Building on the ISO 27001 certification first achieved by SweetSoft in 2025, the Company continued to review, improve, and strengthen its information security management system in 2026 and obtained an updated ISO/IEC 27001:2022 certificate for the new certification period.
According to the certificate issued by Quality Registrar Systems (QRS), the certified scope covers software production and outsourcing, Internet applications and web design, computer consulting and computer system management, information technology services, data processing, leasing and other IT-related activities, as well as information portal services. The certificate is valid from 11 September 2026 to 10 September 2027.
Information Security Is More Than a Technical Requirement
At SweetSoft, information security is not considered simply a set of security measures to be added at the final stage of a project. Instead, it is integrated into the Company’s management practices and throughout the entire lifecycle of software development, deployment, and operation.
ISO/IEC 27001:2022 provides a structured framework for identifying information assets, assessing security risks, establishing appropriate policies and controls, and maintaining mechanisms for ongoing monitoring and continual improvement.
For SweetSoft, maintaining ISO 27001 certification is therefore not merely about complying with an international standard. More importantly, it supports the systematic standardization of information security practices across the Company’s daily operations — including personnel and access management, source code and data protection, infrastructure management, backup and recovery, change control, incident management, and the identification and treatment of risks related to both SweetSoft’s and its customers’ information.
Protecting Customer Data Is a Long-Term Commitment
In delivering software products and information technology services, SweetSoft recognizes that data is not merely an asset within an information system; above all, it is an asset entrusted to us by our customers and therefore a responsibility that must be protected.
For this reason, the confidentiality, integrity, and availability of information are considered throughout the entire lifecycle of a solution — from system analysis and architecture design to software development, infrastructure deployment, operation, maintenance, and technical support.
This is particularly important for information systems used by government agencies, organizations, and enterprises, where requirements relating to account management, access control, authorization, audit logging, backup and recovery, secure connectivity, configuration management, and incident response should be addressed from the design stage rather than added only after the system has been completed.
“Security by Design” — Building Security into the System from the Beginning
One of the key principles SweetSoft continues to promote in its software development process is “Security by Design.”
Under this approach, information security requirements are considered from the earliest stages of business analysis and system architecture design. Matters such as access-control models, user authentication, data-access boundaries, protection of sensitive information, audit logging, backup and recovery, API security, session management, and incident-response capabilities are taken into account before and throughout the development process.
This represents an important shift from:
“Develop first, then perform security checks”
to:
“Build security requirements directly into the architecture, development process, and software lifecycle from the outset.”
At SweetSoft, this also means moving away from the traditional view that security is solely the responsibility of infrastructure or cybersecurity teams. Instead, information security is a shared responsibility across management, business analysts, solution architects, developers, testers, system administrators, and operations teams.
“Security by Design — Information security should not be an additional layer added at the end; it should be built into the product from its very first design decisions.”
ISO 27001 Is a Process of Continual Improvement
Achieving certification is not the end of the journey.
An Information Security Management System delivers real value only when its policies, processes, and controls are consistently applied in day-to-day operations, regularly reviewed, and continuously improved in response to evolving technologies, emerging cybersecurity threats, and changing business requirements.
SweetSoft’s continued maintenance and improvement of its ISO/IEC 27001:2022 certification following its initial certification in 2025 reflects the Company’s long-term approach to building structured, systematic, and sustainable information security capabilities, rather than addressing security requirements separately on a project-by-project basis.
This provides an important foundation for SweetSoft to further enhance the quality and reliability of its software products and IT services, strengthen risk-management capabilities, and reinforce the trust of customers and partners who rely on SweetSoft to develop, deploy, and operate information systems containing important and sensitive data.

At SweetSoft, protecting customer data and ensuring information security are not merely compliance requirements. They are fundamental principles that must be embedded from the design stage, reflected in every product, and maintained throughout the entire lifecycle of an information system.
Get more information at QRS (Quality Registrar Systems) website: https://qrsyst.com/verify-certificate?token=34424afe-1fa6-44c5-a5fa-3588de6ceb12&fp=3ztIhiGuatkW