Skip to main content

How Staff WiFi Helps You Meet ISO/IEC 27001: Mapping Annex A Controls to Your Wireless Network

You will be able to decide whether your staff WiFi can evidence 12 ISO/IEC 27001:2022 Annex A controls, including A.5.15, A.8.5 and A.8.22. You will also be able to replace a shared WPA2-PSK key with IEEE 802.1X and dynamic VLANs. Finally, you can assemble the RADIUS logs, segregation tests and supplier records an auditor accepts at stage 2.

By Iain JewittPublished
📖 14 min read3,181 words2 worked examples12 key definitions

Video overview

Part of our core series: Guest WiFi Guide →

A staff WiFi network built on the IEEE 802.1X standard and integrated with Microsoft Entra ID produces audit evidence for 12 ISO/IEC 27001:2022 Annex A controls. These include A.5.15 access control, A.8.5 secure authentication and A.8.22 segregation of networks. Individual authentication, role-based VLAN assignment, encrypted transport and centralised RADIUS logs produce the records an auditor accepts. A shared WPA2-PSK password produces none of them.

What does ISO 27001 ask of your staff WiFi?

Your staff WiFi is the foundation of any wireless compliance posture. It carries the devices that reach your property management system, point of sale, rota software and email. Purple Staff WiFi replaces shared passwords with Identity-Based Networks. Each person authenticates with their own credential, and every connection is logged against a named identity. Guest and tenant networks sit on top of that foundation. They never replace it.

ISO/IEC 27001:2022 never mentions wireless by name. It requires you to run an information security management system (ISMS). You must justify every Annex A control in your Statement of Applicability (SoA). Annex A lists 93 controls in four themes: organisational, people, physical and technological. Your staff WiFi touches the organisational (5.x) and technological (8.x) themes most directly.

Policy versus evidence

Your stage 1 audit reviews documentation. At stage 2, and at every surveillance audit, the auditor tests whether controls actually operate. A policy that says "staff WiFi access is restricted to authorised personnel" is a statement of intent. A RADIUS log showing a named person authenticated at 08:14 and was placed on the finance VLAN proves the control works.

That gap catches many organisations. The wireless policy is sound, but the network cannot produce a record of who connected. You end up with a minor nonconformity against A.5.15 or A.8.5, and a corrective action plan to deliver before the next visit.

Why does a shared WiFi password fail the audit?

How WPA2-PSK fails the A.8.5 authentication test

A.8.5 requires secure authentication technologies and procedures, based on access restrictions and your access control policy. WPA2-Personal, usually called WPA2-PSK, authenticates a device, not a person. Everyone who knows the pre-shared key derives encryption keys from the same secret. The network has no way to tell a store manager from a contractor who left last spring.

Three failures follow from that design:

  • No individual identity. Logs show a MAC address, not a person. MAC addresses are randomised by default on current iOS and Android releases, so even device attribution is unreliable.
  • No clean revocation. Removing one leaver means changing the key for everyone at the site. Most teams postpone it, so the key outlives several staff turnovers.
  • Offline attack exposure. An attacker who captures a WPA2 four-way handshake can attempt to guess the key offline. Weak or long-lived keys fall to that attack.

WPA3-Personal replaces the handshake with Simultaneous Authentication of Equals (SAE), which resists offline dictionary attacks. It still uses one shared password. It fixes the cryptography but not the identity problem, so it still fails A.5.16 and A.8.5 for staff access.

How 802.1X gives you individual accountability

IEEE 802.1X is port-based network access control. The access point blocks traffic until an authentication server approves the device. That server speaks RADIUS (Remote Authentication Dial-In User Service, RFC 2865). The credential exchange runs inside an Extensible Authentication Protocol (EAP) method.

The two methods you will meet most often:

  • EAP-TLS. Both sides present certificates. There is no password to phish or share, so it gives the strongest identity evidence.
  • EAP-TTLS. The server presents a certificate and builds a TLS tunnel. The client then sends its credential inside that tunnel. Purple's published Staff WiFi configurations for Juniper Mist and Cisco Meraki use EAP-TTLS.

