1. The short answer

Yes, but not merely by using GitHub. For ISO 27001, you must include the code forge in the scope, address its risks and retain evidence. For ENS ALTA in a SaaS environment, GitHub Enterprise Cloud provides components that Team does not offer, although acceptance depends on the exact service, contract, configuration, recognised evidence and auditor.

The rule that explains everything

A contracted capability is not an implemented control. An implemented control is not audited evidence. And the provider's certification is not the customer's certification.

2. The inherited certification trap

The most common misconception is that because GitHub holds certifications and runs on Azure, that conformity already covers your project. It does not. A certification protects the specific boundary that was assessed. It does not automatically extend inwards.

Specific Microsoft or Azure services or regions being within an ENS scope does not cover GitHub through corporate ownership or use of their infrastructure. The provider's certification also does not cover your tenant, configuration or service delivery system. GitHub must be identified and treated as a supplier or dependency in the scope, risks and evidence.

Diagram of four separate boundaries (Microsoft and Azure, the GitHub service, the customer's tenant and the certified system) showing that an external certification does not carry over inwards.
Each boundary requires its own evidence. An external certification does not carry over to the customer's system.

3. The five steps of evidence

Demonstrating compliance means climbing five steps. Most organisations stop at the second, the provider step, and confuse what GitHub states with what they can prove.

Five-step staircase: regulation, provider, contract, tenant and auditor, with the provider highlighted because many organisations stop there.
From regulation to the auditor. Certification requires completing the entire staircase with traceable evidence.

The leap that almost nobody makes is from the Provider step to the Tenant step: moving from what GitHub promises to what you have actually configured, logged and made recoverable. This is where a low-cost plan reaches its limits.

4. What GitHub Team does not let you demonstrate

GitHub Team is not insecure. It supports private repositories, 2FA, roles, repository rules and reviews. For an ENS ALTA system, the issue is not the provider's security, but your ability to demonstrate governance, traceability, jurisdiction and recovery. These are the most significant gaps.

Dimension GitHub Team Enterprise Cloud (EU + EMU)
IdentityPersonal accounts, without EMU, SAML or SCIM.Users managed through your IdP, SAML or OIDC and SCIM.
Audit180 days and manual export, without an API.API and audit streaming to your SIEM.
ResidencyNo selectable region for GitHub.com.Code and primary data in the EU, with exceptions.
NetworkNo enterprise IP allow list.Network-based access restrictions.
SLANo standard Enterprise SLA.Availability commitment with service credits.
BackupInternal resilience, without your own complete logical backup.External independent backup depends on risks, RPO, RTO and shared responsibility.
Code securitySecret Protection and Code Security as add-ons.Central governance, although advanced features remain add-ons.
Cloud evidenceNo identified recognised certificate for the service.More evidence, but ENS conformity remains conditional.

It can form part of a well-managed ISO 27001 ISMS. As a target state for ENS ALTA, based on the publicly available evidence, it is not sufficient on its own.

5. What changes with GitHub Enterprise Cloud

As at 22 July 2026, within GitHub's analysed public SaaS offering, Enterprise Cloud with EU data residency and Enterprise Managed Users is the only plan bringing these components together. Features, retention, SLAs, residency and add-ons may change.

1Corporate identity

Accounts managed through your IdP, SAML or OIDC and SCIM for effective user provisioning and deprovisioning.

2EU data residency

Code and primary data in the European Union, with documented exceptions.

3Audit data sent to your SIEM

API and log streaming to collect, retain and correlate events.

4Network boundary

An IP allow list to enforce the same access restrictions as the rest of the system.

5SLA and contract

An availability commitment and a stronger contractual basis for negotiation.

6More evidence

SOC 1, SOC 2 Type II, CSA STAR and additional business continuity documentation.

6. Enterprise provides components, not certificates

Buying Enterprise does not certify you. ISO 27001 certifies the ISMS within a defined scope. ENS certifies the conformity of the systems included.

ISO 27001

Viable with sound judgement

It does not require a particular brand or plan. Even Team can form part of a certified ISMS if you address risks, control identity, logs and backups, and retain evidence. Enterprise reduces the evidential burden.

ENS ALTA

Conditional

At category ALTA, the op.nub.1 enhancement requires information systems supporting third-party cloud services to conform to ENS or hold an equivalent certification whose procedure is recognised by the CCN Certification Body. Enterprise helps, but acceptance depends on the exact service, contract, configuration and auditor.

