We are certified to ISO 9001 and ISO 27001 by Alcumus ISOQAR, a certification body accredited by UKAS. Certificate number 26361.

Most companies put the badges in the footer and leave it there. Badges are easy to display and, on their own, tell you very little. This page explains what the two standards actually require of us, what they do not cover, and how you can check the certificate is real.

At a glance

ISO 9001ISO/IEC 27001
What it coversQuality managementInformation security management
Revision certified to20152022
Certificate number26361QMS00126361ISMS001
First certified13-Jan-202006-Mar-2026
Current certificate valid to21-Jan-202506-Mar-2029

Both certificates are issued by Alcumus ISOQAR Limited, which is accredited by UKAS under accreditation number 0026.

Scope of each certificate

A certificate applies only to the activities named in its scope statement, and the two scopes are not necessarily the same. We quote each in full rather than summarising, so you can see exactly what is covered by which standard.

ISO 9001. The Quality Management System for the virtual provision of IT solutions and consultancy including design, development, and support.

ISO/IEC 27001. The Information Security Management System (ISMS) for the virtual provision of consultancy services that support organisations in streamlining their processes within the regulatory frameworks applicable to their operations along with the technology and software development for the pharmaceutical industry and other industries, in accordance with the Statement of Applicability version 1.

Ask us for a PDF of either certificate at any point. We will send it without asking why.

What ISO 9001 actually means

ISO 9001 is a quality management standard, and the word “quality” is where most people are misled. It does not certify that our software is good. No standard can do that. What it certifies is that we have written down how we work, that the way we work is capable of producing a consistent result, and that an independent auditor checks once a year whether we are actually following it.

In practice, on your project, that means:

  • Every piece of work has a named owner and an agreed point at which it is done. No work drifts along without someone accountable for finishing it.
  • What we agreed, and every change to it, is recorded. Six months later there is a written record rather than two conflicting memories.
  • When something goes wrong, it is logged, the cause is investigated, and the process changes. Not just the symptom fixed. The auditor asks to see the log and asks what changed as a result, so there is a cost to us in not doing it.
  • Suppliers and subcontractors are assessed rather than assumed. If we bring in a third party or a hosting provider, they have been checked against criteria we can show you.
  • Someone outside the business audits us every year. They have no commercial interest in telling us we are fine.

The honest summary: ISO 9001 is not a promise of a brilliant outcome. It is evidence that the way we work is deliberate rather than improvised, and that somebody independent tests that claim annually.

What ISO 27001 actually means

ISO 27001 is the international standard for managing information security. The common misreading is that it is a technical certificate, a stamp saying the firewalls are configured correctly. It is broader and, for you, more useful than that. It requires us to identify what information we hold, work out realistically what could go wrong with it, put proportionate controls in place, and prove to an auditor that those controls are operating.

In practice, on your project, that means:

  • We keep a register of the information we hold and what the damage would be if it leaked, changed or vanished. Your data is on that register, and the controls follow from the risk rather than from habit.
  • Access to your systems is granted to named individuals, reviewed, and removed when someone leaves. No shared logins, no dormant accounts held by a contractor who finished last year.
  • Devices are encrypted, multi factor authentication is in place, and patching runs to a schedule that is recorded.
  • There is a written incident response plan with defined timescales, including how quickly we tell you. Most SMEs discover during an incident that no such plan exists. Ours is documented and tested.
  • Backups are tested, not merely taken. An untested backup is a hope, not a control.
  • Staff are vetted on joining, trained, and offboarded to a checklist. Information security failures are usually people and process failures rather than technology failures, and the standard treats them that way.
  • Cloud providers and other suppliers are assessed for security before we put your data anywhere near them.

Where we work inside your systems, we act on your instructions as a data processor. Where we hold your contact and contract details for our own purposes, we are the controller. Both are covered by the same set of controls.

Why UKAS accreditation is the part that matters

This is the detail most buyers do not know to ask about, and it is worth two minutes of your time.

Anyone can print a certificate. There are firms that will sell you an “ISO 9001 certificate” for a few hundred pounds with no meaningful audit, and the resulting document looks much the same as ours on a website.

The difference is accreditation. UKAS is the United Kingdom Accreditation Service, appointed by government as the sole national accreditation body. UKAS does not certify companies like us; it assesses the certification bodies that do, and audits them on whether their audits are rigorous. Alcumus ISOQAR is accredited by UKAS under accreditation number 0026, which is why our certificate carries the UKAS crown and tick alongside the ISOQAR mark.

So the chain is: an independent body audits us, and a national body audits them. When you are comparing suppliers, look for the UKAS mark and the accreditation number, not just the words “ISO certified”.

What certification does not mean

We would rather say this ourselves than have you wonder.

  • It is not a guarantee that nothing will go wrong. It is evidence that there is a defined system for preventing, detecting and handling it, and that the system is independently tested.
  • It does not certify our software or your systems. The certificate covers our management system, not any individual product or your infrastructure.
  • ISO 27001 is not the same as UK GDPR compliance. They overlap heavily and 27001 does much of the practical work, but data protection law imposes obligations of its own. Ours are set out in our privacy notice.
  • Scope is everything. A certificate applies only to the activities named in its scope statement. Ours is quoted in full above rather than summarised, precisely so you can see what it does and does not cover.

Working with us in a regulated or audited environment

If your own auditors, insurers or larger customers ask questions about your suppliers, we can usually answer them from documentation that already exists:

  • a copy of both certificates and the scope statements
  • our information security policy summary
  • a completed supplier security questionnaire, in your format
  • data processing terms for work where we handle personal data on your behalf
  • confirmation of insurance cover

Ask, and we will send them. There is no charge and no sales process attached.


Company details

Maly IT Solutions Limited
Registered in England and Wales, company number 07102935
Registered office: 50 Princes Street, Ipswich, England, IP1 1RJ
VAT registration: GB 982 6714 82

Privacy policy · Terms and conditions · Cookie notice

Scroll to Top