Either way, the RADIUS server records an identity for every session. RADIUS accounting (RFC 2866) adds session start, interim updates and stop records. Each record carries the authenticated name, the access point identifier, the device MAC and the assigned IP address. Join those to your firewall logs and you can attribute a connection to a named person. That chain is the accountability an auditor looks for.

Which authentication method passes which control?

Method Individual identity (A.5.16) Secure authentication (A.8.5) Single-person revocation Per-role segregation (A.8.22) Where it fits
WPA2-PSK No - shared key Fails No - rotate key for everyone Separate SSID per role Legacy devices only, isolated VLAN
WPA3-Personal (SAE) No - shared password Fails for staff access No - rotate password for everyone Separate SSID per role Small sites with no RADIUS
iPSK (per-device or per-group key) Per key holder Partial - key, not person Yes - delete one key Yes - VLAN per key Tenant isolation, headless devices
WPA2-Enterprise (802.1X) Yes - named identity Passes Yes - disable the account Yes - dynamic VLAN Default for staff WiFi
WPA3-Enterprise (802.1X) Yes - named identity Passes Yes - disable the account Yes - dynamic VLAN High-assurance estates, new builds

How does staff WiFi map to each Annex A control?

The table below maps the 12 controls a wireless network most often evidences. Use it as the starting point for the wireless rows in your SoA.

Annex A control Wireless implementation Artefact the auditor will accept
A.5.15 Access control 802.1X on the staff SSID, policy linking roles to network access Access control policy plus RADIUS accept and reject logs
A.5.16 Identity management Accounts sourced from your identity provider, one identity per person Joiner, mover and leaver records matched to RADIUS identities
A.5.17 Authentication information Certificates or directory credentials, no shared WiFi password Credential issuance procedure, certificate inventory
A.8.2 Privileged access rights Admin group mapped to a management VLAN, separate from general staff RADIUS policy export showing the admin role and its members
A.8.3 Information access restriction Role-to-VLAN mapping, firewall ACLs per VLAN VLAN and ACL configuration, connectivity test results
A.8.5 Secure authentication WPA2-Enterprise or WPA3-Enterprise with EAP-TLS or EAP-TTLS WLAN configuration export, EAP method in use
A.8.16 Monitoring activities RADIUS accounting with interim updates, failed-login alerting Sample accounting records, alert rules, review sign-off
A.8.20 Networks security Controller-managed SSIDs, rogue access point detection Network diagram, WLAN inventory, rogue AP report
A.8.21 Security of network services Cloud RADIUS from a certified supplier, RadSec transport Supplier ISO 27001 certificate, service agreement
A.8.22 Segregation of networks Staff, guest and device traffic on separate VLANs VLAN design, inter-VLAN test showing blocked traffic
A.8.23 Web filtering Staff VLANs routed through your firewall or DNS filter Filtering policy and logs keyed to VLAN or identity
A.8.24 Use of cryptography AES encryption over the air, TLS for RADIUS transport Cryptography policy, WLAN cipher settings, RadSec certificate

Identity and authentication: A.5.15, A.5.16, A.5.17 and A.8.5

These four controls stand or fall together. The auditor picks a sample of leavers from your HR system and asks you to show their WiFi access ended. With 802.1X tied to your directory, disabling the account ends future authentications. Purple integrates with Microsoft Entra ID, Okta and Google Workspace, so joiners, movers and leavers flow from the system you already manage.

Bring the RADIUS reject logs for those sampled leavers. A reject with a timestamp after the leaving date is clean evidence.

Privileged and restricted access: A.8.2 and A.8.3

Your network engineers need access to switch and controller management interfaces. Front-desk staff do not. Map the IT administrator group to a management VLAN, and every other role to a VLAN that cannot reach management addresses. The RADIUS policy itself becomes your privileged access evidence, because it lists exactly which group receives which network.

