ISO/IEC 27001
Information security management
The standard for the system that manages the confidentiality, integrity and availability of information.
What the standard requires
ISO/IEC 27001 certifies a management system, not a product. It requires an organization to identify its information assets, assess the risks to them, justify the controls it selects, and demonstrate through evidence that the system runs. An audit examines how you decide, who decided, and where that is recorded — not which technology you bought.
What it means for you
When you hand infrastructure to a provider, how that provider separates access and what it does during an incident becomes your risk. 27001 shows the answer lives in a system rather than in individuals.
Certificate details
- Certificate number
- 2671034
- Certification body
- Naviga Belgelendirme (TÜRKAK akreditasyonlu)
- Issued
- 26 February 2026
- Valid until
- 25 February 2027
- Scope
- Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
ISO 9001
Quality management
The standard for doing the work repeatably, with the same outcome each time.
What the standard requires
ISO 9001 requires processes to be defined, owners to be named, failures to be recorded and traced to a cause, and improvement to be measured. "Quality" here is not an adjective; it is evidence that the outcome is not left to chance.
What it means for you
In a managed service the outcome is decided not by what happens on a good day, but by whether the same steps are followed on a bad one. 9001 shows those steps are written down and audited.
Certificate details
- Certificate number
- 2640032
- Certification body
- Naviga Belgelendirme (TÜRKAK akreditasyonlu)
- Issued
- 26 February 2026
- Valid until
- 25 February 2027
- Scope
- Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
ISO/IEC 20000-1
IT service management
The standard for planning, delivering and measuring IT as a service.
What the standard requires
ISO/IEC 20000-1 requires service levels to be defined; incident, problem, change and capacity management to run as distinct disciplines; and delivery against the agreed level to be measured. It covers the chain from how a ticket is raised to who approved a change.
What it means for you
This is the standard most directly about an MSP: what you buy is an operating discipline, not technology. 20000-1 shows that discipline has been independently audited.
Certificate details
- Certificate number
- 2656038
- Certification body
- Naviga Belgelendirme (TÜRKAK akreditasyonlu)
- Issued
- 26 February 2026
- Valid until
- 25 February 2027
- Scope
- Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
ISO 22301
Business continuity management
The standard for planning, in advance, how the business continues through disruption.
What the standard requires
ISO 22301 requires a business impact analysis, recovery objectives (RTO and RPO) for critical processes, written plans, and — most importantly — that those plans are exercised. An untested plan does not count as a plan under the standard.
What it means for you
The real question when buying disaster recovery is not "do you have backups" but "when did you last restore, and how long did it take". 22301 shows that question is answered on a schedule.
Certificate details
- Certificate number
- 2656037
- Certification body
- Naviga Belgelendirme (TÜRKAK akreditasyonlu)
- Issued
- 26 February 2026
- Valid until
- 25 February 2027
- Scope
- Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
ISO/IEC 27701
Privacy information management
The standard for the system that governs how personal data is processed; it extends 27001.
What the standard requires
ISO/IEC 27701 cannot be certified on its own — it extends an existing ISO/IEC 27001 information security management system. It requires the organization to establish whether it acts as controller or processor, to record which personal data it processes for what purpose and on what legal basis, to answer data-subject requests through a defined process, and to govern its sub-processors.
What it means for you
When you hand infrastructure to a provider, you usually remain the controller under GDPR or KVKK while the provider is the processor. 27701 shows the provider has put its processor obligations into a system, and that the system has been independently audited.
Certificate details
- Certificate number
- 2671035
- Certification body
- Naviga Belgelendirme (TÜRKAK akreditasyonlu)
- Issued
- 26 February 2026
- Valid until
- 25 February 2027
- Scope
- Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
ISO 14001
Environmental management
The standard for the system that manages the environmental impact of an organization's activities.
What the standard requires
ISO 14001 requires an organization to identify the environmental impacts its activities produce, track the legal obligations attached to them, set measurable objectives and evidence its progress. The certificate does not attest to being green; it attests that the impact is known, measured and managed.
What it means for you
In IT services most of the environmental impact sits in data-center energy and hardware lifecycle. Enterprise procurement questionnaires now ask about this as a matter of course; 14001 answers with a credential rather than a statement.
Certificate details
- Certificate number
- 2643033
- Certification body
- Naviga Belgelendirme (TÜRKAK akreditasyonlu)
- Issued
- 26 February 2026
- Valid until
- 25 February 2027
- Scope
- Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
ISO 45001
Occupational health and safety management
The standard for the system that manages workers' health and safety risks.
What the standard requires
ISO 45001 requires hazards to be identified, risks assessed, workers consulted in that process, and incidents recorded and investigated. Its distinguishing requirement is participation: decisions taken by management alone do not satisfy the standard.
What it means for you
Field and data-center work makes this credential concrete: cabling, moving hardware, electrical work and working at height are real hazards. A provider sending engineers to your site having this system in place means that risk is managed on your site too.
Certificate details
- Certificate number
- 2644036
- Certification body
- Naviga Belgelendirme (TÜRKAK akreditasyonlu)
- Issued
- 26 February 2026
- Valid until
- 25 February 2027
- Scope
- Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Validity can be verified against the certification body's own register. Original certificates are available for an audit or a supplier assessment.
Need the certificates for an audit?
Tell us what your supplier assessment or audit requires and we will send it.
Our services in these areas ISO Standards · Regulatory Compliance