As at 22 July 2026, I have not found sufficient public evidence of a recognised certificate identifying the assessed GitHub service, region and scope. It must be requested and verified, not assumed.

7. If the evidence is unavailable, change the scope

If you cannot obtain recognised evidence for the exact service, you still have options. There are two routes, and neither is automatic.

Option A

Another cloud service that does provide recognised certification for your category, together with its contract and configuration.

Option B

A code forge included in the scope of a system with category ALTA ENS certification or contracted as a service delivered through that system. Self-hosting does not confer automatic conformity: you assume responsibility for patching, hardening, high availability, backups, keys, logs, physical security and continuous operations.

The most defensible architecture separates GitHub from direct production access, builds on controlled runners, signs artefacts, and moves logs and backups outside the GitHub domain. That way, a repository compromise does not bring down your system.

8. Annexes supporting the decision

These annexes summarise the material underpinning the analysis. They help frame specific questions for the provider and the auditor.

Levels of evidence

LevelWhat it means
NRegulation. An obligation established by an official source.
VProvider. A capability or commitment stated by GitHub.
CContract. A verified obligation in the signed agreement.
TTenant. A control verified in your actual environment.
AAuditor. Formal acceptance by the certification body.

Ten due diligence questions for GitHub

  1. A certificate recognised by the CCN for the exact service, region and scope, if one exists.
  2. Current ISO 27001 and SOC 2 Type II certifications, including scope, entity, locations and exclusions.
  3. A location map covering code, logs, backups, support and telemetry.
  4. A list of subprocessors, countries, and the change and notification mechanism.
  5. Encryption, key management, rotation and customer-managed key options.
  6. RPO and RTO for each component and recent recovery test results.
  7. Available events, retention, delivery to the SIEM and recovery after disruption.
  8. The notification period for code compromises, not only personal data breaches.
  9. Audit rights, cooperation with the certification body and access to forensic evidence.
  10. Portability of all assets and a real exit migration test.
Frequently asked questions

Frequently asked questions

Can I keep my code in GitHub and get ISO 27001 certified?

Yes. ISO 27001 does not mandate a platform or plan. GitHub is identified and treated as a supplier or dependency within the ISMS scope, risks and evidence. Team does not rule it out on its own, although Enterprise reduces identity, audit, oversight and evidence effort.

Is GitHub Team enough for a high category ENS system?

As a target state, with the public evidence available, it is not enough on its own. It lacks corporate identity, audit logs you can stream to your SIEM, selectable residency, a standard SLA and a full logical backup you can demonstrate. It can stay as a temporary transition with the residual risk accepted in writing and a migration date.

Does GitHub or Azure certification count for me?

It is not inherited. A certification covers the assessed provider boundary, not your tenant or service delivery system. Only the specific certified Microsoft or Azure services, regions and scopes count. GitHub must be treated in your scope, risks and evidence as a supplier or critical dependency.

What does GitHub Enterprise Cloud give me that Team does not?

Enterprise Managed Users with SAML or OIDC and SCIM, EU residency for code and main data, an API and audit log streaming to your SIEM, an IP allow list, an SLA with credits and broader evidence. External independent backup is decided from risks, RPO, RTO and shared responsibility.

Does buying Enterprise make me ENS high certified?

No. Enterprise brings the pieces, but it does not prove conformity on its own. Acceptance depends on the exact service, contract, configuration, an equivalent certification whose procedure is recognised by the CCN Certification Body and the auditor.

If I cannot obtain that recognised evidence, what do I do?

You have two paths. Move to another cloud service that does provide the recognised certification for your category, or use a code forge included in the scope of a system with a high category ENS certification. Self hosting does not grant automatic conformity: it moves patching, high availability, backup, keys, logs and continuous operation onto your team.

Next step

If this affects your project

Was this useful?

Share it with the person who decides where your code resides.

This analysis is intended for IT, security and senior management professionals working with the public sector or demanding clients.

LinkedIn

Official sources consulted

Cut-off date: 22 July 2026. Verify the links before an audit or procurement decision.

Note on evidence. Where no public documentation has been found, this should be understood as an absence of located evidence, not as an absolute assertion that none exists.

Initial assessment

Does your critical code need to withstand audit scrutiny?

I can review where your code resides, what evidence you lack and which architecture enables you to demonstrate compliance without oversizing the project.