Network controls: A.8.20, A.8.21 and A.8.22

A.8.21 covers the services you rely on, including cloud RADIUS. Standard RADIUS over UDP protects only the password attribute, using an MD5-based scheme. RadSec (RFC 6614) wraps the whole RADIUS exchange in TLS. Purple's Staff WiFi configurations use RadSec between your access points and Purple's cloud RADIUS. On Juniper Mist you add a RadSec certificate at organisation level, as the Staff WiFi - Juniper Mist support article describes.

For the supplier side of A.8.21, Purple holds ISO 27001 and Cyber Essentials certification. Purple reports 99.999% platform uptime. Ask for the current certificate and keep it with your supplier records.

Evidencing segregation on a single SSID (A.8.22)

Auditors often assume segregation means one SSID per network. It does not. With 802.1X, the RADIUS server returns VLAN attributes in the Access-Accept message, as defined in RFC 3580. The access point places each person on their role's VLAN, even though everyone joined the same SSID.

To evidence it, produce three things:

  1. The role-to-VLAN mapping table from your RADIUS policy.
  2. Firewall rules showing which VLANs may talk to which.
  3. A dated test: a device on the general staff VLAN attempts to reach the finance subnet and fails.

One SSID also reduces airtime overhead from beacons. Fewer broadcast networks help capacity planning in dense venues.

Monitoring, filtering and cryptography: A.8.16, A.8.23 and A.8.24

For A.8.16, RADIUS accounting gives you session-level records. Purple's Staff WiFi - Cisco Meraki configuration enables accounting servers with interim updates. Pair those records with a documented review: who looks at repeated authentication failures, how often, and what triggers escalation. A.8.15 logging sits alongside this control and draws on the same records.

A.8.23 web filtering happens at your firewall or DNS filter, not on the WiFi. Staff WiFi contributes the VLAN or identity your filter keys on, so policy can differ for kitchen tablets and head office laptops.

For A.8.24, WPA2-Enterprise and WPA3-Enterprise encrypt traffic over the air with AES. WPA3-Enterprise also mandates Protected Management Frames (IEEE 802.11w). Its 192-bit mode uses GCMP-256 with EAP-TLS for the highest assurance. Note the cipher suite in your cryptography policy.

Revocation through RFC 5176 CoA

Disabling an account stops the next authentication. It does not always end a live session. RADIUS Change of Authorization (CoA), defined in RFC 5176, lets the server send a Disconnect-Request to end a session immediately. It can also send a CoA-Request to move it to another VLAN.

Check what your deployment actually does. Purple's published Cisco Meraki configuration leaves RADIUS CoA support disabled. Confirm with Purple how immediate revocation is handled on your estate before you write it into your control description. Auditors test what you claim, so claim only what runs.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.

What does this look like on a live estate?

Worked scenario: a three-property hotel group

Situation. A hotel group running three properties of around 200 rooms each received a minor nonconformity at surveillance. The staff WiFi used one WPA2-PSK key across all sites, unchanged for 18 months. Around 140 staff, including agency housekeepers, knew it.

What was done. The group moved staff WiFi to WPA2-Enterprise with 802.1X on its existing access points, with RadSec to cloud RADIUS. Accounts came from the group's directory. Reception, housekeeping, finance and IT each mapped to their own VLAN on a single SSID. The guest network stayed separate.

Outcome. At the follow-up audit, 100% of sampled staff sessions traced to a named person. The auditor sampled five leavers, and each showed a RADIUS reject after their leaving date. The nonconformity closed. Removing a leaver dropped from re-keying three sites to disabling one account. See how Purple works across Hotels.

Worked scenario: a 60-store retail chain

Situation. A 60-store chain held ISO 27001 certification and also fell under PCI DSS v4.0. Each store broadcast three staff SSIDs: one for handheld scanners, one for manager laptops, one for staff phones. Segregation evidence was a diagram nobody had tested.

