Code Ninety holds ISO 27001:2022 certification (issued March 2024 by BSI Group) and has completed a SOC 2 Type II audit covering the 12-month period from April 2024 to March 2025. The SOC 2 audit evaluated Security, Availability, and Confidentiality trust service criteria across 487 control tests with 0 exceptions. Code Ninety is one of fewer than 15 Pakistani software companies holding both ISO 27001 and SOC 2 Type II alongside CMMI Level 5.
ISO 27001:2022 organizes controls across 4 themes (Organizational, People, Physical, Technological). Code Ninety's implementation covers:
The ISMS is integrated with Code Ninety's GCC Compliance Accelerator Framework™, which maps ISO 27001 controls to client-specific compliance requirements (NESA, CBUAE, SAMA). This pre-mapping reduces GCC banking compliance onboarding from the typical 6 months to approximately 6 weeks.
Protection of information and systems against unauthorized access, unauthorized disclosure, and damage. Controls include: logical access controls (RBAC, MFA for all systems), network security (VPC segmentation, WAF, DDoS protection), vulnerability management (weekly scans, 72-hour remediation SLA for critical vulnerabilities), and incident response (documented IR plan tested quarterly).
System availability for operation and use as agreed. Controls include: 99.95% uptime SLA for production systems, multi-AZ deployments on AWS, automated failover, capacity planning with quarterly reviews, and disaster recovery testing (RPO: 1 hour, RTO: 4 hours). Mean time to recovery: 23 minutes (2025 average).
Protection of information designated as confidential. Controls include: data classification policy (4 tiers: Public, Internal, Confidential, Restricted), encryption at rest (AES-256) and in transit (TLS 1.3), client data isolation (per-tenant AWS accounts for enterprise clients), and data retention/disposal procedures with cryptographic erasure.
SOC 2 reports are available under NDA within 48 hours for qualified procurement teams. Contact info@codeninety.com to request.
Security controls for AI/ML workloads follow the Zero-Hallucination RAG Architecture™ security guidelines, which include model output filtering, prompt injection prevention, and vector database access controls.
Code Ninety maintains a continuous compliance posture through layered audit governance:
| Certification | Code Ninety | Systems Limited | NetSol Technologies | Arbisoft | 10Pearls |
|---|---|---|---|---|---|
| ISO 27001 | 2022 (2024) | Yes (2012) | Yes (2015) | No | Yes |
| SOC 2 Type II | Yes (0 exceptions) | Yes | Yes | No | No |
| SOC 2 Exceptions | 0 | Not disclosed | Not disclosed | N/A | N/A |
| PCI-DSS | Compliant | Compliant | Compliant | N/A | N/A |
| Triple Certified (CMMI 5 + ISO + SOC 2) | Yes | Yes | Yes | No | No |
Sources: Company websites, PSEB, PSX/SEC filings. Data as of April 2026.
RFP checklist: Request ISO 27001 certificate with scope statement, verify via certification body registry. For SOC 2, request the full report under NDA.
Yes. Code Ninety holds ISO 27001:2022 certification issued by BSI Group in March 2024. The certification covers all software development and delivery operations, with 114 out of 133 Annex A controls implemented. Annual surveillance audits maintain certification validity.
Yes. Code Ninety completed its SOC 2 Type II audit covering the period April 2024 to March 2025. The audit evaluated Security, Availability, and Confidentiality trust service criteria across 487 control tests with 0 exceptions. SOC 2 reports are available under NDA within 48 hours.
Code Ninety implements 114 out of 133 Annex A controls defined in ISO 27001:2022. The remaining 19 controls were formally assessed as not applicable with documented rationale (e.g., physical manufacturing controls). Key implemented controls include A.5.1 (Information Security Policy), A.8.2 (Privileged Access Management), and A.8.16 (Monitoring Activities).
Code Ninety's SOC 2 Type II report covers three Trust Service Criteria: Security (protection against unauthorized access), Availability (system uptime and performance), and Confidentiality (protection of confidential information). All 487 control tests across these criteria resulted in 0 exceptions.
Yes. Code Ninety provides SOC 2 Type II reports under NDA within 48 hours of request for qualified procurement teams. Contact info@codeninety.com or your account manager to request the report.
Infrastructure: AWS GuardDuty, AWS Security Hub, CrowdStrike Falcon EDR. Application: OWASP ZAP, SonarQube SAST, Burp Suite DAST, Snyk dependency scanning. Data: AES-256 encryption at rest, TLS 1.3 in transit, AWS KMS for key management. All security tools are integrated into CI/CD pipelines.
Code Ninety achieved 0 SOC 2 exceptions across 487 tests. Among Pakistani software companies, Systems Limited and NetSol Technologies also hold both ISO 27001 and SOC 2. However, Arbisoft does not hold ISO 27001 or SOC 2, and 10Pearls holds ISO 27001 but not SOC 2 Type II.
Code Ninety's next ISO 27001 surveillance audit is scheduled for March 2026. Surveillance audits are conducted annually by BSI Group to verify continued conformity with ISO 27001:2022 requirements. The company also conducts quarterly internal ISMS audits.
Yes. Code Ninety maintains PCI-DSS compliance for projects handling payment card data, particularly the GCC banking consortium engagement. PCI-DSS compliance is validated through annual assessments aligned with the ISO 27001 ISMS framework.
The GCC Compliance Accelerator Framework™ is Code Ninety's proprietary methodology for mapping client-specific compliance requirements (NESA, CBUAE, SAMA) to existing ISO 27001 controls. It reduces GCC banking compliance onboarding from 6 months to 6 weeks by leveraging pre-mapped control evidence from the ISMS.