At Capestone, reliability is central: in how we handle information and in how we organize our services. That is why we are certified according to ISO/IEC 27001:2022 (information security) and ISO 9001 (quality management). These certifications underline that our processes are structurally designed to manage risks, continuously improve quality and ensure consistency.
ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining and continuously improving an Information Security Management System (ISMS). The goal is to make information security risks manageable, with appropriate measures for confidentiality, integrity and availability of information, among other things.
ISO 9001 is the worldwide standard for a Quality Management System (QMS) that helps organizations tightly control and continuously optimize their processes. With a strong focus on customer satisfaction and the structural securing of agreements, this standard guarantees consistent and reliable quality of the results delivered. The overarching goal of ISO 9001 is to increase operational efficiency and lay a solid foundation for sustainable growth.
For organizations that depend on reliable connectivity, IoT solutions and managed services, demonstrable mastery of processes is essential. Our ISO certifications give customers additional assurance that we:
Procedural and demonstrable work (established practices, roles and controls)
Structurally assess and mitigate risks (including on information security and continuity)
Handle incidents and deviations in a controlled manner and learn from them
Apply continuous improvement based on measurement, internal controls and management review
Our ISO/IEC 27001 certification means that information security is not “ad hoc,” but part of a structural management system. In practice, we work with, among others:
Risk management: periodic risk analyses and establishment of control measures
Policies and procedures: clear guidelines for handling information and assets
Access management: roles, authorizations and periodic controls
Incident management: notification, follow-up and evaluation process for security incidents
Awareness and training: awareness and behavior as part of mastery
Continuous improvement: evaluation through internal audits and management review
Our ISO 9001 certification ensures that quality is not dependent on individuals, but on processes. Consider:
Process control and documentation: established practices, agreements and quality controls
Supplier and supply chain management: selection, evaluation and performance agreements
Customer feedback & improvement actions: structural follow-up of signals from the market
KPIs and performance metrics: steering for reliability, lead time and customer satisfaction
Continuous improvement: corrective and preventive measures based on analyses
Are you fully ISO certified or does this apply to a specific scope?
Our certification is for the scope described on the certificate. We always refer to the exact scope on the certificate.
What is the difference between ISO 27001 and ISO 9001?
ISO 27001 focuses on information security risk management (ISMS). ISO 9001 focuses on quality management and process control (QMS).
Who is DNV and what is their role?
DNV is an independent, international certification body. They act as the external party that objectively assesses our processes; they conduct the audits and issue the official certificate when we meet all standards requirements.
How do you ensure that this stays current?
The standards require periodic audits, internal controls and continuous improvement. This is embedded in our management systems.
Capestone bv
Nieuwenhuizenweg 3
2314 XP Leiden
Nederland