PICMS is now Cyber Essentials certified and registered with the ICO. The part we are proudest of: we prepared and evidenced the whole thing inside PICMS, using the same Cyber & Privacy pack our customers use.
Today is a good day for PICMS Ltd. We are now Cyber Essentials certified (whole organisation, certificate 54c71e02, assessed by IASME) and registered with the ICO for data protection (registration ZC221368). Both are independently verifiable, and both are now on our Trust & Security page.
When we started PICMS, we said we would build a platform that helps UK organisations get compliant and stay compliant, and that we would hold ourselves to the same standard we ask of everyone else. That was the promise. This is us keeping it.
The UK government-backed baseline for cyber security, covering the five technical control areas that stop the most common internet-based attacks. Assessed and certified by IASME, the Cyber Essentials delivery partner. Verify the certificate.
Registration with the Information Commissioner's Office is the legal baseline for any UK organisation processing personal data. Our entry (ZC221368) is public on the ICO register.
We did not get here with a spreadsheet, a consultant and a fortnight of panic. We prepared and evidenced our Cyber Essentials assessment inside PICMS, using the same Cyber & Privacy pack our customers use. The five control areas, the controls behind them, the evidence for each one, the gaps and the fixes, all of it lived in the product.
So this is more than a badge. It is proof. If our platform can take our own company from aligned-with-the-controls to certified, it can do the same for yours. We are not asking you to trust a demo. We are showing you the platform working on the hardest possible customer to impress: us.
We work with social housing providers, consultants and UK SMEs. Increasingly, the first question in a tender or a supplier review is not what your software does, it is whether you can be trusted with data. Cyber Essentials and ICO registration answer that question directly, in a form a procurement team recognises on sight.
They are not vanity badges. For a lot of the work we want to win, they are the entry ticket to the conversation.
We publish where we are, not where we would like to be. Cyber Essentials is certified. ICO registration is live. ISO 27001 is not certified yet. We are in active preparation with a target audit window in Q4 2026, and we manage that information security management system in PICMS too. When it is done, you will read about it here, including anything we get wrong along the way.
That honesty is deliberate. A compliance platform that overstates its own status has no business asking you to trust its assessment of yours. It is also why our Trust page carves out exactly what we hold and what we do not, rather than implying a blanket seal of approval.
The Cyber & Privacy pack that certified us is the same one you would use. It maps your evidence to the Cyber Essentials control areas, flags what is missing before an assessor does, and keeps everything in one place so the assessment is a review rather than a scramble. To be clear about the limits: the software does not make you certified, an assessment body does that. What it does is get you ready, keep you ready, and take the panic out of the paperwork.
If you want the same journey for your organisation, that is where to start. And if ISO 27001 is on your horizon, you can run the groundwork in the same place, exactly as we are.
The Cyber & Privacy pack that certified PICMS maps your evidence to the control areas, flags the gaps before an assessor does, and keeps it all audit-ready. Same tool, your organisation.