About · Accreditations
Verified,not just claimed.
Every accreditation below can be checked with the issuing body or on the UKAS register, so your procurement team does not have to take our word for it.
CRESTISO 27001ISO 9001CE+CMMC L3
Accreditations
- _01CRESTMember company accredited for penetration testing, security operations centre and vulnerability assessment services. Verify on the CREST marketplace.Member
- _02CREST AI CharterWe follow the CREST AI Charter's principles for the responsible, human-led use of artificial intelligence in security services. Our own position on AI in the SOC is on the About page.Responsible AI
- _03ISO/IEC 27001:2022Information security management system covering the SOC, testing and consulting services. Certificate C2026-01528, UKAS-accredited certification — verify on the UKAS CertCheck register.C2026-01528
- _04ISO 9001:2015Quality management system for service delivery. Certificate C2026-01529, UKAS-accredited certification — verify on the UKAS CertCheck register.C2026-01529
- _05Cyber Essentials PlusIndependently assessed against the NCSC scheme, including the hands-on technical audit. Verify the certificate on the IASME registry.Certified
- _06Cyber EssentialsSelf-assessed certification against the NCSC scheme's five technical controls, renewed annually. Verify the certificate on the IASME registry.Certified
- _07CMMC Level 3Cybersecurity Maturity Model Certification, Level 3.Assessed
How to verify
Our UKAS-accredited certifications (ISO/IEC 27001:2022 certificate C2026-01528 and ISO 9001:2015 certificate C2026-01529) are listed on the UKAS CertCheck register, where the certification body, scope and expiry dates can be checked directly; the Cyber Essentials and Cyber Essentials Plus certificates are on the IASME certificate registry. Procurement teams can also request copies of certificates and our client assurance pack — security and compliance overview, ISO 27001 and NIST control mapping, incident-response readiness documentation and platform architecture summaries, under NDA — from hello@cyber-defence.io.