-
ISO/IEC 27001 certification
-
Yes
-
ISO/IEC 27001 accredited by
-
TÜV SÜD South Asia Private Limited
-
ISO/IEC 27001 accreditation date
-
Friday 2 August 2024
-
What the ISO/IEC 27001 doesn’t cover
-
The Mphasis ISO/IEC 27001 certification excludes specific areas that fall outside its direct control. These exclusions include all client‑owned or client‑managed IT infrastructure, systems, and services, meaning any technology environment operated by the customer is not covered under Mphasis’ ISMS scope. It also excludes personal devices not used for business purposes, as these are beyond organizational governance. Additionally, publicly available information is out of scope since it does not require confidentiality controls. Finally, third‑party systems that Mphasis does not directly administer or manage are excluded, as the company cannot apply or enforce security controls on external environments it does not control. These exclusions ensure that ISO 27001 applies only to systems, services, and assets that Mphasis fully governs.
-
ISO 28000:2022 certification
-
No
-
ISO 9001 certification
-
Yes
-
ISO 9001 certification accredited by
-
DNV Business Assurance B.V
-
ISO 9001 accreditation date
-
Thursday 13 June 2024
-
What the ISO 9001 doesn’t cover
-
Mphasis’ ISO 9001:2015 certification covers the organization’s Quality Management System for delivering Applications, Business Process Outsourcing (BPO), Infrastructure Services, and Support Functions across the certified sites. Because the scope is explicitly limited to these service areas and locations, any Mphasis services outside this defined scope—including services delivered from non‑listed sites, offerings not categorized under applications, BPO, or infrastructure services, or any functions not part of the certified QMS boundaries—are not covered by the ISO 9001 certification. In other words, ISO 9001 applies only to the services and locations listed in the certificate appendices; all other service lines, geographies, or operational units fall outside its audited and certified quality framework
-
Quality management systems (QMS)
-
Yes
-
CSA STAR certification
-
No
-
PCI certification
-
Yes
-
PCI DSS certification accredited by
-
PCI Security Standards Council
-
PCI DSS accreditation date
-
Friday 1 August 2025
-
What the PCI DSS doesn’t cover
-
Mphasis’ PCI DSS attestation applies only to the specific service‑provider environment defined in its PCI DSS v4.0.1 Attestation of Compliance. The assessment confirms that Mphasis does not store, process, or transmit any cardholder data, and therefore only the thin‑client desktop machines used to authenticate into external client cardholder‑data environments (CDEs) fall within PCI scope. All other Mphasis services—including application development, BPO operations, infrastructure services, cloud platforms, data centers, business processes, and any systems that do not directly interact with a client’s CDE—are explicitly out of scope for PCI DSS. Since no cardholder data resides in Mphasis’ internal environment, these broader service lines are governed by other security frameworks but not evaluated under PCI DSS requirements.
-
Cyber essentials
-
No
-
Cyber Essentials Alternative
-
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
-
Cyber essentials plus
-
Yes
-
Cyber Essentials Plus Certificate Number
-
A4dacfec-0c39-4c17-9ba7-406c3bded960
-
Other security certifications
-
No