Accreditations
Credentials that stand behind every engagement.
Independent accreditation is how you know security work is done properly. Here's what backs ours, and the standards we assess, prepare, and certify our clients against.
- CREST-accredited testing
- ISO 27001 certified
- Crown Commercial Service supplier
- Cyber Essentials certified
Accreditation isn't a badge on a website. It's an independent check that our people, methods, and conduct meet a recognised standard. It's why our testing is repeatable, our reporting holds up to scrutiny, and our advice is trusted by regulated organisations and the public sector alike.
Accreditations & certifications we hold
Independent credentials Blackfoot carries, including several of the standards we help our clients achieve.

Our penetration testing and red teaming follow CREST methodologies and standards of conduct, delivered by a CREST-accredited team.

Blackfoot is certified to ISO 27001, the international standard for information security management, by Perry Johnson Registrars under UKAS accreditation 0105. We run our own business to the bar we help clients meet.

We're certified to the UK government-backed Cyber Essentials scheme for baseline cyber hygiene.

Blackfoot is a Crown Commercial Service supplier, available to UK public-sector organisations through government procurement frameworks.

As a PECB partner we deliver accredited training and certification for ISO standards and the data protection officer qualifications.

Blackfoot is a PCI Qualified Security Assessor (QSA) company, assessing against the Payment Card Industry Data Security Standard, the discipline we were founded on.
Standards & frameworks we deliver
We assess against, prepare for, and certify our clients to the standards that matter most in the UK.
PCI DSS
As a Qualified Security Assessor (QSA) company, we advise on and assess against the Payment Card Industry Data Security Standard, and arrange the quarterly ASV scans it requires. PCI DSS is where Blackfoot began, back in 2008.
ISO 27001
We prepare and support organisations through ISO 27001 certification and ongoing information-security management.
Cyber Essentials & Cyber Essentials Plus
We help organisations certify to the UK government-backed baseline for everyday cyber hygiene.
UK GDPR & Data Protection Act
Outsourced DPO and data-protection expertise aligned to UK GDPR and the Data Protection Act 2018.
Need a partner your auditors will trust?
Get a fixed-scope quote, usually the same working day.