Independently assessed
Certified to the standards we would ask of your suppliers.
With the numbers to check, because a badge is a claim and a certificate number is evidence.
Holding ISO 27001, ISO 9001 and Cyber Essentials at our size is unusual. Most providers in this region do not hold ISO 27001 at all, and a good number hold nothing.
ISO/IEC 27001:2022
An audited information security management system. An external body checks, every year, that we do what we say we do with information security: how we control access, how we handle incidents, how we vet suppliers, and how we prove it.
For you it means the way we hold credentials, documentation and data is governed by something an auditor has looked at, rather than by habit.
- Certificate number
- 486222025
- Issued by
- Citation ISO Certification Limited
- Valid until
- 2 July 2029
- Scope
- The provision of managed IT services, including IT consultancy services, hardware and software applications, and the reselling of software, telecommunications and internet services across all sectors
Cyber Essentials
The UK government-backed scheme covering five basic technical controls: how devices are configured, how they are patched, who holds administrative rights, what is exposed to the internet, and how malware is kept off.
It is the certification most supply-chain security questionnaires ask about, and the one insurers increasingly want to see. We hold it ourselves, which is a different thing from helping you get it.
- Certificate number
- 84255d53-1dd5-452a-b453-7b69c98387d7
- Issued by
- IASME
- Valid until
- 30 September 2027
- Scope
- Whole organisation, excluding development and testing networks and any hosted client networks
ISO 9001:2015
An audited quality management system. It governs how work is documented, how problems are recorded and corrected, and how the process is reviewed and improved.
It is the reason what we hold about your estate is a record rather than one engineer's memory — asset register, licences, users, domains and DNS zone data — kept to a standard an auditor has looked at, and handed over in full if you ever leave us.
- Certificate number
- 486222025
- Issued by
- Citation ISO Certification Limited
- Valid until
- 2 July 2029
- Scope
- The provision of managed IT services, including IT consultancy services, hardware and software applications, and the reselling of software, telecommunications and internet services across all sectors
Accreditations
Separate from the certifications above, and worth distinguishing: an accreditation authorises us to do something, where a certification is an audited management system.
Nominet Accredited Registrar
Nominet runs the .uk domain registry. An accredited registrar is authorised to register and manage .uk domains directly, and holds a tag against which those domains sit.
It means your .uk domains are registered by us rather than resold through someone else, so there is no third party between you and the registry when something needs changing. It also means a transfer away is a tag change rather than a negotiation.
Ofcom-registered telecoms reseller
Ofcom is the UK communications regulator. A Reseller Identification Code is a unique three-letter administrative code it issues to identify authorised resellers of fixed-line and broadband telecoms services in the UK.
- Ofcom RID
- IQX
It means the lines and broadband we sell you come from a reseller the regulator has on its books, rather than from someone buying wholesale and hoping nobody asks. It is also what puts us under a published complaints code with a route to independent adjudication, rather than a complaints procedure of our own devising.
Scope, stated honestly
These certifications cover Puzzle Technology's own systems and processes. They are not a statement about your infrastructure, though they are a fair indication of how we will look after it.
Most providers are deliberately vague about this, because the vagueness is useful to them. We would rather be clear, and say the same thing to your customer if they ask us directly.
What this means for you
Most of what follows is how we run ourselves. A provider that cannot keep its own business running is no use to yours, and the certifications are what stop that being a matter of opinion. You get the benefit of it second-hand, which is the right way round.
- Supplier assurance evidence. When your customer asks about your supply chain, we are the part of it you do not have to worry about, and we will answer their questions in writing.
- Documented incident response. Not an intention. A written process that gets audited, and that says what happens and who is told.
- Vetted subcontractors. Anyone we bring in is assessed under the same management system rather than found on the day.
- Tested restores, ours as well as yours. Items are taken back out of backups and checked that they open, because an untested backup is a belief rather than a backup. We prove our own the same way: a provider who cannot restore its own systems cannot keep yours running through the week it goes wrong.
- Corrections that are written down. When we get something wrong we say so and apologise for it — and then, because we hold ISO 9001, it is recorded and put right through a documented process that gets audited, rather than being forgotten once the apology has been made.
The site you are reading is built the same way.
- No third-party trackers, no tag managers, and no cookie banner, because nothing is tracked that would need one.
- Analytics are self-hosted, cookieless and IP-anonymised.
- Static files. There is no content management system to compromise and no plugin supply chain to inherit.
- A strict content security policy, and an A+ grade on Mozilla Observatory and SSL Labs.
If any detail above is out of date, tell us. This page is generated from a single data file, and the moment a certificate passes its expiry date the page stops publishing its number, its issuing body and its dates, and asks you to contact us instead. A lapsed certificate cannot sit here looking current.
Questions people ask
- Do your certifications cover our systems?
- No, and anyone telling you otherwise is being loose with the truth. They cover our own systems and processes. They are a fair indication of how we will look after yours, and they are not a substitute for you holding your own.
- How do we verify these are real?
- Every certificate number, issuing body and expiry date is published here, with a link to the registry where it can be checked independently. You should check, and you should ask any other provider for the same.
- Can you help us get Cyber Essentials?
- Yes. We hold Cyber Essentials ourselves, and ISO 27001 on top of it — which is externally audited every year rather than self-declared. We are not asking you to do anything we have not done, and we will tell you honestly where you stand before you submit anything.
- Our customer has sent us a security questionnaire. Does this help?
- Considerably. A good deal of a typical questionnaire concerns systems we run, and we can evidence those on your behalf. What to do when one arrives is a page of its own.
Talk to us
Twenty minutes on the phone will tell you more than any amount of reading. We will tell you honestly if we are not the right fit.