1. The short answer
Yes, but not merely by using GitHub. For ISO 27001, you must include the code forge in the scope, address its risks and retain evidence. For ENS ALTA in a SaaS environment, GitHub Enterprise Cloud provides components that Team does not offer, although acceptance depends on the exact service, contract, configuration, recognised evidence and auditor.
A contracted capability is not an implemented control. An implemented control is not audited evidence. And the provider's certification is not the customer's certification.
2. The inherited certification trap
The most common misconception is that because GitHub holds certifications and runs on Azure, that conformity already covers your project. It does not. A certification protects the specific boundary that was assessed. It does not automatically extend inwards.
Specific Microsoft or Azure services or regions being within an ENS scope does not cover GitHub through corporate ownership or use of their infrastructure. The provider's certification also does not cover your tenant, configuration or service delivery system. GitHub must be identified and treated as a supplier or dependency in the scope, risks and evidence.
3. The five steps of evidence
Demonstrating compliance means climbing five steps. Most organisations stop at the second, the provider step, and confuse what GitHub states with what they can prove.
The leap that almost nobody makes is from the Provider step to the Tenant step: moving from what GitHub promises to what you have actually configured, logged and made recoverable. This is where a low-cost plan reaches its limits.
4. What GitHub Team does not let you demonstrate
GitHub Team is not insecure. It supports private repositories, 2FA, roles, repository rules and reviews. For an ENS ALTA system, the issue is not the provider's security, but your ability to demonstrate governance, traceability, jurisdiction and recovery. These are the most significant gaps.
| Dimension | GitHub Team | Enterprise Cloud (EU + EMU) |
|---|---|---|
| Identity | Personal accounts, without EMU, SAML or SCIM. | Users managed through your IdP, SAML or OIDC and SCIM. |
| Audit | 180 days and manual export, without an API. | API and audit streaming to your SIEM. |
| Residency | No selectable region for GitHub.com. | Code and primary data in the EU, with exceptions. |
| Network | No enterprise IP allow list. | Network-based access restrictions. |
| SLA | No standard Enterprise SLA. | Availability commitment with service credits. |
| Backup | Internal resilience, without your own complete logical backup. | External independent backup depends on risks, RPO, RTO and shared responsibility. |
| Code security | Secret Protection and Code Security as add-ons. | Central governance, although advanced features remain add-ons. |
| Cloud evidence | No identified recognised certificate for the service. | More evidence, but ENS conformity remains conditional. |
It can form part of a well-managed ISO 27001 ISMS. As a target state for ENS ALTA, based on the publicly available evidence, it is not sufficient on its own.
5. What changes with GitHub Enterprise Cloud
As at 22 July 2026, within GitHub's analysed public SaaS offering, Enterprise Cloud with EU data residency and Enterprise Managed Users is the only plan bringing these components together. Features, retention, SLAs, residency and add-ons may change.
Accounts managed through your IdP, SAML or OIDC and SCIM for effective user provisioning and deprovisioning.
Code and primary data in the European Union, with documented exceptions.
API and log streaming to collect, retain and correlate events.
An IP allow list to enforce the same access restrictions as the rest of the system.
An availability commitment and a stronger contractual basis for negotiation.
SOC 1, SOC 2 Type II, CSA STAR and additional business continuity documentation.
6. Enterprise provides components, not certificates
Buying Enterprise does not certify you. ISO 27001 certifies the ISMS within a defined scope. ENS certifies the conformity of the systems included.
Viable with sound judgement
It does not require a particular brand or plan. Even Team can form part of a certified ISMS if you address risks, control identity, logs and backups, and retain evidence. Enterprise reduces the evidential burden.
Conditional
At category ALTA, the op.nub.1 enhancement requires information systems supporting third-party cloud services to conform to ENS or hold an equivalent certification whose procedure is recognised by the CCN Certification Body. Enterprise helps, but acceptance depends on the exact service, contract, configuration and auditor.
As at 22 July 2026, I have not found sufficient public evidence of a recognised certificate identifying the assessed GitHub service, region and scope. It must be requested and verified, not assumed.
7. If the evidence is unavailable, change the scope
If you cannot obtain recognised evidence for the exact service, you still have options. There are two routes, and neither is automatic.
Another cloud service that does provide recognised certification for your category, together with its contract and configuration.
