Skip to content

Certifications and compliance

Certified management systems

Four management systems, four independent audits. Below is what each certificate actually means and why it matters to a customer — explained, not badged.

ISO27001

ISO/IEC 27001

Information security management

The standard for the system that manages the confidentiality, integrity and availability of information.

What the standard requires

ISO/IEC 27001 certifies a management system, not a product. It requires an organization to identify its information assets, assess the risks to them, justify the controls it selects, and demonstrate through evidence that the system runs. An audit examines how you decide, who decided, and where that is recorded — not which technology you bought.

What it means for you

When you hand infrastructure to a provider, how that provider separates access and what it does during an incident becomes your risk. 27001 shows the answer lives in a system rather than in individuals.

Certificate details

Certificate number
2671034
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
ISO9001

ISO 9001

Quality management

The standard for doing the work repeatably, with the same outcome each time.

What the standard requires

ISO 9001 requires processes to be defined, owners to be named, failures to be recorded and traced to a cause, and improvement to be measured. "Quality" here is not an adjective; it is evidence that the outcome is not left to chance.

What it means for you

In a managed service the outcome is decided not by what happens on a good day, but by whether the same steps are followed on a bad one. 9001 shows those steps are written down and audited.

Certificate details

Certificate number
2640032
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
ISO20000-1

ISO/IEC 20000-1

IT service management

The standard for planning, delivering and measuring IT as a service.

What the standard requires

ISO/IEC 20000-1 requires service levels to be defined; incident, problem, change and capacity management to run as distinct disciplines; and delivery against the agreed level to be measured. It covers the chain from how a ticket is raised to who approved a change.

What it means for you

This is the standard most directly about an MSP: what you buy is an operating discipline, not technology. 20000-1 shows that discipline has been independently audited.

Certificate details

Certificate number
2656038
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
ISO22301

ISO 22301

Business continuity management

The standard for planning, in advance, how the business continues through disruption.

What the standard requires

ISO 22301 requires a business impact analysis, recovery objectives (RTO and RPO) for critical processes, written plans, and — most importantly — that those plans are exercised. An untested plan does not count as a plan under the standard.

What it means for you

The real question when buying disaster recovery is not "do you have backups" but "when did you last restore, and how long did it take". 22301 shows that question is answered on a schedule.

Certificate details

Certificate number
2656037
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
ISO27701

ISO/IEC 27701

Privacy information management

The standard for the system that governs how personal data is processed; it extends 27001.

What the standard requires

ISO/IEC 27701 cannot be certified on its own — it extends an existing ISO/IEC 27001 information security management system. It requires the organization to establish whether it acts as controller or processor, to record which personal data it processes for what purpose and on what legal basis, to answer data-subject requests through a defined process, and to govern its sub-processors.

What it means for you

When you hand infrastructure to a provider, you usually remain the controller under GDPR or KVKK while the provider is the processor. 27701 shows the provider has put its processor obligations into a system, and that the system has been independently audited.

Certificate details

Certificate number
2671035
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
ISO14001

ISO 14001

Environmental management

The standard for the system that manages the environmental impact of an organization's activities.

What the standard requires

ISO 14001 requires an organization to identify the environmental impacts its activities produce, track the legal obligations attached to them, set measurable objectives and evidence its progress. The certificate does not attest to being green; it attests that the impact is known, measured and managed.

What it means for you

In IT services most of the environmental impact sits in data-center energy and hardware lifecycle. Enterprise procurement questionnaires now ask about this as a matter of course; 14001 answers with a credential rather than a statement.

Certificate details

Certificate number
2643033
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
ISO45001

ISO 45001

Occupational health and safety management

The standard for the system that manages workers' health and safety risks.

What the standard requires

ISO 45001 requires hazards to be identified, risks assessed, workers consulted in that process, and incidents recorded and investigated. Its distinguishing requirement is participation: decisions taken by management alone do not satisfy the standard.

What it means for you

Field and data-center work makes this credential concrete: cabling, moving hardware, electrical work and working at height are real hazards. A provider sending engineers to your site having this system in place means that risk is managed on your site too.

Certificate details

Certificate number
2644036
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consultancy, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)

Validity can be verified against the certification body's own register. Original certificates are available for an audit or a supplier assessment.

Need the certificates for an audit?

Tell us what your supplier assessment or audit requires and we will send it.

Get in touch

Our services in these areas ISO Standards · Regulatory Compliance