IT & Software
Certification audits that read the pipeline, not a policy pack
ISO 27001, ISO 42001, ISO 20000-1, ISO 22301 and ISO 9001 certification for software and platform companies, assessed by auditors who ask to see the repository, the ticket and the access review rather than a folder of screenshots.

Explore the controls
The operational pressures the audit is read against
Your auditor works from the pressures your teams already carry, not from a blank template.
Security reviews blocking deals
Enterprise procurement stalls without credible, certified security management.
AI capability outpacing governance
Customers and regulators now ask how AI is controlled, not whether you have it.
Service commitments at scale
SLAs multiply across customers while incident and change discipline strains.
Compliance without killing velocity
Controls must ride the pipeline, not park alongside it.
Field view
Walk the platform. Meet the evidence.
Scroll from the campus to the ops floor. Each stop is somewhere an auditor asks the platform to produce a record, not a description.

Stop 01 / 04
One platform, enterprise scrutiny
Every enterprise deal now arrives with a security review attached. A certification audit asks the same platform the same kind of question, and accepts the same kind of answer: evidence, not assurances.
Standards that matter in it & software
Recommended by relevance to the sector's risk profile and customer requirements.
Certification services for this sector
Certification to ISO 27001, 42001, 20000-1, 22301 and 9001
Stage 1, Stage 2 and an independent certification decision, with a scope statement written to describe the product, platform and environments your buyers actually assess.
Combined and integrated audits
Security, AI management, service management, continuity and quality examined in one audit programme, so the clauses they share are assessed once rather than five times.
Distributed-team sampling and transfer
Offices, remote engineering and hosting regions sampled where the system is genuinely common, and transfer of an active accredited certificate without restarting your cycle.
Pre-assessment, surveillance and training
An optional pre-assessment that reports gaps without prescribing fixes, surveillance in Years 1 and 2, recertification in Year 3, and public training courses.
How the audit runs here
Scope and duration set before the visit
Effective headcount including contractors and remote engineers, the services and environments inside scope and the risk category fix audit time by formula, not by negotiation.
The auditor needs the live systems, not exports
Read-only walkthroughs of the repository, pipeline, ticketing, identity and logging, with an engineer driving. Screenshots assembled the week before are weaker evidence than the system itself.
Evidence sampled through a release and an incident
One change and one incident are followed end to end — approval, testing, deployment, rollback, post-incident review. For ISO 42001 an AI feature is traced the same way, from inventory entry to production monitoring.
Findings graded, decision separated
Majors, minors and opportunities for improvement are reported within five working days. Someone outside the audit team takes the certification decision.
Sector evidence
Technology examples will appear here only where a certified organization has approved publication in writing. CORE does not publish client names, architecture details or audit findings without that consent.
IT & Software questions, answered straight
Ready to certify your it & software operation?
Tell us the standards, scope, headcount and sites. You will get a clear scope statement, an audit duration set by the accreditation body's formula, and a fixed quotation.



