3 min read

RedSecLabs Achieves UKAS-Accredited ISO 27001:2022 and ISO 9001:2015 Certification

RedSecLabs Achieves UKAS-Accredited ISO 27001:2022 and ISO 9001:2015 Certification

RedSecLabs achieves UKAS-accredited ISO/IEC 27001:2022 and ISO 9001:2015 certification

The London cybersecurity consultancy that has guided dozens of organisations through ISO 27001 now holds accredited certification to the standard itself, alongside ISO 9001 for quality management

LONDON, 13 August 2026. RedSecLabs, an independent cybersecurity consultancy serving regulated organisations, today announced that it has achieved certification to ISO/IEC 27001:2022 for information security management and ISO 9001:2015 for quality management, following independent certification audits by SGS United Kingdom Limited.

The certification puts the firm on the other side of an assessment process it has supported clients through for years. RedSecLabs has helped organisations ranging from early-stage startups to established enterprises with ISO 27001 implementation, gap analysis, internal audit and certification readiness. It is now independently assessed against the same standards across its own operations.

Why accreditation matters

The United Kingdom Accreditation Service (UKAS) is the UK's sole national accreditation body, appointed by government to assess the competence of organisations providing certification, testing, inspection, calibration and other conformity assessment services.

The distinction between accredited and unaccredited certification matters, particularly in regulated procurement and third-party assurance. Buyers increasingly look beyond the words "ISO certified" and check who issued the certificate, whether the certification body is appropriately accredited and what activities are actually covered by the certificate.

RedSecLabs' ISO/IEC 27001:2022 and ISO 9001:2015 certifications were completed through a UKAS-accredited certification process with SGS United Kingdom Limited.

Copies of the certificates, including the certified scope and certification details, are available on request. Certification status can also be independently verified through SGS's Certified Client Directory.

What each standard covers

ISO/IEC 27001:2022 sets the requirements for an Information Security Management System, including information security risk assessment and treatment, policies, controls, monitoring and continual improvement.

For a cybersecurity consultancy handling sensitive client information, vulnerability data, penetration-testing evidence and assessment reports, those requirements have a direct bearing on how information is accessed, protected, transmitted, retained and disposed of.

ISO 9001:2015 covers quality management. For a professional services firm, that means the way the work itself is delivered also comes under independent scrutiny.

For RedSecLabs, this includes how engagements are scoped, how work is reviewed, how reports are quality-assured before reaching clients, how retests are handled, how corrective actions are tracked and how feedback is used to improve delivery.

From adviser to auditee

"We ask clients to prove their controls rather than simply describe them, so it was important that we applied the same standard to ourselves," said Rafay Baloch, Founder and CEO of RedSecLabs.

"Advising on a control and living with it are different jobs. Going through the certification process from the auditee's side gives you a different appreciation of evidence, ownership and consistency. That experience will make us better advisers to the organisations we support."

"Accreditation matters as well. If an organisation is relying on an ISO certificate as part of a procurement or third-party assurance process, it should check who issued it, whether the certification falls within an accredited scope and what the certificate actually covers."

Alongside existing credentials

The certifications add to RedSecLabs' broader cybersecurity and assurance credentials, including its CREST membership, PCI DSS Qualified Security Assessor status and SWIFT Customer Security Programme assessment capabilities.

For organisations in financial services, payments, SaaS and other regulated sectors, these capabilities allow security testing, compliance and assurance requirements to be considered together rather than as completely separate exercises.

The certifications also support RedSecLabs' continued international expansion, with the firm serving clients across the United Kingdom, United States, GCC, Pakistan and other international markets.

Organisations preparing for ISO 27001 certification, carrying out a gap assessment or reviewing the validity and scope of a supplier's existing ISO certificate can contact RedSecLabs for an initial scoping discussion.

ISO 27001 services:
https://www.redseclabs.com/services/iso-27001-certification-services

About RedSecLabs

RedSecLabs is a London-headquartered cybersecurity consultancy providing penetration testing, red teaming, incident response and compliance assurance to organisations across financial services, payments, healthcare, SaaS and the public sector.

The company is a CREST member and PCI DSS Qualified Security Assessor company, and is certified to ISO/IEC 27001:2022 and ISO 9001:2015. RedSecLabs operates internationally, with a presence in the United Kingdom, United States and United Arab Emirates.

The firm was founded by Rafay Baloch, a cybersecurity researcher and practitioner known for his work in browser and application security.

www.redseclabs.com

Media enquiries
[email protected]
+44 20 3996 1505