Licel has completed its latest ISO/IEC 27001:2022 and CSA Cyber Trust Mark surveillance audits, with no minor or major non-conformities identified. Licel holds the Cyber Trust Mark at the highest tier (Tier 5, Advocate).
The audits were conducted with ISOCert, Licel's certification and audit partner. As part of the ISO/IEC 27001:2022 surveillance audit, the auditor highlighted the quality and completeness of the evidence presented, recognizing it as thorough, well organized, and consistently cross-referenced across policies, project records, management reviews, technical evidence, and third-party reports. The auditor concluded that this reflected "a mature and genuinely operating ISMS rather than a 'paper-only' compliance exercise."
That distinction matters, because information security management should not exist solely as a set of documented policies. It should be embedded in day-to-day engineering, software development, infrastructure management, risk assessment, and operational decision-making.
"Our customers include banks and payment providers operating in highly regulated environments," said Mikhail Dudarev, CTO and co-founder at Licel. "For them, security is not limited to the technology they deploy. It also depends on the engineering practices, operational controls, and security governance of the suppliers they rely on. Independent audits provide evidence that these controls are not only documented, but operating effectively in practice".
Continuous independent assurance
Certification is one stage of an ongoing security program rather than an endpoint. Surveillance audits provide independent confirmation that the controls and processes established at certification continue to operate effectively, and that they remain aligned with the organization's evolving risks and responsibilities.
These organizational certifications sit alongside the independent product-level evaluations Licel maintains. DexProtector and the Licel vTEE have each been independently evaluated and approved by EMVCo under its Software-Based Mobile Payments program. Together, the two layers of assessment cover both what Licel builds and how Licel operates.
For customers in regulated and security-sensitive environments, both are relevant. Independent assessment of Licel as an organization can be referenced directly in a customer's own third-party risk and supplier assurance processes.
For Licel, the principle remains the same:
Security should not simply be claimed. It should be demonstrated, independently assessed, and continuously maintained.