Highgate is now ISO 27001 and ISO 9001 certified: what it means for you

Highgate now holds ISO 27001 and ISO 9001, both independently audited. What each standard covers, what it means for supplier due diligence, and what changes day to day (nothing).

In July 2026, Highgate IT Solutions was certified to two international standards by Alcumus ISOQAR: ISO 27001 for information security management, and ISO 9001 for quality management. One governs how we protect data. The other governs how we run the business that looks after yours.

This article is the point of reference. If your auditors or a procurement panel ask about your IT partner’s credentials, the answer lives here, and the certificates themselves are a click away.


What do the two standards cover?

ISO 27001 is the international standard for information security management. Certification means an external assessor has examined how we handle and protect data, how access to systems is controlled, how incidents are managed, and how the whole framework improves over time, and has certified that it all meets the standard. It sits behind our cybersecurity services and everything else we do to help customers reduce risk.

ISO 9001 is the international standard for quality management. It covers our people and our processes: how work is scoped, delivered, checked, and put right when something slips. In a managed services relationship, that consistency is most of what you are paying for.

Neither certificate is self-declared. Both run on a three-year cycle with surveillance audits every year in between, so the assessor keeps coming back. That, really, is the point.


What does it mean for you?

Supplier due diligence gets quicker. If you are completing a security questionnaire, a tender, or an insurance renewal, “our IT partner holds ISO 27001 and ISO 9001” answers whole sections in one line. Use it. That is what it is for.

You can evidence the decision. Regulators and insurers increasingly ask how you know your suppliers are secure, and “we checked” is a weak answer. An independently audited partner is one you can defend in writing. Mercer & Hole, an FCA-regulated accountancy practice with 300 staff across four offices, is exactly the kind of business that has to stand behind its supplier choices:

“What sets Highgate apart is the relationship. We’re a complex business with demanding requirements across four offices, and they treat us accordingly – responsive, fairly priced, and genuinely invested in getting it right. A vendor you can truly rely on.”

Tom Luknar, IT Manager at Mercer & Hole

Quality is audited too. Security certifications are becoming table stakes among larger providers. A certified quality management system is much rarer in the mid-market IT channel, and it covers the part of the relationship you feel every week: whether the work is done consistently, whether problems are put right properly, and whether the service you were sold is the service you get.


What changes in how we work together?

Nothing, day to day. Your account manager and your service desk contacts stay the same. The certifications are formal, external evidence of the standard we already held ourselves to.

Worth saying plainly: helping customers meet these same standards is day-job work for our team. We take businesses through Cyber Essentials and wider security frameworks as part of the same practice that now holds them. Running to that discipline in-house was, in one sense, overdue; much of what the auditors examined was already in place. The audit put it under an external light and turned it into evidence for your file as well as ours.


Where can you see the certificates?

Both certificates are published on our accreditations page, alongside Cyber Essentials Plus and our other accreditations. If you need a copy or a scope statement for your records, download them there or ask your account manager. Procurement and audit teams are welcome to cite them directly, and that page will stay current as certificates renew.


What should you ask of any IT provider?

The suppliers that struggle with due diligence are rarely hiding anything. They just cannot show their working. After sixteen years supporting more than 2,500 UK businesses, our view is that showing matters nearly as much as doing, because you are the one who has to answer for the choice.

If you are weighing up a provider, certified or not, we have published two guides on what to check: how to tell whether an IT provider is actually secure, and whether they will actually deliver. We wrote both expecting to be marked against them.

And if the next supplier questionnaire on your desk asks about us, send it over. Answering it is now the easy part.