Skip to content
Partenariat - Data Guardians x Label Cyber Safe

Cyber-Safe Label and ISO 27001 certification: do you have to choose?

Data Guardians is now an official partner of the Swiss Cyber-Safe label, a cybersecurity label designed for SMEs and public administrations. This is an opportunity to answer a question our clients frequently ask: is it better to invest in a cybersecurity label or in a certification? The answer is quite simple: they are two very different but complementary things — and your organisation probably needs both.

Why this partnership?

The Cyber-Safe label, created in 2018 and operated by the Swiss Association for the Cybersecurity Label (ASLaC), is recognised by the Swiss Confederation: Cyber-Safe is an implementation partner of the national cyberstrategy of the Federal Office for Cybersecurity (FOCS).

As an official partner of the label, Data Guardians steps in at three key stages: the initial gap analysis against the label’s requirements, the support provided to meet those requirements and, finally, the implementation of any corrective measures identified by the auditors.

This partnership is therefore a natural extension of our ISO 27001 certification support. As our CEO, Mahandry Rambinintsoa, put it: “The two approaches do not replace one another, they reinforce one another. ISO 27001 structures information security governance; Cyber-Safe puts the organisation to the test in the field”.

Label or certification: what are the differences?

The confusion is still common, including within the boards of Swiss organisations. Let’s clear it up.

A certification, such as ISO 27001, attests that a management system exists and is actively steered. Following a risk-based approach, the auditor assesses whether the measures are appropriate to the context of the organisation: there is genuine room for interpretation, and two companies can both be compliant with different set-ups. It is proof of governance, valid for 3 years with annual surveillance audits.

A label, such as Cyber-Safe, records results. Each requirement, concrete and predefined, is either met or not: it is black or white — the auditor ticks the box, or doesn’t. It is proof from the field, valid for 2 years.

The real difference: certification assesses the adequacy of a system (with judgement), while the label verifies the achievement of criteria (with no room for negotiation).

As a result, neither of the two stands “above” the other, because they do not measure the same thing: the first verifies that security is designed and steered, the second that it is tested and effective.

What do they actually verify?

To shed some light on the concrete requirements of these two options, Data Guardians has put together the following comparison:

ISO/IEC 27001 Certification Cyber-Safe Label
Nature International standard for information security management systems (ISMS) Swiss cybersecurity label, operated by ASLaC
Philosophy Is security governed, documented and continuously improved? Does the organisation have a minimum level of security today?
Assessment logic Audit of the system: processes, documentation, evidence of operation Verification that each security criterion set by the label is met
Example: vulnerability management A vulnerability management process is required, applied and audited. The procedure doesn’t matter: internal and external scans are performed, and thresholds are set on the results that must not be exceeded.
Example: awareness An awareness programme is required. Phishing campaigns carried out within a set timeframe; thresholds are set on the results that must not be exceeded.
Validity Certificate valid for 3 years, with annual surveillance audits. Label valid for 2 years; requirements are tightened at the next audit.
Recognition International benchmark, often required contractually (IT, finance, healthcare, etc.). Recognised by the Swiss Confederation (implementation partner of the FOCS National Cyber Strategy), supported by certain insurers and umbrella organisations.
Primary target Organisations of all sizes, across all sectors. SMEs and public administrations (organisations from 3 to 248 employees labelled to date).
What it proves Security that is designed, structured and sustainable. Security that is tested and effective in the field.

How are they complementary?

An ISO 27001 certification audit assesses your management system, not your attack surface. The auditor will run neither vulnerability scans nor phishing campaigns as part of the audit. An ISO 27001-certified organisation may therefore, at a given point in time, have critical exploitable vulnerabilities.

Conversely, the Cyber-Safe label captures a solid security posture at a given moment, but does not structure governance over time. Risk management, steering and continuous improvement are specific to ISO 27001.

This is precisely why the two approaches are complementary and reinforce each other. One without the other can leave blind spots. Together, they give your clients, prospects and management what they are really asking for: security that is governed AND demonstrated.

How can Data Guardians support you?

Our team supports you across the entire journey: preparation for the Cyber-Safe Label and implementation of corrective measures, ISO 27001 certification support, awareness and phishing campaigns with DG Learning, and long-term steering through our managed DPO, CISO & ISMS Manager services and our Governance, Risk and Compliance tool: DGRC.

Wondering which of the two initiatives to launch first, or how to combine them? Let’s talk.

Share this article:

Privacy Policy Summary

This site uses cookies so that we can provide you with the best possible user experience. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team understand which sections of the site you find most interesting and useful.

To learn more, please see our privacy policy.