ISO 27001
Certified information security management.
What it means for you
ISO 27001 is the international standard for information security management. Our certification means the way we handle data, manage risk and run our processes is independently audited against the highest benchmark.
- Independently audited security management system
- Rigorous handling of client and company data
- Continual risk assessment and improvement
- Assurance that supports your own compliance obligations
- 93Controls in ISO/IEC 27001:2022 Annex A
- ~3,300UK certificates across all sectors (ISO Survey 2024)
- 3 yearsCertificate cycle, with annual surveillance audits
What the standard covers
ISO/IEC 27001 is the leading international standard for information security management, currently in its 2022 edition. Certification means operating a full information security management system: risk assessment, leadership accountability and continual improvement, measured against 93 controls spanning organisational, people, physical and technological security.
Certification cannot be bought
A UKAS-accredited certification body audits the system in two stages before awarding the certificate, then returns for surveillance audits every year, with full recertification every three years. It is a standing discipline, not a plaque. Around 3,300 certificates exist across every sector of the UK economy, so it remains genuinely uncommon.
Why it matters when choosing an MSP
Your IT provider holds privileged access to your systems, data and identities, which makes the provider’s own security the hidden risk in every outsourcing decision. UK government research counts roughly 12,900 MSPs in the UK; only a small fraction hold accredited ISO 27001. Ours means the way we handle your environment is independently audited, every year.
The services this powers
ISO 27001, your questions answered
What is ISO 27001 in plain English?
It is the international benchmark for managing information security as a system, not a set of gadgets. A certified organisation has independently audited processes for assessing risk, controlling access, handling incidents and improving continuously, covering 93 controls in the current 2022 edition.
Why does our IT provider holding ISO 27001 matter to us?
Because your MSP holds the keys: admin access, your data, your identities. ISO 27001 certification means an accredited auditor independently verifies how we manage that responsibility, every year. It also strengthens your own position in client due diligence, GDPR accountability and insurance questionnaires.
Is ISO 27001 a one-off assessment?
No. Certificates run on a three-year cycle with mandatory annual surveillance audits in between, so the discipline has to hold continuously. Letting standards slip means losing the certificate.
More accreditations
Want ISO working for your business?
Book a free consultation and we’ll show you how it fits into a joined-up IT, security and print service.