What was done. The chain collapsed the three SSIDs into one 802.1X staff SSID with dynamic VLAN assignment. Legacy scanners that could not run 802.1X moved to an isolated VLAN with tightly scoped firewall rules. The security team ran a dated segregation test in a sample of stores.

Outcome. Staff SSIDs per store fell from three to one. The same segregation test results served the A.8.22 evidence pack and PCI DSS segmentation testing under Requirement 11.4.5. One test now fed two audits. Read more on Retail deployments.

The pattern repeats in other regulated estates. Ward staff in Healthcare and onboard crew on Trains need the same named-identity evidence.

Where does staff WiFi sit alongside guest and multi-tenant networks?

Does the same control set apply to guest WiFi?

Partly. If guest WiFi shares physical infrastructure with your staff network, it falls inside your ISMS scope for A.8.20 and A.8.22. The auditor will want proof that a guest cannot reach staff or payment systems. That is a segregation question, answered with the same VLAN and firewall evidence.

Guest WiFi also raises A.5.34, privacy and protection of personal information, because it collects visitor data. GDPR governs that data. Purple's SecurePass add-on gives guest networks encrypted, individually authenticated access, which strengthens the guest side of the same audit. Auditors usually ask about both networks in one sitting, so prepare both evidence packs together.

Staff WiFi at a conference centre, airport or mixed-use building often serves several organisations. Each may run its own ISMS. Identity PSK (iPSK) gives each tenant organisation its own key, and RADIUS maps that key to the tenant's VLAN. Purple's Multi-Tenant WiFi uses iPSK as the isolation mechanism.

Know the trade-off. iPSK isolates tenants from each other cleanly, which evidences A.8.22. Within a tenant it identifies a key, not a person. For a tenant's own staff, 802.1X remains the stronger answer to A.8.5.

What are the limits you should know about?

EAP-TTLS depends on certificate validation. In a TTLS tunnel, the client sends its credential once the tunnel is up. If devices accept any server certificate, an attacker running a rogue access point can harvest credentials. Push the trusted server certificate to managed devices through your mobile device management platform. Record that in your A.8.5 evidence.

WPA2 is still in the published configuration. Purple's documented Juniper Mist and Cisco Meraki setups specify WPA2-Enterprise. WPA2-Enterprise satisfies A.8.5 when paired with a sound EAP method. If your risk assessment calls for WPA3-Enterprise, confirm support for your hardware and client base first.

Staff WiFi does not cover every control. It evidences technical controls. Physical controls such as A.7.8, equipment siting, and people controls such as A.6.3, security awareness training, need their own evidence.

Logs are personal data. RADIUS records hold names, device identifiers and timestamps. Define a retention period, a lawful basis under GDPR and an access list for the logs. ISO 27001 sets no fixed retention period, so you must set one and follow it.

Your supplier's certificate is not yours. Purple's ISO 27001 certification supports your A.8.21 supplier evidence. It does not certify your ISMS.

What should you do before your stage 2 audit?

Work through this list six to eight weeks before the auditor arrives:

  1. List every SSID on the estate, with its security type and VLAN. Retire any shared-key staff SSID or justify it in the SoA.
  2. Export the RADIUS policy showing each role, its VLAN and its members.
  3. Pull five leaver records from HR and match each to a RADIUS reject after the leaving date.
  4. Run a dated segregation test from the staff, guest and device VLANs, and screenshot the blocked attempts.
  5. Sample a week of accounting records and show the review that followed.
  6. File supplier evidence for your cloud RADIUS provider, including the ISO 27001 certificate.
  7. Check client certificate validation on a sample of managed devices.

If you are still on a shared password, start with the WLAN change. Purple publishes step-by-step guides for Juniper Mist and Cisco Meraki. For the wider enterprise pattern on other vendors, see How to Configure WPA2-Enterprise on Common Access Point Platforms (Cisco, Aruba, Ubiquiti).

See also: Purple Staff WiFi, the foundation for your wireless compliance posture, with SecurePass for guest networks and Multi-Tenant WiFi for shared estates.

