-
ISO/IEC 27001 certification
-
Yes
-
ISO/IEC 27001 accredited by
-
BSI
-
ISO/IEC 27001 accreditation date
-
Wednesday 10 September 2025
-
What the ISO/IEC 27001 doesn’t cover
-
Our ISO/IEC 27001:2022 certification applies specifically to the Information Security Management System (ISMS) supporting the provision of network, hosting, data handling, telephony, applications, collaboration, infrastructure, network and security services delivered from the locations listed on the certificate.
The certification does not extend beyond this defined scope. In particular, it does not cover activities, systems, services, or locations that are not explicitly included within the certified scope or Statement of Applicability. It also does not certify individual products, standalone customer environments, or third-party services that are outside Redcentric’s operational control.
Additionally, while the certification demonstrates that our ISMS conforms to ISO/IEC 27001:2022 requirements, it does not in itself guarantee absolute security or confer exemption from contractual, regulatory, or legal obligations.
Where services fall outside the certified scope, Redcentric applies proportionate security controls aligned to the principles of ISO/IEC 27001, and assurance can be provided on request.
-
ISO 28000:2022 certification
-
No
-
ISO 9001 certification
-
Yes
-
ISO 9001 certification accredited by
-
BSI
-
ISO 9001 accreditation date
-
Thursday 15 May 2025
-
What the ISO 9001 doesn’t cover
-
Our ISO 9001:2015 certification is limited to the scope explicitly defined on the certificate and applies only to the activities, services, and locations listed therein. Accordingly, any services, processes, or activities that fall outside the defined scope of the design and delivery of managed telecommunications services, IT services, hosted voice and data services, data centre operations, workplace disaster recovery services, storage and Gov Cloud services are not covered.
The certification applies solely to Redcentric Solutions Ltd and the specific UK and international locations named on the certificate. Activities undertaken by other legal entities within the wider Redcentric Group, joint ventures, partners, or subcontractors operating independently of Redcentric’s certified management system are excluded unless explicitly stated. Similarly, customer-managed environments or services where Redcentric does not retain operational control are outside the scope of certification.
ISO 9001 certification does not extend to individual products, guarantee specific service performance outcomes, or provide assurance over regulatory, financial, commercial, or information security compliance. These areas are addressed through separate governance arrangements, contractual controls, and other applicable standards where relevant.
This clearly defined scope ensures transparency and confirms that certification applies only where Redcentric maintains full responsibility and control under its certified quality management system.
-
Quality management systems (QMS)
-
Yes
-
CSA STAR certification
-
No
-
PCI certification
-
Yes
-
PCI DSS certification accredited by
-
Gemserv Limited
-
PCI DSS accreditation date
-
Thursday 6 November 2025
-
What the PCI DSS doesn’t cover
-
Redcentric's PCI DSS v4.0.1 certification applies only to the services defined within the assessment scope of the Attestation of Compliance. Specifically, certification is limited to Infrastructure as a Service (IaaS), PCI Comply Voice Service, Managed Firewall services. It does not extend to other managed or bespoke services delivered by Redcentric.
Services excluded from scope include “other managed services” tailored to individual customer requirements. These may include applications, systems security services, IT support, physical security, terminal management systems, or other hosting and managed offerings, not directly related to the assessed PCI services. Where such services are provided, they are assessed as part of the customer’s own PCI DSS compliance obligations rather than Redcentric's service provider certification.
The certification does not cover the storage, processing, or transmission of cardholder data, as Redcentric does not perform these activities. Responsibility for cardholder data, including customer system components, applications, and hosted data, remains with Redcentric clients. Redcentric does not have logical access to customers’ hosted systems, which further limits the certification scope.
Additionally, requirements relating to software development, merchant activities, handling of cardholder media, and direct access to cardholder data are excluded, as they are not applicable to Redcentric’s role as a managed service provider.
-
Cyber essentials
-
Yes
-
Cyber Essentials Certificate Number
-
15e9866d-2e5e-45da-9965-1c9176390caa
-
Cyber essentials plus
-
Yes
-
Cyber Essentials Plus Certificate Number
-
Eacf9619-51c6-4294-bf31-e87af09dd4b6
-
Other security certifications
-
Yes
-
Any other security certifications
-
CHECK registered security tester