Careberry ISO 27001 certification badge alongside a care manager reviewing secure digital care records on a laptop

Careberry Is Now ISO 27001 Certified: What That Means for Your Service

There is a question that comes up in almost every tender, every local authority due diligence pack, and every conversation with a cautious registered manager:

"How do we know our data is safe with you?"

It is a fair question. A care management platform holds some of the most sensitive information there is: health needs, medication, capacity assessments, safeguarding notes, next-of-kin details, staff records. For a provider, answering that question has usually meant taking a supplier’s word for it, or wading through a security questionnaire that neither side particularly enjoys.

Today we can answer it differently. Careberry Software Ltd has been assessed and certified as meeting the requirements of ISO/IEC 27001:2022, the international standard for information security management.

The certificate was issued by the British Assessment Bureau, part of the Amtivo group, under UKAS accreditation. Certificate number 274951. Valid from 8 September 2026 to 7 September 2029, subject to annual assessments.

What ISO 27001 Actually Is, In Plain English

ISO/IEC 27001 is the international standard for information security management. The current version is the 2022 edition. Certificates issued against the older 2013 version expired on 31 October 2025, so a 2022 certificate is the only current one worth having.

It is worth being precise about what it certifies, because the term gets used loosely. ISO 27001 does not certify a product. It certifies a management system: the way an organisation identifies information risks, decides what to do about them, assigns responsibility, trains its people, and demonstrates that it is working.

That distinction matters. A padlock icon on a login page tells you nothing. ISO 27001 asks harder questions. Who has access to what, and why? What happens when a laptop is lost? How quickly would you know if something went wrong, and who would you tell? What have you actually tested, rather than assumed?

To be certified, an organisation is audited by an independent body against the clauses of the standard and Annex A, which sets out 93 controls grouped into four themes: organisational, people, physical, and technological security. Nothing is taken on trust. Evidence is examined, staff are interviewed, and gaps have to be closed before a certificate is issued.

Accreditation Matters as Much as Certification

This is the part that gets skipped, and it is the part a careful buyer should look for.

Anyone can print a certificate. What gives one weight is whether the body that issued it is itself supervised. Our certificate is issued under UKAS accreditation, the United Kingdom Accreditation Service being the national accreditation body recognised by government. An unaccredited certificate against the same standard is not the same thing, and commissioners increasingly know the difference.

Our certificate covers the provision of care management software services encompassing care planning, rostering, medication management, compliance monitoring, workforce management, recruitment, invoicing and reporting solutions for care providers in the UK. That is the working platform, not a narrow slice of it. Scope is another detail worth checking on any supplier’s certificate, because a certificate can be scoped so tightly that it covers almost nothing you actually use.

Why This Matters More in Care Than in Most Sectors

Care providers sit in an unusual position. You are trusted with intimate information about people who are, by definition, vulnerable. You are also accountable for it.

Under the UK GDPR and the Data Protection Act 2018, a provider remains the data controller for the information it holds, whichever supplier processes that information on its behalf. Article 28 of the UK GDPR requires a controller to use only processors that provide sufficient guarantees of appropriate technical and organisational measures. Choosing a system is a data protection decision, not only an operational one.

We see three places where certification changes something practical for our customers.

  • Due diligence gets shorter. Commissioners, integrated care boards, and framework buyers increasingly ask for written supplier security assurance. A current, accredited ISO 27001 certificate answers a large part of that pack in one document, rather than a dozen bespoke responses drafted from scratch each time.
  • It supports your own compliance work. Every provider handling NHS patient data must complete the NHS Data Security and Protection Toolkit each year, and the toolkit has been moving onto a model aligned to the Cyber Assessment Framework. Careberry is an NHS England assured Digital Social Care Record supplier and maintains its own DSPT position. Certification does not complete your toolkit for you. That duty stays with you as the provider. What it does mean is that the questions you face about your supplier now have a clear, independently verified answer.
  • It is a signal about how a company is run. Certification is not a one-off badge. It carries annual surveillance assessments and a three-year cycle, and it is conditional on maintaining the standard throughout. Ours runs to 7 September 2029. The system has to keep working long after the announcement.

The Foundations Were Already There

Certification did not change how Careberry is built. It documented and independently tested what we had already committed to.

Providers using Careberry already work with passkeys and biometric sign-in, Microsoft single sign-on, market-leading role permissions that let one login carry different rights across roles and branches, geo-fenced clock-in and clock-out, offline mode for carers working where the signal does not reach, and GP Connect and PDS integration with the NHS. We ship updates every two weeks, and we are a Microsoft partner.

What ISO 27001 adds is the layer around all of that. The risk register. The access reviews. The incident response process. The supplier assessments, the staff training, and the internal audits that make sure none of it quietly drifts. It is the difference between a platform that is secure and an organisation that can prove it, year after year.

We were, after all, a care provider first. Careberry began inside Care & Carers in Buckinghamshire in 2017, was spun out as an independent company in 2020, and remains bootstrapped with no external funding. The people who designed these controls have also been the people signing the DSPT, answering the commissioner’s questionnaire, and taking the call when something needs sorting at 7am. That perspective is hard to buy in.

A Certificate Is Not the Point

It would be easy to treat this as a marketing milestone. It is not, or at least it should not be.

The point of information security in care is not compliance. It is that a woman receiving support at home should never have to wonder who can read her care plan. It is that a carer’s address and right-to-work documents stay where they belong. It is that a family, already carrying a great deal, never has to add "is their data safe?" to the list.

People first. Process next. Technology always.

Want to see how Careberry handles security in practice? Book a demo and we will walk you through it. Certificate, scope, controls and all.

Written By
The Careberry Team
08 September 2026