Is NVOY ISO 27001 certified?

Yes. NVOY holds ISO/IEC 27001:2022 certification for the provision of IT managed services, professional services and supply of IT equipment — certificate 21497ISMS001, issued by Alcumus ISOQAR under UKAS accreditation. You can verify it yourself on the UKAS CertCheck register rather than taking our word for it.

COMMITTED TO SAFETY

The Certificate

Standard - ISO/IEC 27001:2022

Certificate number - 21497ISMS001

Certification body - Alcumus ISOQAR

Accreditation - UKAS

Scope - The provision of IT managed services, professional services and supply of IT equipment

Verify

Team member presenting in front of task board, representing collaborative planning.

Why UKAS accreditation matters

Not every ISO 27001 certificate is accredited. Anyone can issue one, and plenty of certificates in circulation come from bodies nobody audits.

UKAS is the UK's national accreditation body. A UKAS-accredited certificate means the organisation that assessed us is itself assessed - that the audit met a defined standard rather than a commercial one.

It's the difference between a certificate and a certificate that means something. When you're comparing providers, ask who issued theirs and whether that body is accredited.

What our certification covers, and what it doesn't

Certification is always scoped. Ours covers the provision of IT managed services, professional services and the supply of IT equipment.

We say that precisely because scope gets stretched. A provider certified for one part of its operation will often imply the whole business is covered. Ours is published, numbered and independently checkable - so you don't have to take our description of it on trust.

Why it matters when you're choosing a provider

A managed IT provider holds administrator access to your systems, your identities and your data. That access makes them part of your attack surface.

Most providers will help you meet a standard. Fewer meet it themselves. It's a reasonable question to ask, and an awkward one for a provider who can't answer it with a number.

Certification isn't a guarantee of good service. What it does tell you is that there's a documented information security management system behind the promises, that it's audited annually by an accredited third party, and that someone independent has checked it.

Getting your own business certified

We take clients through Cyber Essentials and ISO 27001 readiness as part of our IT Security practice - gap analysis, building the management system, and the evidence trail auditors expect.

Having been through it ourselves, we know which parts are genuinely hard and which are just paperwork.