ISO 27001 is the international standard for an information security management system (ISMS), and it is the single most requested certificate in enterprise data centre procurement. In Kenya the pattern is clear: the leading operators are either certified or mid-process, because banks, cloud providers and multinationals treat the certificate as a filter. Without it, a facility is effectively excluded from the most valuable conversations. This page explains what the standard actually certifies, what the audit cycle looks like, and how it maps onto Kenyan law.
What ISO 27001 actually certifies
The most common misconception is that ISO 27001 certifies a building. It does not. It certifies a management system: the documented policies, risk assessments, controls, and review cycles through which an organisation manages information security. The same certificate framework applies to a bank, a law firm, or a colocation hall. For a data centre, what gets certified is the operator's systematic approach to identifying, assessing and treating security risks, and the independent audit that confirms the system exists and functions.
That distinction matters when you read a certificate. The scope statement on the certificate says exactly which entity, which facility, and which services are covered. "Our group is ISO 27001 certified" and "this facility's operations are in scope" are different claims, and a buyer is entitled to the second one in writing.
The audit cycle, start to finish
Certification runs on a repeating cycle. It begins with a readiness review, where the certification body checks that the ISMS documentation exists and the organisation actually ran its own internal audit and management review. Then comes the certification audit, where auditors test whether the system works as documented, sampling evidence across controls. Once granted, the certificate typically runs on a three-year cycle with annual surveillance audits, and a full recertification at the end of the term. Failure to maintain the system, not just the controls but the reviews and records, is what suspends certificates in practice.
For a Kenyan operator, the preparation phase dominates the effort: writing and living the policies, building the risk register, running the internal audit, and collecting evidence. Audit fees are the smaller line item; the organisational work is the real cost, which is why the cost question has no honest single-number answer.
The controls that bite hardest in a data centre
The standard's control set is broad, but for a colocation or managed facility a handful of themes carry most of the weight. Physical and environmental security: perimeter protection, entry control, monitoring, equipment siting, power and cooling resilience. Operations security and logging: who did what, when, with records that survive an audit. Supplier relationships: contractors and remote-hands staff inside the trust boundary. And capacity and continuity management, which overlaps with the facility's core product.
These are precisely the controls a buyer should map against the facility tour: if the certificate is real, the physical security layers, biometric readers, mantraps, CCTV retention, rack locks, and access logs, should be observable in operation, not just in a policy document.
How it maps onto Kenyan law
Kenya does not mandate ISO 27001, but three legal frameworks make it commercially decisive. The Data Protection Act 2019 requires data processors and controllers to implement "appropriate technical and organisational measures" for personal data, and certification is the most widely accepted demonstration of exactly that; the Kenya Data Protection Act obligations fall directly on data centre operators acting as processors. The Computer Misuse and Cybercrimes Act 2018 makes evidence discipline a legal asset, which aligns with the ISMS logging culture. And the Communications Authority's licensing regime, under which operators hold their NFP-T2 licence, adds regulatory expectations that a documented ISMS makes far easier to answer. The Policy Intelligence hub tracks these instruments as they evolve.
The failure modes that actually suspend certificates
Certificates rarely lapse because a control failed. They lapse because the system around the controls stopped being lived: management reviews that stopped happening, internal audits skipped to save a quarter, risk registers untouched since certification day, and new services launched without going through the ISMS change process. Auditors sample for exactly this, which is why the operational rhythm, regular reviews, current records, evidence of decisions, matters as much as the controls themselves. A Kenyan operator planning certification should budget for that ongoing discipline from the start, not treat it as a one-time project.
What to verify before you trust the certificate
Three checks separate a meaningful certificate from wallpaper. One, scope: confirm the certificate names the operating entity and the facility, not just a corporate parent. Two, accreditation: confirm the certification body itself is accredited, so the audit means what it claims. Three, currency: check the issue date, the surveillance audit history, and the expiry, a certificate in year three without surveillance visits is a risk signal, not a comfort.
If you are comparing facilities, our security explainer shows how certification fits alongside the physical, network and data layers, and the threat patterns seen in Kenya show what the controls are actually for. And if you are building a career rather than a facility, the individual training paths live in our certifications and careers guide; facility certification and personal certification are different tracks that are easy to confuse.
