-
ISO/IEC 27001 certification
-
Yes
-
ISO/IEC 27001 accredited by
-
NQA
-
ISO/IEC 27001 accreditation date
-
Thursday 19 June 2025
-
What the ISO/IEC 27001 doesn’t cover
-
Stiona’s ISO/IEC 27001 certification covers the design, development, hosting and support of the Stiona Digital Transformation Platform, which provides the common core infrastructure, security controls and operational processes used to deliver the Stiona Managed Service. This includes the information security management system governing platform operations, service monitoring, incident and problem management, access control, data handling, resilience measures and assurance activities. All services within scope operate within Microsoft Azure UK regions, supported by ISO/IEC 27001-certified underlying infrastructure, with Stiona applying additional layered security, governance and operational controls. Managed Services delivered for Stiona-hosted services inherit these platform-level security controls. The certification does not cover customer-owned devices, networks, systems or environments outside the Stiona-managed platform; customer-managed identity providers, access policies or administrative configurations; third-party systems or integrations outside Stiona’s operational control unless independently certified; customer-specific business processes or operational procedures outside the managed service scope; or Managed Services delivered for services deployed into customer-owned cloud subscriptions unless explicitly included through a separately agreed scope extension. This statement reflects the defined ISO/IEC 27001 scope and Statement of Applicability version 2.2.0 dated 12/05/2025.
-
ISO 28000:2022 certification
-
No
-
ISO 9001 certification
-
Yes
-
ISO 9001 certification accredited by
-
NQA
-
ISO 9001 accreditation date
-
Monday 8 December 2025
-
What the ISO 9001 doesn’t cover
-
Stiona’s ISO 9001 certification covers the design, development, hosting and support of the Stiona Digital Transformation Platform and the associated managed service processes used to operate and support Stiona-hosted services. This includes quality management controls relating to service delivery, operational support, incident and problem management, change control, assurance activities and continual service improvement within the Stiona Managed Service. The certification does not extend to customer-specific operational processes, organisational policies or internal procedures implemented by customers when consuming managed services. Responsibility for how customers operate their own business processes, manage users, define internal workflows, or govern service usage remains with the customer. The ISO 9001 certification also does not cover third-party services, integrations or external systems that customers may rely on, including identity providers, external applications or data sources not operated by Stiona. Quality management for those external components sits outside the scope of Stiona’s certification. In addition, the certification does not cover bespoke professional services, consultancy, or optional additional services delivered outside the standard managed service scope, which are governed by separate agreements and delivery controls. Customers remain responsible for ensuring their own compliance with applicable laws, policies and organisational requirements.
-
Quality management systems (QMS)
-
Yes
-
CSA STAR certification
-
No
-
PCI certification
-
No
-
Cyber essentials
-
Yes
-
Cyber Essentials Certificate Number
-
2de34373-dcc6-4d1a-9e8c-34dca505158d
-
Cyber essentials plus
-
Yes
-
Cyber Essentials Plus Certificate Number
-
4b695eb6-5888-4775-b3cf-ed2c49818143
-
Other security certifications
-
No