Three certifications a UK buyer should check – what each one explains about a file transfer provider and where to verify them.
When an organisation chooses a file transfer platform, their files will typically be passing through the supplier's hosted cloud solution, so the supplier's own security practices must become part of the organisation’s decision making process. Certifications can help organisations with their decision making as they are independent evidence rather than the supplier's own assurances. Three commonly requested certifications in the UK are ISO 27001, Cyber Essentials and if the organisation is part of the NHS, the NHS Data Security and Protection Toolkit.
ISO 27001
ISO 27001 is the international standard for an information security management system. Certification means an independent certification body has audited how the supplier manages information security as an organisation: its people, processes and technology, not just its IT. A certificate lasts three years, with annual surveillance audits.
Cyber Essentials
Cyber Essentials is the minimum standard of cyber security recommended by the UK government, developed by the National Cyber Security Centre. It confirms that five technical controls were in place at the date of assessment: firewalls, secure configuration, security update management, user access control and malware protection. A Cyber Essentials certification is valid for 12 months.
The NHS DSPT
Utilised by NHS customers, the Data Security and Protection Toolkit (DSPT) applies when the files contain NHS patient data. Every organisation with access to NHS patient data and systems must complete it, including the technology suppliers whose platforms process that data. It is an annual self assessment developed in direct response to the National Data Guardian's 10 data security standards. Each organisation publishes its own result.
DSPT differs slightly from ISO 27001 and Cyber Essentials: a supplier can be described as DSPT compliant, not DSPT certified. There are four published DSPT statuses: Standards Met, Standards Exceeded, Approaching Standards or Standards Not Met.
How the three compare
|
|
ISO 27001 |
Cyber Essentials |
NHS DSPT |
|
What it covers |
A management system covering people, processes and technology. |
Five technical controls against common internet based attacks. |
Practices measured against the National Data Guardian's 10 data security standards. |
|
Who issues it |
An independent certification body, in the UK usually accredited by UKAS. |
A certification body licensed by IASME. |
A self assessment on a toolkit administered by NHS England. |
|
How long it lasts |
Three years, with annual surveillance audits. |
One year. |
One year. |
|
Where to check |
What none of them tell you
All three assess the supplier's organisation. None of them describes how a specific product behaves: the product’s specification such as encryption method used, access controls and hosting location should be considered alongside these credentials to ensure the product is suitable for the organisation’s own requirements.
How AMS approaches these credentials
AMS is ISO 27001 certified, Cyber Essentials certified and DSPT compliant. The ISO 27001 certificate is listed under Automated Messaging Systems Ltd on the IAF Cert Search, the current Cyber Essentials certificate can be viewed on the certificate registry, and the 2025-26 DSPT assessment is published as Standards Met, under ODS code 8K883 on the DSPT register.
AMS File Transfer is hosted in Microsoft Azure UK datacentres, uses 256 bit AES encryption to protect file transfers and sharing, and records a full audit trail.
Keep reading: ISO 27001 and Cyber Essentials for UK file transfer.
If you are assessing a file transfer or sharing platform against ISO 27001, Cyber Essentials or the NHS DSPT, describe your requirements to us and our team will advise on the right fit for your requirements.