Frequently asked questions

Does Purple Staff WiFi work with the access points we already own?

Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You change the WLAN profile to WPA2-Enterprise and point it at Purple's cloud RADIUS over RadSec. Purple publishes step-by-step Staff WiFi guides for Juniper Mist and Cisco Meraki. No rip and replace is required, so your audit evidence improves without a hardware project.

Will a shared WPA2-PSK staff password fail our ISO 27001 audit?

It is likely to draw a nonconformity against A.8.5 or A.5.16. A shared key authenticates devices, not people, so you cannot show which named person connected. You also cannot revoke one leaver without changing the key for everyone. Some organisations keep a PSK network for legacy devices that cannot run 802.1X. That works only on an isolated VLAN, with the exception justified in your Statement of Applicability.

Is Purple itself ISO 27001 certified?

Yes. Purple holds ISO 27001 certification, alongside Cyber Essentials, and operates as a GDPR-compliant platform. That supports your supplier evidence under A.8.21, security of network services, and A.5.19, information security in supplier relationships. Ask Purple for the current certificate and its scope, and file it with your supplier records. Remember that a supplier's certificate supports your ISMS but does not certify it.

Do we need WPA3-Enterprise to pass the audit?

No. ISO 27001 does not name a WiFi security standard. It asks you to choose controls that fit your risk assessment. WPA2-Enterprise with 802.1X and a sound EAP method satisfies A.8.5 and A.8.24 in most risk profiles. WPA3-Enterprise adds mandatory Protected Management Frames and an optional 192-bit mode. Choose it where your risk assessment or sector rules demand higher assurance, and confirm your client devices support it.

Does guest WiFi need to be inside our ISO 27001 scope?

Yes, wherever it shares infrastructure with your staff network or business systems. The auditor will test that guests cannot reach staff, payment or management networks under A.8.22. Guest WiFi also collects personal data, which brings in GDPR and A.5.34. Purple's SecurePass add-on gives guest networks individual, encrypted authentication. Prepare guest and staff evidence packs together, because auditors usually review both in the same session.

How much effort does moving from a shared password to 802.1X take?

The access point change is one WLAN profile in your controller dashboard, documented step by step in Purple's support guides. Most of the effort sits elsewhere. You map roles to VLANs, connect your identity provider and onboard staff devices. You also plan for legacy devices that cannot run 802.1X. Run a pilot at one site, capture evidence from it, and roll out to the rest of the estate once the pattern holds.

Can one staff SSID serve several companies on the same site?

Yes. Use identity PSK (iPSK) to give each tenant organisation its own key. RADIUS maps each key to that tenant's VLAN, so traffic stays isolated on a shared SSID. Purple's Multi-Tenant WiFi uses this approach. iPSK isolates tenants cleanly and evidences A.8.22. Within each tenant it identifies a key rather than a person, so 802.1X stays the stronger choice for individual staff authentication.

How do we prove a leaver lost WiFi access?

Disable the account in your identity provider, then show the RADIUS reject logs for any attempt after the leaving date. Purple integrates with Microsoft Entra ID, Okta and Google Workspace, so joiner, mover and leaver changes reach the network from your directory. Auditors typically sample several leavers from HR records. A timestamped reject after the leaving date gives them clean, attributable evidence under A.5.16 and A.5.18.

Key Definitions

IEEE 802.1X

The IEEE standard for port-based network access control. The access point blocks traffic until an authentication server, normally RADIUS, approves the device, with credentials exchanged inside an Extensible Authentication Protocol (EAP) method.

802.1X is what WPA2-Enterprise and WPA3-Enterprise use, and it is the mechanism that turns a staff SSID into named-identity evidence for A.5.15, A.5.16 and A.8.5.

RADIUS

Remote Authentication Dial-In User Service, defined in RFC 2865. The server accepts or rejects each authentication request and can return attributes in the Access-Accept message, such as the VLAN to assign.

RADIUS accept and reject logs are the core artefact for access control and leaver sampling, so your RADIUS policy export becomes audit evidence in its own right.

