Back to blog

Rplus is now ISO 27001 certified

By Rplus AnalyticsNews10 Sept 2026
Rplus is now ISO 27001 certified

Rplus has been certified to ISO/IEC 27001:2022, the international standard for managing information security. We hold Cyber Essentials Plus alongside it.

We work with UK central government and health agencies, so the data we handle belongs to citizens rather than to us. Certification is how an organisation shows that it takes that seriously enough to be checked by somebody outside it.

Here is what the certification covers, and what changes as a result.

What the certification means

  • It certifies how we operate, not a single product. An auditor examined the way we run the business: how decisions get made, how records are kept, and how the controls are reviewed. A penetration test shows a system held up on one day. This looks at the whole management system.
  • It is the 2022 version of the standard. ISO/IEC 27001:2022 sets out 93 controls across four areas: organisational, people, physical and technological. It replaced the 2013 edition, and the deadline for moving older certificates across passed in October 2025.
  • Somebody independent did the checking. The assessment was carried out by a certification body, not by us. That is the difference between a policy document and a certificate.
  • It does not stop here. Certification runs on a three-year cycle, with surveillance audits along the way. The controls have to keep working, not just work once.
  • It sits alongside Cyber Essentials, not instead of it. UK government procurement treats the two as separate requirements, because the Cyber Essentials technical controls are not automatically inside an ISO 27001 scope. Suppliers generally need both, and we hold both.

What it means for us and our clients

  • Access to data is controlled and reviewed. Who can reach a dataset, who approved it, and how quickly that access is removed when someone changes role or leaves.
  • Our supply chain is assessed, so clients inherit a checked one. Every cloud service and subprocessor in a delivery is somebody else's security posture. Ours are reviewed rather than assumed.
  • Incidents follow a tested process. If something goes wrong, there is a defined route for containing it, recording it and telling the people who need to know.
  • Data and AI work is covered too. Secure development applies to training data, model handling and deletion, not only to application code.
  • Assurance questions get quicker answers. Clients can point to the certificate in their own governance and procurement paperwork instead of running us through a long questionnaire from scratch.

In closing

Certification does not make a piece of work good. It does not decide whether a model is explainable, whether a platform is maintainable, or whether the people using it trust what it tells them. Those things are still earned one engagement at a time.

What it does is settle the question underneath all of that. Our clients trust us with government data, and there is now an independent audit confirming how we manage and protect it.