News • 3 min read
By Bitpanda
04.03.2025
We are proud to announce that we were recently granted the ISO 27001:2022 certification, underlining our ongoing commitment to security and compliance. While we have been ISO-certified for the past three years, this latest renewal reflects our adherence to the most recent version of the standard, incorporating new requirements that we have successfully met. All of our entities, including all business areas, are certified, highlighting our ongoing focus on being the industry's safest and most regulated cryptocurrency platform.
ISO 27001 is a global standard for companies that want to follow best practices for their Information Security Management System (ISMS) design and implementation.. At Bitpanda, we use ISO 27001 as a framework for consistent information security governance and control implementation throughout our organisation.
Being certified against this standard is a mark of confidence issued by an accredited external auditor, validating our security posture. This certification confirms that our security design, policies, processes, practices, and behaviour meet stringent ISO 27001 requirements. This demonstrates that our systems and our overall approach have been independently assessed, underscoring our commitment to safety and security.
After nearly a decade, the ISO issued a new version of ISO 27001 in 2022. To be clear, Bitpanda has officially complied with the standard for three years, with annual audits and renewals. With this new version, we have further improved our ISMS with new control layers. Compared to the 2013 version, 11 new controls emerged in ISO (for example, Threat Intelligence) despite a consolidation from 114 to 93 Annex A controls. Moreover, there is a division into four control categories (previously 14): Organisational, People, Physical, and Technological.
For Bitpanda users, there will be no change in the way you use our platform, but behind the scenes, our security measures are stronger than ever. Though some companies will obtain ISO certification as a formality, not all will implement every ISO control. At Bitpanda, we’re different and go above and beyond to implement every control, ensuring your information is protected from every possible angle.
Let’s take the four control categories and show how your data is safeguarded through multiple layers:
Organisational Controls: These bring together information security policies, strong security practices (such as incident management and access controls), roles and responsibilities, regulatory compliance, vendor due diligence, audits, and KPIs.
As a fully regulated financial organisation, ISO is just one part of our broader compliance framework, which also includes DORA and MiCAR. At Bitpanda, we ensure these standards work seamlessly to maintain the highest levels of security and compliance.
People Controls: Our key controls related to people include background checks, terms and conditions, and awareness, on which we place special emphasis. We ensure our employees and third parties know exactly what kind of data they are managing and how to protect it.
Physical Controls: We leverage physical security to keep all physical assets secure from unauthorised access.
Though we are fully cloud-native, we uphold the highest security standards for devices, servers, and other assets, safeguarding them against physical threats.
Technological Controls: From automation to monitoring, this encompasses system policies, anonymisation, firewalls, scaling, segregation, filtering, testing, secure deployment, and much more.
Wherever Bitpanda's and our customers’ confidential data is processed - whether network security or the last endpoint device - we ensure it remains secure.
At Bitpanda, security and compliance are continuous priorities - not just an obligation but a responsibility we embrace. Obtaining a certification is not the finish line but part of an ongoing effort to strengthen our safeguards. We continuously monitor our environment, preparing for emerging risks and working vigorously on improvements without waiting for an audit.
Ultimately, we are committed to treating all confidential data with the highest level of care, ensuring that Bitpanda remains a secure and trusted platform for investing in digital assets.
Learn more about our security practices and why your assets are safe with us.
Bitpanda GmbH ve grup şirketleri (Bitpanda) Türk Parasının Kıymetini’nin Korunması Hakkında 32 sayılı Karar’ın 2/b maddesine göre Türkiye’de yerleşik sayılan hiçbir kişiye yönelik olarak 6362 sayılı Sermaye Piyasası Kanunu başta olmak üzere Türkiye Cumhuriyeti Devleti mevzuatı hükümleri gereği Türkiye’de faaliyet izni gerektiren hiçbir sermaye piyasası faaliyetine dair hizmet sunmamaktadır. Şayet Bitpanda’nın yabancı sermaye piyasalarında vermiş olduğu hizmetlerden Türkiye’de yerleşik kişilerin faydalandığı tespit edilecek olursa tüm zararları kullanıcıya ait olmak üzere bu hizmetler ivedilikle sona erdirilecektir.
We use cookies to optimise our services. Learn more
The information we collect is used by us as part of our EU-wide activities. Cookie settings
As the name would suggest, some cookies on our website are essential. They are necessary to remember your settings when using Bitpanda, (such as privacy or language settings), to protect the platform from attacks, or simply to stay logged in after you originally log in. You have the option to refuse, block or delete them, but this will significantly affect your experience using the website and not all our services will be available to you.
We use such cookies and similar technologies to collect information as users browse our website to help us better understand how it is used and then improve our services accordingly. It also helps us measure the overall performance of our website. We receive the date that this generates on an aggregated and anonymous basis. Blocking these cookies and tools does not affect the way our services work, but it does make it much harder for us to improve your experience.
These cookies are used to provide you with adverts relevant to Bitpanda. The tools for this are usually provided by third parties. With the help of these cookies and such third parties, we can ensure for example, that you don’t see the same ad more than once and that the advertisements are tailored to your interests. We can also use these technologies to measure the success of our marketing campaigns. Blocking these cookies and similar technologies does not generally affect the way our services work. Please note, however, that while you’ll still see advertisements about Bitpanda on websites, the adverts will no longer be personalised for you.