Building in public · A milestone for PICMS

We used our own platform to get Cyber Essentials certified

PICMS is now Cyber Essentials certified and registered with the ICO. The part we are proudest of: we prepared and evidenced the whole thing inside PICMS, using the same Cyber & Privacy pack our customers use.

Jason Misters · Founder, PICMS · 19 August 2026

Today is a good day for PICMS Ltd. We are now Cyber Essentials certified (whole organisation, certificate 54c71e02, assessed by IASME) and registered with the ICO for data protection (registration ZC221368). Both are independently verifiable, and both are now on our Trust & Security page.

When we started PICMS, we said we would build a platform that helps UK organisations get compliant and stay compliant, and that we would hold ourselves to the same standard we ask of everyone else. That was the promise. This is us keeping it.

Cyber Essentials — certified

The UK government-backed baseline for cyber security, covering the five technical control areas that stop the most common internet-based attacks. Assessed and certified by IASME, the Cyber Essentials delivery partner. Verify the certificate.

ICO — registered

Registration with the Information Commissioner's Office is the legal baseline for any UK organisation processing personal data. Our entry (ZC221368) is public on the ICO register.

The part that matters most

We did not get here with a spreadsheet, a consultant and a fortnight of panic. We prepared and evidenced our Cyber Essentials assessment inside PICMS, using the same Cyber & Privacy pack our customers use. The five control areas, the controls behind them, the evidence for each one, the gaps and the fixes, all of it lived in the product.

So this is more than a badge. It is proof. If our platform can take our own company from aligned-with-the-controls to certified, it can do the same for yours. We are not asking you to trust a demo. We are showing you the platform working on the hardest possible customer to impress: us.

A compliance platform should be able to pass the assessments it helps you prepare for. We ran ours through the product, kept the evidence audit-ready, and came out certified. That is the whole point of building the thing.

Why trust signals matter for the people we serve

We work with social housing providers, consultants and UK SMEs. Increasingly, the first question in a tender or a supplier review is not what your software does, it is whether you can be trusted with data. Cyber Essentials and ICO registration answer that question directly, in a form a procurement team recognises on sight.

They are not vanity badges. For a lot of the work we want to win, they are the entry ticket to the conversation.

Building in public, honestly

We publish where we are, not where we would like to be. Cyber Essentials is certified. ICO registration is live. ISO 27001 is not certified yet. We are in active preparation with a target audit window in Q4 2026, and we manage that information security management system in PICMS too. When it is done, you will read about it here, including anything we get wrong along the way.

That honesty is deliberate. A compliance platform that overstates its own status has no business asking you to trust its assessment of yours. It is also why our Trust page carves out exactly what we hold and what we do not, rather than implying a blanket seal of approval.

What this means if you are certifying too

The Cyber & Privacy pack that certified us is the same one you would use. It maps your evidence to the Cyber Essentials control areas, flags what is missing before an assessor does, and keeps everything in one place so the assessment is a review rather than a scramble. To be clear about the limits: the software does not make you certified, an assessment body does that. What it does is get you ready, keep you ready, and take the panic out of the paperwork.

If you want the same journey for your organisation, that is where to start. And if ISO 27001 is on your horizon, you can run the groundwork in the same place, exactly as we are.

Jason Misters — Founder, PICMS

IRCA Registered Principal Auditor, lead auditor and ISO consultant. Founder of Training Assurance Consultancy and PICMS. Verifiable on the CQI-IRCA register.

Get Cyber Essentials ready, the way we did.

The Cyber & Privacy pack that certified PICMS maps your evidence to the control areas, flags the gaps before an assessor does, and keeps it all audit-ready. Same tool, your organisation.

Explore the Cyber & Privacy pack Start Free Trial