ISO 27001 is the one security credential recognised in every market on this page. One ISMS, one certificate, scoped to cover the countries you operate in. Local law adds its own layer — registration duties, breach-notification clocks, critical-infrastructure designations — and the country guides below cover each layer in turn.
Most security credentials are national. The Essential Eight is Australian, SOC 2 is an American attestation, and national schemes bind an organisation to one regulator while carrying little weight with a customer in another market.
ISO/IEC 27001 is the international standard for information security management, and a certificate issued by an accredited certification body in one country is read the same way by a procurement team in another. For organisations selling across the markets on this page, it is the credential that does not have to be re-earned at each border.
What is certified is the management system rather than a product or a datacentre. Annex A holds 93 controls in four themes; all 93 are assessed against your risks and the applicable ones documented in the Statement of Applicability. Certification runs Stage 1 (documentation review) and Stage 2 (interviews and evidence), then annual surveillance audits and full recertification every three years. That cycle is identical whether the auditor sits in Ulaanbaatar, Jakarta or Sydney.
The standard does not incorporate local law. Every jurisdiction adds its own layer, and that layer is where multi-market compliance becomes difficult.
The pattern repeats across the region: a cyber security law that designates critical infrastructure or regulated operators, and a data protection law that sets handling duties and a breach-notification deadline. The instruments differ by name and follow the same structure.
Indonesia sits at the demanding end. PP 71/2019 governs electronic systems, operators register with Kominfo as PSEs, BSSN sets technical standards and runs security assessments that include ISO/IEC 27001 readiness checks, and the UU PDP requires notification to authorities and affected users within 72 hours of a breach. Mongolia sits at the lighter end: a Law on Cyber Security that designates organisations with critical information infrastructure, and a GDPR-aligned Law on Personal Data Protection, neither of which mandates ISO 27001.
Local law rarely requires the certificate by name. It requires registration, secured systems, protected personal data and notification after an incident, together with proof of all four to a regulator, a bank, or a customer’s security questionnaire. An ISMS is the structure those audiences recognise.
That produces the working model for the region: build one ISMS, record each country’s legal requirements inside it on entering the market, and extend the certificate’s scope rather than starting again. The certificate covers new markets as they are added, and the legal-requirements register grows with them.
Secure60 has delivery infrastructure across all of these markets via Rackcorp — 28 datacentres in the ten countries this section covers, including ten in Australia — so log collection, monitoring and evidence can run on in-country infrastructure where contracts or regulators require it. We have no local offices, and the certification audit is performed by a locally accredited body.
Country guides, each covering the local regulatory hooks and what certification takes there:
| Market | Guide | Delivery infrastructure via Rackcorp |
|---|---|---|
| Indonesia | ISO 27001 in Indonesia | 2 datacentres |
| Mongolia | ISO 27001 in Mongolia | 4 datacentres |
| Hong Kong | ISO 27001 in Hong Kong | 2 datacentres |
| India | ISO 27001 in India | 2 datacentres |
| Kyrgyzstan | ISO 27001 in Kyrgyzstan | 2 datacentres |
| Philippines | ISO 27001 in the Philippines | 2 datacentres |
| Thailand | ISO 27001 in Thailand | 2 datacentres |
| Singapore | ISO 27001 in Singapore | 1 datacentre |
| New Zealand | ISO 27001 in New Zealand | 1 datacentre |
Cross-cutting guides for organisations operating in more than one of them:
A regulator in Jakarta asks about PSE registration and the 72-hour breach deadline. A Mongolian counterparty asks about critical-infrastructure obligations. A certificate scoped without those obligations inside it answers neither.
The sequence matters. Each jurisdiction’s legal requirements go into the ISMS as inputs — into the risk assessment, the controls and the incident process — and the certificate then evidences the result. Built in that order, one management system serves many jurisdictions, because each jurisdiction’s requirements are already inside it.
Secure60 delivers the certification and operates the security behind it. Across this region that means one engagement: ISMS build, controls, evidence collection and the day-to-day security operations behind them, on one security platform that works across every market above. In-country infrastructure comes via Rackcorp where residency is required. The certification audit is performed by a locally accredited certification body; we prepare you for it. Secure60 holds ISO 27001:2022 certification, so the system we build for you is the one we run.
Is ISO 27001 recognised in every country in this section?
Yes. ISO/IEC 27001 is an international standard, and a certificate issued by an accredited certification body is recognised across borders. That recognition is the advantage over a national scheme: the certificate is earned once.
Can one ISO 27001 certificate cover several countries?
Yes. You define a multi-country scope in the ISMS, engage one certification body, and the sites are listed on the certificate. See ISO 27001 across multiple jurisdictions for how that works in practice.
Do any of these countries legally require ISO 27001?
Local law rarely names ISO 27001 as a requirement. Mongolia’s laws, for example, do not mandate it. What the laws set are obligations: register, secure your systems, notify after a breach. An ISMS is the recognised structure for evidencing that those obligations are met.
Who performs the certification audit?
An accredited certification body in the relevant market, and not Secure60. Audit fees are set by the certification body and vary with the size and scope of what is being certified.
Does Secure60 have a presence in these countries?
We have delivery infrastructure in each market via Rackcorp — 28 datacentres across the ten countries this section covers, including Australia. We have no local offices, and the certification audit is performed by a locally accredited body.