What our badges mean, and how we check them

Every badge on this site states something specific that we checked, and the date we checked it. None of them is a promise about the work a company will do for you.

The process

Three steps, in this order

Is the company real?

We find them in the public company register and confirm the name, the number and the address. Everything else hangs off a real, identifiable legal entity.

Do they hold what they say?

For each certificate, we go to the body that issued it. Where there is a public register we look the certificate up and record the URL. Where there is not, a person reads the certificate and we say so.

Is it still true?

Certificates expire. We record the expiry date at the time we check, and when it passes the badge comes off automatically — the same day, whether or not anybody is watching.

Reviews

Who is allowed to review

Only people we can connect to a real business. Every reviewer confirms a working email address and we check that their company exists in the register. Where anything looks unusual — and the checks are the same whatever the review says — we ask for an invoice before publishing.

Client-verified
The strongest tier. This reviewer showed us a document — an invoice, quote or contract — evidencing that the company worked for them.
Verified business reviewer
Confirmed a working business email address at a company we found in the register. A real check, and a lighter one.

Credentials we check

Recognised everywhere

These mean the same thing in every country, so they show on every profile.

ISO/IEC 27001 certification

An internationally recognised standard for managing information security. An outside auditor has examined how this company protects data and confirmed it meets the standard.

How we check it: We look up the certificate in the IAF CertSearch database of accredited certifications, or, where the certification body does not publish there, we confirm the certificate directly with that body. We check the company name, the certificate number, the scope and the expiry date.

Issued by International Accreditation Forum ↗

ISO 9001 certification

An internationally recognised standard for quality management — how consistently a company delivers what it promises.

How we check it: We look up the certificate in the IAF CertSearch database of accredited certifications, or confirm it with the issuing certification body. We check the company name, certificate number, scope and expiry.

Issued by International Accreditation Forum ↗

SOC 2 report

An independent auditor's report on how a company handles customer data. Common where a provider works with American clients.

How we check it: There is no public register of SOC 2 reports. We read the report itself, confirm it was issued by a licensed CPA firm, and record the period it covers and the date it was issued. We do not publish the report.

Issued by AICPA ↗

PCI DSS compliance

A payment industry standard for companies that handle card data.

How we check it: Where the provider appears on Visa's public Global Registry of Service Providers we verify there. Otherwise we read the Attestation of Compliance and confirm the assessor is a listed Qualified Security Assessor.

Issued by PCI Security Standards Council ↗

CREST accredited member company

Accreditation for companies doing security testing and incident response work. CREST assesses the company's processes, not just an individual's exam pass.

How we check it: We check the company appears on CREST's published list of accredited member companies, and record which accreditations it holds.

Issued by CREST ↗

Microsoft Solutions Partner designation

Microsoft has assessed this company's technical skills, certifications and customer results in a particular area, such as Modern Work or Security.

How we check it: We confirm the designation on the company's own Microsoft partner listing and record which designations they hold. Microsoft reassesses these annually, so we re-check yearly.

Issued by Microsoft ↗

Professional indemnity insurance

Insurance that pays out if the company's professional mistake costs you money. Worth checking before letting anyone near your systems.

How we check it: There is no public register of insurance policies. We read a certificate of insurance issued by the insurer or broker and record the insurer, the level of cover and the renewal date. We do not publish the policy.

Cyber liability insurance

Insurance covering the costs of a cyber incident — including, in some policies, incidents affecting the company's clients.

How we check it: We read a certificate of insurance from the insurer or broker and record the insurer, cover level and renewal date. We do not publish the policy, and we do not assess whether the cover is adequate for your business.

Specific to the United Kingdom

These are only shown to people searching in this country. A certificate that means a great deal here can mean nothing elsewhere, and showing it there would be noise dressed up as reassurance.

Cyber Essentials

A UK government-backed scheme covering the five basic technical controls that stop the most common cyber attacks. The company has declared it meets them and that declaration has been verified.

How we check it: We look the certificate up on IASME's NCSC certificate search, which is the authoritative UK register, and check the company name, certificate number and issue date. The register only lists certificates issued in the last twelve months, so a certificate that has dropped off the register has lapsed — and we remove the badge.

Issued by IASME (NCSC Cyber Essentials Partner)

Cyber Essentials Plus

The stronger version of Cyber Essentials. Rather than taking the company's word for it, an assessor has independently tested the controls on their actual systems.

How we check it: We look the certificate up on IASME's NCSC certificate search and check the company name, certificate number, level and issue date. As with Cyber Essentials, the register covers the last twelve months, so lapsing removes the badge.

Issued by IASME (NCSC Cyber Essentials Partner)

ICO registration

UK organisations that handle personal information must pay a data protection fee and appear on the Information Commissioner's public register. This is a legal baseline, not an achievement — but a company that has not done it is one to ask about.

How we check it: We search the ICO's public register of fee payers for the company's registration reference and confirm the name, address and expiry date shown there.

Issued by Information Commissioner's Office

IASME Cyber Assurance

A UK certification covering broader security and data protection practice than Cyber Essentials, at a cost aimed at smaller companies.

How we check it: We verify the certification with IASME and record the level held, the certificate number and the expiry date.

Issued by IASME

NCSC Cyber Advisor

An NCSC-assured scheme for companies that give small-business cyber security advice. The company has been assessed on the quality of the advice it gives, not only on its own security.

How we check it: We confirm the company appears as an assured service provider under the NCSC Cyber Advisor scheme and record the assurance date.

Issued by National Cyber Security Centre

Common questions

The things people ask

What does a Signal Mark badge mean?

That we checked a specific claim on a specific date. For a credential, we confirmed it with the body that issued it and recorded the expiry date. It is a statement of fact about a moment in time, not a guarantee about the work a company will do for you.

Who is allowed to leave a review?

Only people we can connect to a real business. Every reviewer confirms a working email address and we check that the company they say they work for exists in the company register. Where anything looks unusual we ask for an invoice before publishing.

Can a company have a bad review removed?

No. They can reply publicly to any review, at any time, and they can dispute one with evidence — which we investigate. We do not remove reviews for being unflattering, and that is what makes the good ones worth something.

What happens when a certificate expires?

The badge comes off the company's profile automatically, on the day, whether or not anybody is watching. A stale verification is worse than none.

Does it cost anything to be listed?

No. Listing is free and verification is free.

A signal, not a guarantee

Everything here is a statement of fact about a moment in time: this company held this certificate, and we checked it on this date. That is genuinely useful, and it is not the same as a promise that any particular job will go well.

A verified company can still let you down. What the mark tells you is that they are who they say they are, that their certificates are real and current, and that the people reviewing them were actually clients. Judgement is still yours.