From Fragmented Structures to a Unified Security Standard
ISO 27001 for AI SaaS
DTI Group — an international, cross-industry technology partner – was facing significant pressure from customers.
An ISO 27001 certification would allow DTI to demonstrably strengthen its information security, meet critical customer requirements, and secure the foundation for future projects and long-term partnerships.
Together with Public Cloud Group as an equal partner, the certification was achieved in just eight months – across three countries, multiple locations, and an international team of 45 employees.
The result: compliant structures, a unified security level, strengthened customer trust, and measurable business impact – especially among customers for whom ISO 27001 is a decisive selection criterion.
Starting Situation & Objectives
DTI supports customers in security-critical industries – internationally, deeply technical, and with high quality standards.
With growth across Switzerland, Germany, and Italy, it became clear:
- Processes were evolving at different maturity levels
- Documentation varied widely
- Security standards differed by location
A stronger harmonization was necessary.
At the same time, the newly developed Al Saas product COGNAiO® Cloud Extract introduced additional requirements for coordination, documen-tation, and internationally aligned compliance and risk management.
Customer pressure increased – but so did op-portunity: A strategic customer required an external supplier audit such as ISO 27001. Another customer made ISO 27001 mandatory to integrate COGNAiO® Cloud Extract into its own software solution. Another customer made ISO 27001 mandatory to integrate COGNAiO® Cloud Extract into its own software solution. For DTI, this created a clear opportunity: win new SaaS customers through certification.
The goal was ambitious: Not a checkbox ISMS – but an international information security management system as a strategic success factor.
Our customers clearly communicated: To use our COGNAiO® Cloud Extract SaaS, they require ISO 27001 proof from us. The direction was obvious — do it. Now.
The challenge
What do you do when a customer suddenly demands ISO 27001 — and you have nothing to show?
- Three countries,
- different organizational structures,
- cultural and operational differences,
- high time pressure,
- ongoing daily operations,
- clear customer expectations.
DTI Schweiz AG had been ISO 9001-certified for eight years. This existing structure provided a strong foundation and was deliberately extended and rolled out internationally — covering the new management system both technically and organizationally, without unnecessary duplication of work.
Approach & role of Public Cloud Group
Public Cloud Group brought structure, speed, and certification expertise — especially in hyperscaler, SaaS, and AI environments. Using a lean and flexible approach, the project was adapted to team resources and maturity levels. The project plan was continuously fine-tuned depending on stakeholders, country, and availability. Through close alignment, clear responsibilities, and weekly cross-country meetings, the ISMS was built and certified in just eight months — faster than many national certification projects.
We knew we had to deliver. Our customers wanted the certificate — and we wanted to prove we operate fast, clean, and securely on an international level.
The result
The impact was immediate:
- Unified processes and management system across all locations
- Transparent and traceable decision paths
- Significantly more efficient change and audit processes
- Noticeably higher trust from customers and partners
- Competitive AI SaaS with structured security procedures
Business Impact
Yes – the certification had direct commercial value:
- Customers could only fully use COGNAiO® after receiving ISO 27001 proof → immediate business benefit and early product trust
- Several new customers confirmed the certification was decisive in their purchasing decision
ISO 27001 therefore directly influenced new business revenue. For DTI, ISO 27001 became the logical next step to operate COGNAO® Cloud Extract securely, reliably, and customer-ready – and to underline its innovation leadership in the IDP space. With clear structures, reduced risk, and measurable market trust, DTI has now strengthened the foundation for further growth.
Additional new customers joined who place great value on certification. So yes — the ISO 27001 investment paid off economically.
Key Achievements at a Glance
-
ISO 27001 certification across three countries in just a few months
-
Existing ISO 9001 used as implementation foundation
-
Unified processes and responsibilities across locations
-
Access to new projects and SaaS customers requiring ISO 27001
-
Increased trust and long-term customer retention
-
Greater transparency, lower risk, better collaboration
About PCG
Public Cloud Group (PCG) supports companies in their digital transformation through the use of public cloud solutions.
With a product portfolio designed to accompany organizations of all sizes in their cloud journey and competence that is a synonym for highly qualified staff that clients and partners like to work with, PCG is positioned as a reliable and trustworthy partner for the hyperscalers, relevant and with repeatedly validated competence and credibility.
We have the highest partnership status with the three relevant hyperscalers: Amazon Web Services (AWS), Google, and Microsoft. As experienced providers, we advise our customers independently with cloud implementation, application development, and managed services.