Certifications
The foundation of trust
Roche uses certifications to validate our high security standards.
Your trust in Roche solutions for clinical and business decisions requires confidence in our ability to secure data and the critical infrastructure managing it, supporting reliable operations and business continuity. Roche aims to build this trust and confidence by complying with recognised industry standards and best practices for security and quality.
For navify® solutions, we have chosen to certify our information security management system to the ISO/IEC 27k series (27001 / 27017 / 27018) as the foundation, adding local certificates as required to operate in those markets. For solutions that comply with this framework, cybersecurity and data privacy is implemented based on the following key tenants:
Based on risk assessments, navify solutions implement various technical, physical and administrative controls to mitigate risk.
Access to structured policies for continuous improvement and a leadership team to create, manage and deploy policies.
Safeguards the confidentiality, integrity and availability of data and systems.
*confidentiality, integrity and availability.
Manages security threats using risk assessment.
ISO 27001:2022
The standard specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). This internationally recognised framework helps organisations of any size or sector manage and mitigate their information security risks in a systematic, holistic way, focusing on the confidentiality, integrity and availability (CIA) of their data. Achieving certification demonstrates to customers and partners that the organisation adheres to global best practices for protecting its sensitive information.
ISO 27017:2015
The certification is supplemental to the ISO/IEC 27001 standard and helps organisations manage and mitigate cloud-specific information security risks, fostering trust and compliance in cloud environments.
ISO 27018:2019
The standard is a code of practice specifically for the protection of personally identifiable information (PII) within public cloud computing services. It provides cloud service providers (acting as PII processors) with controls and guidance to assess risks and implement measures for data privacy. Certification demonstrates a commitment to transparency and adherence to international best practices for safeguarding personal data in the cloud environment.
ISO 27701:2019
The international standard for privacy information management. It functions as an extension to the widely known ISO 27001 (information security), expanding its scope to specifically address the protection of personally identifiable information (PII).
While ISO 27001 focuses on keeping data secure (confidentiality, integrity, availability), ISO 27701 focuses on keeping data private (rights of the individual, consent and purposeful processing).
Cyber Essentials
Cyber Essentials is a UK government-backed certification standard requiring five baseline technical controls to protect organisations against common cyber threats.
Cyber Essentials Plus
Cyber Essentials Plus is a UK government cybersecurity certification that verifies five baseline controls through hands-on technical audits, including internal and external vulnerability scans, MFA checks, and simulated malware delivery performed by an accredited independent assessor.
Digital Security Protection Toolkit - Standards Exceededs
'Standards Exceeded' is the highest attainment level in the UK NHS Data Security and Protection Toolkit (DSPT), awarded to organisations that go beyond mandatory compliance requirements by demonstrating exemplary information governance and holding Cyber Essentials Plus.

At Roche, we follow strict data governance principles and privacy policies to ensure your information is secure and used only for its intended purpose. Our systems are designed to comply with global regulations and to safeguard your data at every step.