Certification and assurance roadmap
| Version | 1.0 |
| Review date | 2026-08-21 |
| Next review | Quarterly |
| Owner | Founder and Data Protection Lead, ScotiTech Solutions Limited |
This page states, honestly, what ScotiTech holds today and what is planned. We do not display badges for anything in the "In progress" or "Roadmap" rows, and we do not describe AXOS as "certified" or "compliant" against any of them.
Status today (2026-08-21)
| Scheme | Status | Notes |
|---|---|---|
| UK GDPR / EU GDPR | Aligned | Controller and processor obligations implemented; DPA, privacy policy, retention enforcement, DSR route, breach commitments published. Alignment is an ongoing obligation, not a certificate. |
| Cyber Essentials (basic) | In progress — application submitted | Expected shortly; certificate reference will be added to the evidence pack on award. |
| Cyber Essentials Plus | Roadmap | Requires basic CE first; target assessment within 3 months of CE award. |
| ISO/IEC 27001:2022 | Roadmap | Scoping and gap analysis planned Q1 2027; certification audit targeted within 12–18 months of kick-off. Statement of Applicability draft will be available under NDA once scoping completes. |
| ISO/IEC 42001:2023 (AI management system) | Roadmap | To follow ISO 27001, sharing the management-system backbone. Target: kick-off within 6 months of ISO 27001 certification. |
| SOC 2 Type I / Type II | Roadmap | Prioritised for US-market demand. Type I readiness targeted alongside ISO 27001 gap analysis; Type II requires a 6–12 month observation period after that. |
| Penetration test (third party) | Planned | Web + API scope with AI-specific cases (prompt injection, retrieval leakage). Summary letter to be added to the evidence pack. |
| ICO registration | Held | Reference available in the procurement pack. |
What we share with reviewers in the meantime
- Trust Center artefacts (security, privacy, DPA, sub-processors, AUP, terms)
- Evidence pack under NDA: progress statements, controls mapping, SBOM and checksums, security questionnaire responses (SIG-Lite, CAIQ), insurance, ICO reference
- Framework mappings (NIST AI RMF, NCSC secure AI, ICO AI) with evidence / gap / not-evaluated labels
- Live technical review of the controls in a customer environment
How dates are set
Targets above are realistic for a founder-led company at our current size. They are commitments to sequencing, not guaranteed award dates — certification bodies set their own schedules. We update this page quarterly and remove a target rather than leave a stale one.
