Trust Center · Compliance

Certification and assurance roadmap

What ScotiTech holds today, what is in progress, and what is roadmap — with realistic timing.

Back to Trust Center

Source: docs/compliance/certification-roadmap.md

Certification and assurance roadmap

Version 1.0
Review date 2026-08-21
Next review Quarterly
Owner Founder and Data Protection Lead, ScotiTech Solutions Limited

This page states, honestly, what ScotiTech holds today and what is planned. We do not display badges for anything in the "In progress" or "Roadmap" rows, and we do not describe AXOS as "certified" or "compliant" against any of them.

Status today (2026-08-21)

Scheme Status Notes
UK GDPR / EU GDPR Aligned Controller and processor obligations implemented; DPA, privacy policy, retention enforcement, DSR route, breach commitments published. Alignment is an ongoing obligation, not a certificate.
Cyber Essentials (basic) In progress — application submitted Expected shortly; certificate reference will be added to the evidence pack on award.
Cyber Essentials Plus Roadmap Requires basic CE first; target assessment within 3 months of CE award.
ISO/IEC 27001:2022 Roadmap Scoping and gap analysis planned Q1 2027; certification audit targeted within 12–18 months of kick-off. Statement of Applicability draft will be available under NDA once scoping completes.
ISO/IEC 42001:2023 (AI management system) Roadmap To follow ISO 27001, sharing the management-system backbone. Target: kick-off within 6 months of ISO 27001 certification.
SOC 2 Type I / Type II Roadmap Prioritised for US-market demand. Type I readiness targeted alongside ISO 27001 gap analysis; Type II requires a 6–12 month observation period after that.
Penetration test (third party) Planned Web + API scope with AI-specific cases (prompt injection, retrieval leakage). Summary letter to be added to the evidence pack.
ICO registration Held Reference available in the procurement pack.

What we share with reviewers in the meantime

  • Trust Center artefacts (security, privacy, DPA, sub-processors, AUP, terms)
  • Evidence pack under NDA: progress statements, controls mapping, SBOM and checksums, security questionnaire responses (SIG-Lite, CAIQ), insurance, ICO reference
  • Framework mappings (NIST AI RMF, NCSC secure AI, ICO AI) with evidence / gap / not-evaluated labels
  • Live technical review of the controls in a customer environment

How dates are set

Targets above are realistic for a founder-led company at our current size. They are commitments to sequencing, not guaranteed award dates — certification bodies set their own schedules. We update this page quarterly and remove a target rather than leave a stale one.