Skip to content

Certifications and compliance

Certified management systems

Four management systems, four independent audits. Instead of a row of logos, here is what each certificate actually means and why it matters to a customer.

CERTIFIEDMANAGEMENT SYSTEMISO/IEC270012022

ISO/IEC 27001

Information security management

The standard for the system that manages the confidentiality, integrity and availability of information.

What the standard requires

ISO/IEC 27001 certifies a management system, not a product. It requires an organization to identify its information assets, assess the risks to them, justify the controls it selects, and demonstrate through evidence that the system runs. An audit looks at how you identified the risk, who made the decision and where that is recorded, rather than at which technology you bought.

What it means for you

When you hand infrastructure to a provider, the way that provider separates access rights and handles incidents becomes your risk. 27001 shows that both depend on a system rather than on individuals.

Certificate details

Certificate number
2671034
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consulting, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
CERTIFIEDMANAGEMENT SYSTEMISO90012015

ISO 9001

Quality management

The standard for doing the work repeatably, with the same outcome each time.

What the standard requires

ISO 9001 requires processes to be defined, owners to be named, failures to be recorded and traced to a cause, and improvement to be measured. Here, "quality" means evidence that the outcome is not left to chance.

What it means for you

In a managed service, the outcome depends on whether the same steps are followed on a bad day as on a good one. 9001 shows those steps are written down and audited.

Certificate details

Certificate number
2640032
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consulting, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
CERTIFIEDMANAGEMENT SYSTEMISO/IEC20000-12018

ISO/IEC 20000-1

IT service management

The standard for planning, delivering and measuring IT as a service.

What the standard requires

ISO/IEC 20000-1 requires service levels to be defined; incident, problem, change and capacity management to run as distinct disciplines; and delivery against the agreed level to be measured. It covers the chain from how a ticket is raised to who approves a change.

What it means for you

This is the standard most directly relevant to an MSP: what you buy is an operating discipline, not technology. 20000-1 shows that discipline has been independently audited.

Certificate details

Certificate number
2656038
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consulting, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
CERTIFIEDMANAGEMENT SYSTEMISO223012019

ISO 22301

Business continuity management

The standard for planning, in advance, how the business continues through disruption.

What the standard requires

ISO 22301 requires a business impact analysis, recovery objectives (RTO and RPO) for critical processes, written plans and, most importantly, exercises that test those plans. An untested plan does not count as a plan under the standard.

What it means for you

When buying disaster recovery, do not stop at "Do you have backups?" Ask, "When did you last restore, and how long did it take?" 22301 shows that question is answered on a schedule.

Certificate details

Certificate number
2656037
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consulting, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
CERTIFIEDMANAGEMENT SYSTEMISO/IEC277012019

ISO/IEC 27701

Privacy information management

The standard for the system that governs how personal data is processed; it extends 27001.

What the standard requires

ISO/IEC 27701 cannot be certified on its own — it extends an existing ISO/IEC 27001 information security management system. It requires the organization to establish whether it acts as controller or processor, to record which personal data it processes for what purpose and on what legal basis, to answer data-subject requests through a defined process, and to govern its sub-processors.

What it means for you

When you hand infrastructure to a provider, you usually remain the controller under GDPR or KVKK while the provider is the processor. 27701 shows the provider has put its processor obligations into a system, and that the system has been independently audited.

Certificate details

Certificate number
2671035
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consulting, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
CERTIFIEDMANAGEMENT SYSTEMISO140012015

ISO 14001

Environmental management

The standard for the system that manages the environmental impact of an organization's activities.

What the standard requires

ISO 14001 requires an organization to identify the environmental impacts its activities produce, track the legal obligations attached to them, set measurable objectives and evidence its progress. The certificate does not attest to being green; it attests that the impact is known, measured and managed.

What it means for you

In IT services most of the environmental impact sits in data-center energy and the hardware lifecycle. Enterprise procurement questionnaires now ask about this as a matter of course; 14001 answers with a credential rather than a statement.

Certificate details

Certificate number
2643033
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consulting, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)
CERTIFIEDMANAGEMENT SYSTEMISO450012018

ISO 45001

Occupational health and safety management

The standard for the system that manages workers' health and safety risks.

What the standard requires

ISO 45001 requires hazards to be identified, risks assessed, workers consulted in that process, and incidents recorded and investigated. Its distinguishing requirement is participation: decisions made by management alone do not satisfy the standard.

What it means for you

Field and data-center work makes this credential concrete: cabling, moving hardware, electrical work and working at height are real hazards. If a provider that sends engineers to your site has this system in place, that risk is managed on your site too.

Certificate details

Certificate number
2644036
Certification body
Naviga Belgelendirme (TÜRKAK akreditasyonlu)
Issued
26 February 2026
Valid until
25 February 2027
Scope
Provision of end-to-end pre-sales and after-sales IT services, including project, installation, maintenance, support, training, consulting, management, monitoring and operation, related to software, hardware, operating systems, virtualization, backup, proactive management, network and security products and solutions, and all IT systems, subsystems and components.
Download certificate (PDF)

Validity can be verified against the certification body's own register. Original certificates are available for an audit or a supplier assessment.

Need the certificates for an audit?

Tell us what your supplier assessment or audit requires and we will send it.

Get in touch

Our services in these areas ISO Standards · Regulatory Compliance