INFORMATION SECURITY & DATA PROTECTION
ISO/IEC 27001:2022 — Including 27017 and 27018
Our data center, the ISMS and our cloud and managed services are certified to ISO/IEC 27001:2022 — extended to include ISO/IEC 27017 (information security in the cloud) and ISO/IEC 27018 (protection of personal data in the cloud). The scope covers colocation services, cloud services and managed services at our Hanover site.
Since 2012, we have had the processes relating to our ISMS regularly audited by independent bodies — providing ongoing evidence of our commitment to information security in practice.
INFORMATION SECURITY & DATA PROTECTION
ISO/IEC 27017 — Information Security in the Cloud
The ISO/IEC 27017 extension supplements our ISMS with specific security measures for cloud environments.
It sets out how responsibilities are shared between the cloud provider and the customer, and ensures that our cloud services are operated in accordance with clearly defined security standards.
INFORMATION SECURITY & DATA PROTECTION
ISO/IEC 27018 — Data Protection in the Cloud
ISO/IEC 27018 sets out how personal data must be protected in cloud environments.
The certification confirms that GRASS-MERKUR meets strict data protection requirements when handling personal data in the cloud — an important assurance, particularly for customers with high compliance requirements.
SUSTAINABILITY & ENERGY
ISO 50001 — Energy Management
Our ISO 50001 certification demonstrates that we have a structured energy management system in place which continuously improves the efficient use of energy in our data center.
In this way, we combine cost-effective operation with the responsible use of resources.
Sustainability & Energy
ISO 14001 — Environmental Management
ISO 14001 confirms that our environmental impact is systematically monitored, assessed and continuously improved.
For our customers, this is clear evidence that sustainability is firmly embedded in GRASS-MERKUR’s operational processes.
AUTOMOTIVE SAFETY
TISAX — Information Security in Accordance with VDA ISA
TISAX is the information security standard defined by the automotive industry.
Successful certification demonstrates that sensitive information belonging to our customers and partners — particularly those in the automotive sector — is protected by us in accordance with recognized industry standards.
Sustainability & Energy
EcoZert — Excellence in Sustainability: ESG
GRASS-MERKUR was once again awarded the EcoZert sustainability seal in 2025. The award recognizes our ongoing commitment to environmentally friendly processes and sustainable development in the operation of data centers and IT infrastructure.
For our customers in the banking, insurance and public sectors, this provides further evidence that security of supply and environmental responsibility are not mutually exclusive at GRASS-MERKUR.
Sustainability & Energy
CrefoZert — Creditreform’s Creditworthiness Certificate
GRASS-MERKUR has been assessed by Creditreform Rating AG for many years and consistently meets the assessment criteria more than adequately.
The CrefoZert certifies the company’s financial stability and builds trust among customers and business partners.
Contact
Request a Security Consultation
Tell us about your project — we will get back to you with a concrete assessment.
Direct Line
GRASS-MERKUR GmbH & Co. KG
Rothwiese 5
30559 Hannover