RADIUS accounting

Defined in RFC 2866, accounting adds session start, interim update and stop records. Each record carries the authenticated name, access point identifier, device MAC and assigned IP address.

Accounting records, joined to firewall logs, let you attribute a connection to a named person and provide the session-level evidence A.8.16 monitoring asks for.

EAP-TLS

An EAP method used with 802.1X in which both the client and the server present certificates, so no password exists to phish or share.

EAP-TLS gives the strongest identity evidence for A.8.5 and is required for the WPA3-Enterprise 192-bit mode, which uses GCMP-256.

EAP-TTLS

An EAP method in which the server presents a certificate and builds a TLS tunnel, and the client then sends its credential inside that tunnel.

Purple's published Staff WiFi configurations for Juniper Mist and Cisco Meraki use EAP-TTLS, which makes client validation of the server certificate a control you must evidence.

WPA3-Personal (SAE)

WPA3-Personal replaces the WPA2 four-way handshake with Simultaneous Authentication of Equals, which resists offline dictionary attacks, but it still relies on one shared password.

Teams often assume a WPA3 upgrade closes an audit finding. It fixes the cryptography but not the identity problem, so it still fails A.5.16 and A.8.5 for staff access.

Identity PSK (iPSK)

A per-device or per-group pre-shared key on a single SSID, with RADIUS mapping each key to its own VLAN.

iPSK isolates tenant organisations on shared estates and evidences A.8.22, but it identifies a key rather than a person, so 802.1X remains the stronger answer for A.8.5.

RadSec

RADIUS over TLS, defined in RFC 6614. It wraps the whole RADIUS exchange in TLS, whereas standard RADIUS over UDP protects only the password attribute with an MD5-based scheme.

RadSec between your access points and Purple's cloud RADIUS supports A.8.21 security of network services and A.8.24 use of cryptography, with the RadSec certificate as evidence.

Dynamic VLAN assignment

RFC 3580 defines how a RADIUS server returns VLAN attributes in the Access-Accept message, so the access point places each authenticated person on their role's VLAN.

Dynamic VLANs let one staff SSID evidence A.8.22 segregation and A.8.3 information access restriction, without broadcasting a separate SSID per role.

RADIUS Change of Authorization (CoA)

Defined in RFC 5176, CoA lets the RADIUS server send a Disconnect-Request to end a live session or a CoA-Request to move it to another VLAN.

Disabling an account stops the next authentication but may not end a live session. Purple's published Cisco Meraki configuration leaves CoA disabled, so confirm immediate revocation before you claim it.

Statement of Applicability (SoA)

The ISO/IEC 27001:2022 document in which you justify the inclusion or exclusion of each of the 93 Annex A controls across the organisational, people, physical and technological themes.

Your wireless rows in the SoA should map to the 12 controls staff WiFi evidences, and any retained shared-key network for legacy devices must be justified there.

Protected Management Frames

IEEE 802.11w protection for WiFi management frames, made mandatory by WPA3-Enterprise.

PMF is one reason to choose WPA3-Enterprise where your risk assessment calls for higher assurance, and the cipher suite should be recorded in your A.8.24 cryptography policy.

Worked Examples

A hotel group running three properties of around 200 rooms each received a minor nonconformity at surveillance. Staff WiFi used one WPA2-PSK key across all sites, unchanged for 18 months and known to around 140 staff, including agency housekeepers.

The group moved staff WiFi to WPA2-Enterprise with 802.1X on its existing access points, using RadSec to cloud RADIUS. Accounts came from the group's directory, so a shared key no longer stood in for identity. Reception, housekeeping, finance and IT each mapped to their own VLAN on a single SSID, while the guest network stayed separate. At the follow-up audit, 100% of sampled staff sessions traced to a named person. The auditor sampled five leavers, and each showed a RADIUS reject after their leaving date. The nonconformity closed, and removing a leaver dropped from re-keying three sites to disabling one account.

