-
ISO/IEC 27001 certification
-
Yes
-
ISO/IEC 27001 accredited by
-
BSI
-
ISO/IEC 27001 accreditation date
-
Wednesday 7 December 2022
-
What the ISO/IEC 27001 doesn’t cover
-
Our ISO/IEC 27001:2022 certification applies exclusively to the organisational units, services, and sites defined within the certification scope and the Statement of Applicability. Any Atos service, function, location, or infrastructure component that sits outside this formally defined multisite scope is therefore not covered by the ISO 27001 certification.
This includes, but is not limited to:
• Atos offices or business units not included in the certified multisite perimeter
• Customer‑specific or client‑hosted environments that are outside Atos‑certified infrastructure
• Cloud platforms or services operated entirely by third‑party providers
• Subcontractor or partner‑managed environments
• Any bespoke or additional services not explicitly listed within the certification scope
-
ISO 28000:2022 certification
-
No
-
ISO 9001 certification
-
Yes
-
ISO 9001 certification accredited by
-
BSI
-
ISO 9001 accreditation date
-
Wednesday 7 December 2022
-
What the ISO 9001 doesn’t cover
-
Our ISO 9001:2015 certification applies only to the organisational units, business functions, services and locations included within the defined multisite certification scope, as detailed in the ISO 9001 scope appendix and the Atos Multisite Certification database. Any unit, project, service line, or operational activity that falls outside this defined scope is therefore not covered by the ISO 9001 certification.
This includes:
– Atos offices, delivery centres or business units not listed in the certified multisite perimeter
– Customer‑specific or client‑managed environments that are not part of Atos‑certified operations
– Third‑party or subcontractor‑managed processes
– Bespoke solutions, local practices or non‑standard activities not included in the official certification scope
– Any additional services or functions not defined within the registered ISO 9001 scope statement
-
Quality management systems (QMS)
-
Yes
-
CSA STAR certification
-
Yes
-
CSA STAR accreditation date
-
Thursday 12 November 2020
-
CSA STAR certification level
-
Level 1: CSA STAR Self-Assessment
-
What the CSA STAR doesn’t cover
-
Our CSA STAR certification is at Level 1 (Self‑Assessment). As a self‑assessed submission, it covers only the specific cloud service elements documented in the CSA STAR Self‑Assessment at the time of publication. Therefore, any Atos service, business unit, cloud environment, customer‑specific deployment, third‑party‑hosted component, or operational process not explicitly included within that self‑assessment is not covered.
-
PCI certification
-
Yes
-
PCI DSS certification accredited by
-
Blackfoot Cybersecurity
-
PCI DSS accreditation date
-
Thursday 11 December 2025
-
What the PCI DSS doesn’t cover
-
Scope covers the datacentres (Shared hosting services), requirements 9 (physical security) and 12 (management security) only.
-
Cyber essentials
-
Yes
-
Cyber Essentials Certificate Number
-
B3310276-430b-47a7-8462-18342f6e825f
-
Cyber essentials plus
-
Yes
-
Cyber Essentials Plus Certificate Number
-
Efbd6336-f752-417e-98a8-8897209366a7
-
Other security certifications
-
No