice — and will re-examine them on a fixed surveillance cycle for the life of the certificate.

// Certified scope

What the certificate actually covers.

Scope matters more than the badge. Ours is stated on the certificate as:

“Provision of Information Security Management for the Design, Development, Operation and Support of AI-native Software-as-a-Service (SaaS) Telecommunications Orchestration Platform.”

That is the platform itself — not a peripheral system or a single office. The orchestration layer our enterprise customers integrate with is inside the certified boundary.

// Certificate details

Verify it independently.

  • Standard: ISO/IEC 27001:2022
  • Registration no.: NL10690E
  • Certified entity: Next Communications B.V., Billitonstraat 1, The Hague 2585TX, Netherlands
  • Valid from: 20 July 2026
  • Valid until / recertification: 19 July 2029
  • Statement of Applicability: Ver. 1.0, dated 11 March 2026
  • Certification body: LMS Certifications FZE LLC

The certification body publishes a verification service at lmscert.me, where the registration number above can be checked against their register.

In practice 02
Operating discipline

A management system, not a document.

Certification is awarded against evidence of how the business actually runs. These are the disciplines an ISO 27001 audit examines and continues to re-examine.

// 01

Risk assessment.

Information security risks are identified, owned and treated through a documented, repeatable process rather than ad hoc judgement.

Documented and owned
// 02

Access control.

Least-privilege access to production systems and customer data, with joiner-mover-leaver process and periodic review of entitlements.

Least privilege
// 03

Incident response.

Defined detection, escalation and notification paths, so a security event has an owner and a clock from the moment it is raised.

Defined escalation
// 04

Continuous audit.

Internal audit plus scheduled external surveillance audits. The certificate is maintained by evidence, and lapses without it.

Surveillance cycle
Data 03
Data protection & residency

Built for regulated buyers.

Our customers are banks, card networks, fintechs and airlines. Their procurement and risk teams set the bar, and the platform is built to clear it.

// Data protection

GDPR by design.

Next Communications B.V. is domiciled in the Netherlands and operates under EU data protection law.

  • GDPR-compliant by design
  • EU data residency available
  • Dedicated APN available for regulated workloads
  • Data processing terms available for enterprise agreements
// Roadmap

What is next.

We publish our security posture as it stands, including work still in flight.

  • ISO/IEC 27001:2022 — certified
  • SOC 2 Type II controls — in progress

If your due-diligence process needs something we have not listed, ask. We would rather tell you where we are than imply more than we hold.

Due diligence

Security questionnaires, answered.

Vendor assessments, DPAs and architecture reviews are a normal part of how we sell. Email sales@nextcommunications.nl with your questionnaire or security requirements and our team will route it to the right people.