A 60-store retail chain held ISO 27001 certification and also fell under PCI DSS v4.0. Each store broadcast three staff SSIDs for handheld scanners, manager laptops and staff phones, and segregation evidence was an untested diagram.

The chain collapsed the three SSIDs into one 802.1X staff SSID with dynamic VLAN assignment, so RADIUS placed each device on its role's VLAN. Legacy scanners that could not run 802.1X moved to an isolated VLAN with tightly scoped firewall rules, rather than keeping a shared key on the main network. The security team ran a dated segregation test in a sample of stores. Staff SSIDs per store fell from three to one. The same test results served the A.8.22 evidence pack and PCI DSS segmentation testing under Requirement 11.4.5, so one test fed two audits.

Frequently asked questions

Does Purple Staff WiFi work with the access points we already own?

Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You change the WLAN profile to WPA2-Enterprise and point it at Purple's cloud RADIUS over RadSec. Purple publishes step-by-step Staff WiFi guides for Juniper Mist and Cisco Meraki. No rip and replace is required, so your audit evidence improves without a hardware project.

Will a shared WPA2-PSK staff password fail our ISO 27001 audit?

It is likely to draw a nonconformity against A.8.5 or A.5.16. A shared key authenticates devices, not people, so you cannot show which named person connected. You also cannot revoke one leaver without changing the key for everyone. Some organisations keep a PSK network for legacy devices that cannot run 802.1X. That works only on an isolated VLAN, with the exception justified in your Statement of Applicability.

Is Purple itself ISO 27001 certified?

Yes. Purple holds ISO 27001 certification, alongside Cyber Essentials, and operates as a GDPR-compliant platform. That supports your supplier evidence under A.8.21, security of network services, and A.5.19, information security in supplier relationships. Ask Purple for the current certificate and its scope, and file it with your supplier records. Remember that a supplier's certificate supports your ISMS but does not certify it.

Do we need WPA3-Enterprise to pass the audit?

No. ISO 27001 does not name a WiFi security standard. It asks you to choose controls that fit your risk assessment. WPA2-Enterprise with 802.1X and a sound EAP method satisfies A.8.5 and A.8.24 in most risk profiles. WPA3-Enterprise adds mandatory Protected Management Frames and an optional 192-bit mode. Choose it where your risk assessment or sector rules demand higher assurance, and confirm your client devices support it.

Does guest WiFi need to be inside our ISO 27001 scope?

Yes, wherever it shares infrastructure with your staff network or business systems. The auditor will test that guests cannot reach staff, payment or management networks under A.8.22. Guest WiFi also collects personal data, which brings in GDPR and A.5.34. Purple's SecurePass add-on gives guest networks individual, encrypted authentication. Prepare guest and staff evidence packs together, because auditors usually review both in the same session.

How much effort does moving from a shared password to 802.1X take?

The access point change is one WLAN profile in your controller dashboard, documented step by step in Purple's support guides. Most of the effort sits elsewhere. You map roles to VLANs, connect your identity provider and onboard staff devices. You also plan for legacy devices that cannot run 802.1X. Run a pilot at one site, capture evidence from it, and roll out to the rest of the estate once the pattern holds.

Can one staff SSID serve several companies on the same site?

Yes. Use identity PSK (iPSK) to give each tenant organisation its own key. RADIUS maps each key to that tenant's VLAN, so traffic stays isolated on a shared SSID. Purple's Multi-Tenant WiFi uses this approach. iPSK isolates tenants cleanly and evidences A.8.22. Within each tenant it identifies a key rather than a person, so 802.1X stays the stronger choice for individual staff authentication.

How do we prove a leaver lost WiFi access?

Disable the account in your identity provider, then show the RADIUS reject logs for any attempt after the leaving date. Purple integrates with Microsoft Entra ID, Okta and Google Workspace, so joiner, mover and leaver changes reach the network from your directory. Auditors typically sample several leavers from HR records. A timestamped reject after the leaving date gives them clean, attributable evidence under A.5.16 and A.5.18.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.