Independently audited quality and information security

Security and Compliance

ISO-Certified Quality and Information Security Management

MicroTelecom's ISO 9001:2015 and ISO/IEC 27001:2022 certifications provide independent evidence that our quality and information-security management systems are formally documented, actively operated, regularly reviewed and externally audited.

The certified management systems cover the processes used to design, develop, secure and deliver business-critical technology within the stated certification scopes.

Current certifications

ISO 9001:2015

Quality Management System (QMS)

Valid through 21 August 2028

ISO/IEC 27001:2022

Information Security Management System

Valid through 31 May 2029

Certificates and supporting information are available upon request.

Certification details

Our Certified Management Systems

Each certificate has a defined scope covering the MicroTelecom activities assessed by the certification body.

Certified

ISO 9001:2015

Certificate 10001250015199

Valid through 21 August 2028

Certified scope

Design, development and deployment of cloud-based and on-premises business systems: point of sale, inventory management, order fulfillment, e-commerce, service desk, payment solutions, mobile business applications and self-checkout, for small businesses and enterprises.

Learn about ISO 9001 on ISO.org
Certified

ISO/IEC 27001:2022

Certificate 09219/MIC27U

Valid through 31 May 2029

Certified scope

Technology and consulting services, including point-of-sale platforms, payment integrations, AI/ML services and cloud-hosted applications.

Learn about ISO/IEC 27001 on ISO.org

External certification

Certification and External Audits

MicroTelecom's management systems are examined by an independent certification body through formal external audits.

Maintaining certification requires documented processes, operational evidence, internal review, corrective action and continual improvement. Auditors evaluate whether the management systems are genuinely implemented and operating within the certified scope.

The certificates and audit process provide documented evidence that these quality and information-security practices are implemented across the design, development and delivery activities included in the certified scopes.

Quality management

What ISO 9001:2015 Covers

ISO 9001 is an internationally recognized quality-management standard. It provides a framework for consistently meeting customer and applicable requirements, managing processes, measuring performance and improving how an organization works.

Customer focus

Understanding requirements and using feedback to improve products, services and delivery.

Controlled processes

Defined responsibilities, documented workflows and consistent review throughout the service lifecycle.

Performance and accountability

Objectives, measurements, internal audits and management review help keep delivery visible and accountable.

Continual improvement

Issues, risks and opportunities are reviewed so corrective action and practical improvements can follow.

Information security

What ISO/IEC 27001:2022 Covers

ISO/IEC 27001 defines the requirements for an Information Security Management System, or ISMS. It provides a risk-based framework for protecting information through coordinated policies, processes, people and technology.

The standard requires organizations to assess information-security risks, select appropriate treatments, monitor effectiveness and continually improve the ISMS.

Confidentiality

Information is accessible only to authorized people and systems.

Integrity

Information remains accurate, complete and protected from unauthorized change.

Availability

Authorized users can access information and services when required.

  • Information-security risk assessment and treatment
  • Access control and identity-management practices
  • Supplier, cloud-service and technology risk management
  • Incident preparation, response and improvement
  • Business continuity and operational resilience considerations

Combined management systems

Relationship Between ISO 9001 and ISO/IEC 27001

The two management systems address complementary areas of service delivery: process quality and information-security risk management.

Area ISO 9001:2015 ISO/IEC 27001:2022 Operational relevance
Primary focus Quality and consistent delivery Information-security risk management Documented quality controls and security risk management
Management approach Process control and improvement Risk assessment and treatment Decisions supported by defined processes and evidence
Review and improvement Objectives, measurement and corrective action Security monitoring, review and improvement Governance that continues after initial implementation

Enterprise production experience

Tier-1 Production Environments

MicroTelecom platforms are deployed in production by Tier-1 enterprise service providers worldwide, including across Europe. These deployments are subject to security, privacy, availability, integration and operational requirements.

Business-critical operations

Our systems support point of sale, payments, service delivery and other essential customer-facing operations.

Enterprise review

Tier-1 deployments include technical, security, procurement, integration and operational review requirements.

Global deployment

Production deployments operate across multiple markets with regional privacy and security requirements.

Ongoing review

ISO audits, internal reviews, vulnerability management and recurring security scans continue as part of operational management after launch.

Privacy and payment security

Privacy and Payment Security in Practice

Our ISO-certified management systems provide the governance foundation for the privacy, data-protection and payment-security practices applied across the MicroTelecom platform.

GDPR

We follow GDPR privacy and security principles applicable to our platform and role, helping customers operate compliant services within European markets.

PDPA

We follow applicable data-protection requirements and practices in the jurisdictions where our systems are deployed.

PCI Security Practices

Our externally accessible systems pass recurring PCI compliance scans, with an updated compliance report produced every four months. We address the requirements applicable to our component while supporting the customer's broader PCI compliance responsibilities.

Security and privacy are shared responsibilities

MicroTelecom is responsible for the security and privacy controls applicable to our platform component. Customers, payment providers and other integrated service providers remain responsible for their respective systems, configurations, business processes and use of data.

Operational application

Application of the Certified Management Systems

Certification gives customers and procurement teams independent evidence that MicroTelecom maintains formal management systems within the stated scopes.

Structured delivery

Projects and services are supported by defined processes, responsibilities and review points.

Risk-based decisions

Quality and information-security risks are identified, assessed and addressed through formal processes.

Enterprise due diligence

Certification documents can support vendor reviews, procurement questionnaires and governance discussions.

Continual improvement

Audits, measurement, management review and corrective action support ongoing improvement.

Frequently asked questions

Certification FAQs

What does ISO certification mean?

It means a certification body has audited MicroTelecom's relevant management system against the requirements of the named standard and certified the activities within the stated scope.

Are individual MicroTelecom products ISO certified?

These are management-system certifications. They apply to MicroTelecom and the activities stated in each certificate's scope, rather than certifying an individual product.

Does ISO/IEC 27001 guarantee that no breach will occur?

No standard can eliminate every risk. ISO/IEC 27001 requires a systematic process for identifying, treating, monitoring and improving the management of information-security risks.

How do the ISO standards support privacy and payment security?

The certified management systems establish documented governance, risk-management, review and improvement processes that support the privacy and payment-security practices applied to our platform.

How can I request the certificates?

Contact MicroTelecom with your company details and due-diligence requirements. We will provide the appropriate certification documents and discuss any questions relevant to your proposed solution.

Request Certification Documents

Certification Documents and Security Information

Contact us to request copies of our current certificates or discuss security, quality and compliance requirements for your deployment.

trustmark/floating