Start typing for search

Awery Passes 2026 ISO 9001 and ISO/IEC 27001 Surveillance Audit With Zero Nonconformities
Awery Passes 2026 ISO 9001 and ISO/IEC 27001 Surveillance Audit With Zero Nonconformities
Copy link

Awery completed its 2026 ISO 9001 and ISO/IEC 27001 surveillance audit with zero nonconformities, extending certification held since 2021

Awery Aviation Software has completed its 2026 surveillance audit for ISO 9001:2015 (Quality Management) and ISO/IEC 27001:2022 (Information Security Management). The audit, carried out on 29 and 30 June 2026 by the independent certification body LL-C (Certification) Czech Republic a.s., closed with zero major and zero minor nonconformities. The auditors' recommendation was to maintain both certificates without interruption.

Awery has held ISO 9001 and ISO/IEC 27001 certification continuously since July 2021. This audit was not a first-time certification: it is the latest step in the annual surveillance cycle that keeps both certificates valid, covering Awery's UAE headquarters and its development site in Ukraine, with the company also operating out of the UK and the US.

Why Independent Certification Matters More in Air Cargo Right Now

Cargo airlines, GSSAs, cargo operators, charter brokers, and ground handlers are exchanging more operational and commercial data through their software vendors than they were even two years ago: digital bookings, live capacity, billing data, and increasingly, data shared through standards such as IATA ONE Record. As that data footprint grows, how a vendor actually runs its own quality and security processes stops being a background detail and becomes something procurement and IT security teams need evidence for, not just assurances.

That is what independent certification provides. ISO 9001 and ISO/IEC 27001 are not self-declared. They are assessed annually by a third-party auditor against a fixed set of international requirements, and the results, including any nonconformities, are a matter of record. For a customer evaluating cargo technology vendors, it means partnering with a provider that runs on a certified platform, rather than one that simply says so.

It is worth being precise about what certification does and does not cover: ISO 9001 and ISO/IEC 27001 certify Awery's own management systems. They are not a guarantee that a customer's own regulatory or security obligations are automatically satisfied. Those obligations remain the customer's own responsibility; certification is one input into that assessment, not a substitute for it.

What ISO 9001:2015 Covers at Awery

ISO 9001 certifies Awery's quality management system across the full scope of its software business: requirements gathering, planning, product development and testing, product control and monitoring, client-side deployment, technical support, and change verification.

In practice, that scope is backed by processes the auditors reviewed directly during this cycle:

  • Annual risk and opportunity review. Awery's leadership team runs a documented SWOT-based review each year, feeding into measurable quality objectives with named owners and deadlines.
  • A live internal audit programme. In 2026 alone, Awery had already logged 33 internal quality-management audits and 32 internal information-security audits across the business by the time of this surveillance visit, the large majority closed with no remarks.
  • Independently verified customer satisfaction. The auditors reviewed Awery's Customer Satisfaction Report, sourced from Capterra, covering the 2025 to 2026 period: 27 verified reviews, an overall rating of 4.6 out of 5.0, and a Net Promoter Score of +60.
  • Integration across modules. The auditors specifically noted the degree of integration between Awery's ERP, finance, and CRM modules as a strength, consistent with Awery's product approach of running cargo, operations, and finance from one connected system rather than several disconnected tools.

What ISO/IEC 27001:2022 Covers at Awery

ISO/IEC 27001 certifies Awery's information security management system: how the company protects the confidentiality, integrity, and availability of the data it processes, across the same operational scope as its quality certification.

For 2026, Awery fully rewrote its risk assessment methodology, moving to a two-factor likelihood-and-impact scoring model. The resulting risk registry identified 15 information security risks; ten were rated high before controls were applied, and after those controls were factored in, none remained rated high, with the rest reduced to moderate or low residual risk.

Several of the technical and operational controls the auditors reviewed are directly relevant to what a customer's own security team would want to see during due diligence:

  • Encryption, using AES-256 for data at rest and TLS 1.3 alongside SFTP/SSH for data in transit.
  • Mandatory multi-factor authentication across critical systems and all remote access.
  • Continuous vulnerability scanning, combined with independent penetration testing at least once a year, and defined patching timelines: critical vulnerabilities on laptops and servers are patched within days, and critical cloud vulnerabilities within 72 hours.
  • A tested disaster recovery plan. In June 2026, Awery ran a tabletop exercise simulating a regional cloud outage. The company's one-hour recovery time objective was met, with production access restored in 52 minutes; a small number of refinements identified during the exercise are already being tracked to completion.
  • An expanding regulatory watch list. Awery's register of legal and contractual requirements was widened this year to explicitly track frameworks relevant to its international customer base, including the EU's NIS2 directive, the EU AI Act, UAE data protection law (PDPL), and the EU Cyber Resilience Act.

The underlying Quality and Information Security Policy was also updated in 2026 to add a formal commitment to environmental sustainability, including a reduced carbon footprint and the use of green data centres.

The Audit Result, in Brief

  • Major nonconformities: zero.
  • Minor nonconformities: zero.
  • Two minor administrative areas for improvement were logged, standard practice under the ISO framework and unrelated to certification status.
  • Both certificates, ISO 9001:2015 and ISO/IEC 27001:2022, are recommended to be maintained.
  • Certification has been held continuously since July 2021.
  • The audit was conducted by LL-C (Certification) Czech Republic a.s., an accredited, independent certification body.

What This Means If You're Evaluating Awery

If you are on a procurement, IT security, or compliance team evaluating cargo technology vendors, ISO 9001 and ISO/IEC 27001 give you a starting point that does not rely on taking a vendor's word for it: an external body has reviewed Awery's quality and security processes against a fixed international standard, on a recurring annual basis, and published the result.

ISO 9001 and ISO/IEC 27001 also sit alongside Awery's SOC 2 Type II certification, giving prospective customers three independently audited reference points rather than one, when assessing a vendor's operational and security maturity.

For a copy of Awery's current ISO 9001 and ISO/IEC 27001 certificates, or supporting documentation for an RFP or vendor due-diligence process, contact sales@awery.aero. To see how Awery's certified cargo management system fits your operation, you can also book a demo.

Frequently Asked Questions

What is the difference between ISO 9001 and ISO/IEC 27001? ISO 9001:2015 is the international standard for quality management systems: how consistently a company plans, builds, and supports its product. ISO/IEC 27001:2022 is the international standard for information security management: how a company protects the confidentiality, integrity, and availability of the data it handles. Awery holds both, covering the same operational scope, from requirements gathering through to technical support and change management.

How often is Awery's certification audited? Certification bodies carry out surveillance audits at least once a year to confirm a certified company continues to meet the standard. Awery's most recent surveillance audit took place in June 2026, and the company has held both certifications continuously since 2021.

Does Awery's certification mean my airline or GSSA is automatically compliant? No. ISO 9001 and ISO/IEC 27001 certify Awery's own management systems, not a customer's regulatory status. They confirm that Awery runs on a certified platform with independently verified quality and security practices. Your organisation's own compliance obligations, whether aviation security regulation, data protection law, or industry-specific rules, remain your responsibility.

Is Awery also SOC 2 certified? Yes. Awery holds SOC 2 Type II certification in addition to ISO 9001 and ISO/IEC 27001, giving customers three independently audited reference points when evaluating vendor security and reliability.

GET PRODUCT TOUR