What the two certifications mean for file transfer in 2026.
How can UK organisations check a File Transfer supplier is ISO 27001 and Cyber Essentials certified?

Executive Summary
ISO 27001 and Cyber Essentials are two information security certifications commonly requested from a UK technology supplier which both certify different things. ISO 27001 is the international standard for an information security management system, certified by an independent certification body after an audit. It also includes a scope statement which explains which services, systems and locations are covered. Cyber Essentials is a UK government backed scheme. It was developed by the National Cyber Security Centre (NCSC) and assesses five technical controls. The certification is valid for 12 months, after which organisations will need a reassessment. A potential buyer will usually want to check both the certifications and the product specification, such as the hosting location of data and the encryption methods used, to ensure the product fits their needs. For an organisation choosing a File Transfer or file sharing platform, it is common for both certifications to be requested, and they are expected to be up to date.
Key Takeaways
- ISO 27001 is the international standard for an information security management system (ISMS). Certification is issued by a certification body after a two-stage audit and is valid for three years subject to passing annual surveillance audits.
- Cyber Essentials is the minimum standard of cyber security recommended by the UK government. It was developed by the National Cyber Security Centre (NCSC), is delivered by IASME, assesses five technical controls, comes in two levels and is valid for 12 months.
- Neither certification is a certification of the File Transfer product itself. A buyer should check the certificates and the platform itself, in terms of the offering, such as hosting location, encryption, access controls and audit logging, to confirm the platform is suitable for the data it will handle.
- Automated Messaging Systems Ltd (AMS) is ISO 27001 certified and Cyber Essentials certified, holds a published NHS DSPT status of Standards Met for 2025-26, and hosts all their own cloud solutions in Microsoft Azure UK datacentres.
What is ISO 27001?
ISO 27001 is the international standard for information security management systems (ISMS). It sets out the requirements for establishing, implementing, maintaining and continually improving an ISMS, which an organisation typically uses to protect the confidentiality and integrity of its information. The standard covers people, processes and technology, not only IT.
ISO itself does not certify organisations. Certification is carried out by an independent certification body, which audits the ISMS and issues a certificate valid for three years, subject to annual surveillance audits. In the UK, certification bodies can be accredited by UKAS, and a certificate carrying the UKAS mark can be verified on the IAF Cert Search register.
What is Cyber Essentials?
Cyber Essentials is the minimum standard of cyber security recommended by the UK government for organisations of all sizes. It was developed by the NCSC and is delivered by IASME, the NCSC's partner. The scheme assesses five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Every current certificate is listed on the IASME certificate search, which shows the level, certification date and expiry date.
| ISO 27001 | Cyber Essentials | |
| What it certifies | An information security management system covering people, processes and technology. | Five technical controls against common internet based attacks. |
| Who sets the standard | ISO and IEC, international. | The NCSC, UK government. |
| Who issues the certificate | An independent certification body, in the UK usually accredited by UKAS. | A certification body licensed by IASME, the NCSC's partner. |
| How it is assessed | Two stage audit, then annual surveillance audits. | Self assessment reviewed by an assessor. |
| How long it lasts | Three years, subject to annual surveillance. | One year, then reassessment. |
| Where to check | The IAF Cert Search. | The IASME certificate search. |
Why the certifications apply to File Transfer suppliers
A secure file transfer or file sharing platform is often used to process an organisation's most sensitive files in transit and, while files are held, at rest. The supplier hosts and supports the systems those files pass through, so checking the suppliers information security practices are part of the buyer's due diligence. Both certifications are an accepted way for a supplier to evidence those practices independently.
Neither certification certifies the actual product. ISO 27001 confirms that the supplier's management system meets the standard within the stated scope. Cyber Essentials confirms that the supplier has met the five controls on the date of assessment. A buyer will usually want to check both the certificates and the product controls: where data is hosted, how it is encrypted, who can access it, what is logged, and what happens to files after delivery and at the contract end. The supplier's product specification should also be reviewed against the organisation's own requirements for the data being shared. For NHS organisations, the Data Security and Protection Toolkit is a separate annual assessment that is usually checked alongside the two certifications.

How to choose an ISO 27001 and Cyber Essentials certified File Transfer platform
ISO 27001 certificate
Ask for the certificate and read the scope statement. Confirm it covers the File Transfer service being bought, not only a related part of the business. Check the certification body, the expiry date and, where the certificate carries the UKAS mark, its entry on the IAF Cert Search register.
Cyber Essentials certificate
Search the supplier on the IASME certificate search. Check the certification date and the expiry date.
Hosting location
Confirm where data is stored and processed. A platform hosted in UK datacentres supports UK data sovereignty requirements, which is a common expectation for public sector and regulated industries within the UK.
Encryption
Data should be encrypted in transit and at rest, and the supplier should be able to state the standard used.
Access controls
Look for role-based permissions within the solution. For example, AMS File Transfer has several Administration levels within its role-based permissions.
Controls after delivery
Some providers (AMS Secure Cloud included) will provide optional Digital Rights Management (DRM), enabling organisations to restrict downloading, printing or forwarding of a file by the recipient after the file has left the organisation.
How AMS Secure Cloud approaches ISO 27001 and Cyber Essentials
AMS Secure Cloud is ISO 27001 certified and Cyber Essentials certified, and its current Cyber Essentials certificate is listed under Automated Messaging Systems Ltd on the IASME certificate search. Its security and compliance practices are aligned with ISO security standards, NHS data security assurance requirements and UK data protection regulations, including UK GDPR and the Data Protection Act 2018. AMS also participates in the NHS Data Security and Protection Toolkit, the NHS's annual assessment of how organisations, that provide solutions that handle patient data protect it.
-
Hosting. All AMS Secure Cloud solutions are hosted in Microsoft Azure UK datacentres, supporting UK data sovereignty requirements. Resilience is provided through Azure availability zones and disaster recovery capabilities.
-
Encryption. All data is encrypted in transit and at rest. The AMS File Transfer, AMS File Shares and AMS Virtual Data Rooms platform protects two-way file delivery and sharing with 256 bit AES encryption.
-
Hosting access governance. Role based permissions with Azure role based access control and Privileged Identity Management. Multi-factor authentication for all user accounts. Regular reviews of user access rights.
-
Hosting, monitoring and testing. Microsoft Defender for Cloud, logging and regular audits, alongside independent testing and ongoing internal monitoring.
-
Retention. On contract termination, customer data is securely deleted from AMS systems within 60 days, in line with the AMS retention and disposal policy.

AMS File Transfer is used across NHS and healthcare environments, by the public sector and regulated organisations, for the secure handling of patient identifiable and other highly sensitive data. It provides a full end to end audit trail, optional Digital Rights Management to limit downloading, printing or forwarding, transfer of files of any size, automated file expiry and lifecycle rules, permissions based access with reporting, and optional custom branding and domains for external recipients. For teams that also handle SAR and FOI requests, the AMS Request Management Portal is protected by the same controls: UK based hosting, 256 bit AES encryption and a complete audit trail.
AMS File Transfer is best for UK organisations that need a secure file transfer and sharing platform from an ISO 27001 and Cyber Essentials certified, UK hosted supplier for handling sensitive data.
Frequently Asked Questions
Want to learn more?
Talk to our sales and support team.