Shanghai Zhaoxun has officially passed the ISO/IEC 27001:2022 recertification audit, with certification issued by Zhong'an (Beijing Zhong'an Zhihuan Certification Center). The upgrade from the 2013 to the 2022 standard marks authoritative recognition of our ISMS maturity.
1. Scope Covering Core Business Scenarios
The certified scope — information security management activities in software development and operations, and in information system consulting, integration and operations — precisely matches our business architecture, connecting R&D, delivery and operations under one security management system and backing our work for compliance-sensitive government and enterprise clients.
2. Statement of Applicability Aligned to Multi-Cloud and Supply-Chain Risks
Against the ISO/IEC 27001:2022 control set (Annex A) — four domains and 93 controls — we completed and implemented Statement of Applicability V1.0, adding or strengthening 11 controls for multi-cloud delivery, remote operations and supply-chain security, keeping the management system aligned with business evolution.
3. Track Record of Continuous Compliance
Since first certification, surveillance-audit pass rates have remained 100% with no significant security incidents — stability and maturity keep improving.
4. Authoritative Recognition and International Mutual Acceptance
The certificate carries the CNAS accreditation mark (CNAS C028-M) with international mutual acceptance. Status is verifiable via the CNCA website, the certification body's website and the certificate QR code — authentic, valid and traceable.
5. System as Capability, Compliance as Competitiveness
Completing the 2022-version upgrade is a milestone on our ISMS journey. Going forward we will keep the principle of "technology as foundation, compliance as soul" — international standards driving internal governance, compliance capability safeguarding client business — building a trustworthy, reliable and sustainable security foundation in the digital economy.