05//Field note/3 min read

built on standards

We are ISO 9001 and ISO 27001 certified. What the audit actually asked for, what we had to change, and why a Kosovo studio bothered with the paperwork.

Brigada Group L.L.C. is now certified to ISO 9001:2015 for quality management and ISO/IEC 27001:2022 for information security. Audited and issued by Invicta Assurance International on 16 September 2026, certificates MTS-52567 and MTS-52568, covering the provision of information technology, software development, consulting and related professional services. Both PDFs are on brigada.dev/certifications, so you can read them rather than take the badge at face value.

The honest reason we did it: clients ask. Not the early-stage founders — the ones with a procurement process. A security questionnaire arrives, it has a line for your ISMS certification, and "we take security seriously" is not an answer to it. Once a deal has stalled on that line, the cost of the audit stops being a question.

The less obvious reason is the one worth writing down. A studio in Kosovo carries a reputational tax it did not earn. The engineering here is good, and everyone who has worked with us knows it, but a buyer in London or Boston comparing three vendors has no way to know it yet. An audit by an accredited third party is one of the few things that travels without us in the room.

What the audit actually asked for was less exotic than we expected, and more specific. Who has access to which client system, and who removed it when someone left. Where client data lives and which supplier touches it. What happens in the first hour of an incident, written down before the incident. How work gets specified, reviewed and corrected, and what we do when a delivery goes wrong rather than what we intend to do. Most of these we were already doing. The gap was almost always between doing a thing and being able to show we had done it every time.

So the real work was evidence, not invention. Access reviews on a schedule instead of when someone remembers. An incident response path with names in it. A supplier list that is current. A statement of applicability that says which controls apply and, more usefully, why the ones we excluded do not. None of that is glamorous, and all of it is the difference between a policy document and a system.

What certification is not: a guarantee that nothing will go wrong, or a substitute for engineers who care. It certifies the management system, not any single project. The three-year cycle with annual surveillance audits is the part that matters most — it means the evidence has to keep existing, not just exist the week an auditor visits.

Built on standards. Engineered for trust. brigada.dev/certifications.

Brigada.dev
Prishtinë, Kosovo
← Back to home
More from the journal
04two days with vector guestField note03ouroboros: the internship you win by out-thinking an AIHiring02slug-or-die: how we hired this quarterHiring