Ukrainian hosting provider and domain registrar Cityhost.ua has officially obtained certificates of compliance with national and international standards DSTU ISO/IEC 27001 and DSTU ISO/IEC 27701. The company successfully passed an independent external audit, confirming the highest level of building an information security management system (ISMS) and personal data protection.
According to industry analysts, today only up to five hosting providers in Ukraine have such confirmed compliance with both standards.
What ISO 27001 and ISO 27701 Certify
Passing the audit confirms that the provider has clear, regulated, and automated internal processes for data handling and risk assessment:
- ISO/IEC 27001: defines strict requirements for building an ISMS, controlling physical and digital access, minimizing compromise points, and auditing infrastructure.
- ISO/IEC 27701: extends the base standard regarding privacy and personal data management (PIMS), guaranteeing protection against leaks of confidential client information.
- Access lifecycle control: a strict procedure for granting, regular review, and immediate revocation of employee rights after role changes or termination.
- Incident response: clearly defined action algorithms for the team in case of failures, account compromise attempts, or cyberattacks, reducing threat neutralization time to a minimum.

Comparison of Security Requirements for Standard vs Certified Hosting
| Parameter / Security Direction | Standard Hosting Provider | Certified Provider (Cityhost.ua) |
| Management System (ISMS) | Internal regulations without external verification | DSTU ISO/IEC 27001 certification |
| Personal Data Protection | Basic compliance with legislation | DSTU ISO/IEC 27701 certification |
| Access Management | Subjective control of rights | Regulated access lifecycle |
| Compliance with NBU Requirements | Does not meet requirements for the financial sector | Full compliance for banks and financial institutions |
| Incident Response | Situational solutions during failures | Pre‑defined incident response cards |
Why Cityhost Certification Matters for Business and Financial Sector
The presence of ISO certificates is not only a guarantee of preserving the multi‑year work of online project owners (sites, databases, mail, developments) but also a legal requirement for several sectors:
- Requirements of the National Bank of Ukraine: financial institutions (banks, insurance companies, pawnshops, microfinance organisations) must place their resources exclusively with providers holding ISO/IEC 27001 and 27701 certificates.
- Independent confirmation of reliability: the audit guarantees that backup procedures, data isolation, and threat response measures work in practice, not just on paper.
- Minimisation of human‑factor risks: a clear division of rights within the hosting company prevents data leakage through unattended accesses of former employees.
Xpert Take
Cityhost.ua’s achievement of ISO 27001 and 27701 certifications sets a high benchmark for the entire Ukrainian hosting market. In an era of persistent cyber threats and strict regulation by the NBU, the reliability of server hardware and speed of support must be backed by a certified security management system. For Ukrainian businesses, this serves as a vital reference point when choosing a secure platform for hosting mission‑critical IT infrastructure.