A code forge included in the scope of a system with category ALTA ENS certification or contracted as a service delivered through that system. Self-hosting does not confer automatic conformity: you assume responsibility for patching, hardening, high availability, backups, keys, logs, physical security and continuous operations.
The most defensible architecture separates GitHub from direct production access, builds on controlled runners, signs artefacts, and moves logs and backups outside the GitHub domain. That way, a repository compromise does not bring down your system.
8. Annexes supporting the decision
These annexes summarise the material underpinning the analysis. They help frame specific questions for the provider and the auditor.
Levels of evidence
| Level | What it means |
|---|---|
| N | Regulation. An obligation established by an official source. |
| V | Provider. A capability or commitment stated by GitHub. |
| C | Contract. A verified obligation in the signed agreement. |
| T | Tenant. A control verified in your actual environment. |
| A | Auditor. Formal acceptance by the certification body. |
Ten due diligence questions for GitHub
- A certificate recognised by the CCN for the exact service, region and scope, if one exists.
- Current ISO 27001 and SOC 2 Type II certifications, including scope, entity, locations and exclusions.
- A location map covering code, logs, backups, support and telemetry.
- A list of subprocessors, countries, and the change and notification mechanism.
- Encryption, key management, rotation and customer-managed key options.
- RPO and RTO for each component and recent recovery test results.
- Available events, retention, delivery to the SIEM and recovery after disruption.
- The notification period for code compromises, not only personal data breaches.
- Audit rights, cooperation with the certification body and access to forensic evidence.
- Portability of all assets and a real exit migration test.
Frequently asked questions
Can I keep my code in GitHub and get ISO 27001 certified?
Yes. ISO 27001 does not mandate a platform or plan. GitHub is identified and treated as a supplier or dependency within the ISMS scope, risks and evidence. Team does not rule it out on its own, although Enterprise reduces identity, audit, oversight and evidence effort.
Is GitHub Team enough for a high category ENS system?
As a target state, with the public evidence available, it is not enough on its own. It lacks corporate identity, audit logs you can stream to your SIEM, selectable residency, a standard SLA and a full logical backup you can demonstrate. It can stay as a temporary transition with the residual risk accepted in writing and a migration date.
Does GitHub or Azure certification count for me?
It is not inherited. A certification covers the assessed provider boundary, not your tenant or service delivery system. Only the specific certified Microsoft or Azure services, regions and scopes count. GitHub must be treated in your scope, risks and evidence as a supplier or critical dependency.
What does GitHub Enterprise Cloud give me that Team does not?
Enterprise Managed Users with SAML or OIDC and SCIM, EU residency for code and main data, an API and audit log streaming to your SIEM, an IP allow list, an SLA with credits and broader evidence. External independent backup is decided from risks, RPO, RTO and shared responsibility.
Does buying Enterprise make me ENS high certified?
No. Enterprise brings the pieces, but it does not prove conformity on its own. Acceptance depends on the exact service, contract, configuration, an equivalent certification whose procedure is recognised by the CCN Certification Body and the auditor.
If I cannot obtain that recognised evidence, what do I do?
You have two paths. Move to another cloud service that does provide the recognised certification for your category, or use a code forge included in the scope of a system with a high category ENS certification. Self hosting does not grant automatic conformity: it moves patching, high availability, backup, keys, logs and continuous operation onto your team.
Official sources consulted
Cut-off date: 22 July 2026. Verify the links before an audit or procurement decision.
- Real Decreto 311/2022, Esquema Nacional de Seguridad
- CCN-STIC 825, ENS y certificaciones ISO 27001
- CCN-STIC 823, seguridad en entornos cloud
- ISO/IEC 27001:2022
- GitHub: planes y funcionalidades
- GitHub Enterprise Cloud con residencia de datos
- GitHub Enterprise Cloud: streaming del registro de auditoría
- GitHub: informes de cumplimiento
- GitHub Data Protection Agreement
- Microsoft: alcance ENS de los servicios
Note on evidence. Where no public documentation has been found, this should be understood as an absence of located evidence, not as an absolute assertion that none exists.
Does your critical code need to withstand audit scrutiny?
I can review where your code resides, what evidence you lack and which architecture enables you to demonstrate compliance without oversizing the project.