Company · Standards

Certifications we pursue, standards we already practise

For IT consulting and infrastructure, certifications are trust made auditable. Here is what each major standard means, why it matters to your business — and exactly where we stand on each, stated honestly.

Certification seal with standards badges

Where we stand — said plainly

Addroit Nexus is in the process of obtaining formal certification for the standards below, prioritising ISO/IEC 27001 and ISO 9001 as our audit-track certifications. Until an accredited body issues each certificate, we do not claim to be "certified" — we self-certify conformance to the standards' practices: we have implemented the controls, we run the internal audits, and we keep the evidence audit-ready.

Our internal preparation guides and self-assessment checklists are maintained openly in the project's certifications/ folder, and we are glad to walk any client or auditor through our control implementation on request. Trust, in our view, is built by showing the homework — not by borrowing a logo.

The Standards

What each one means — benefits and use cases

ISO 9001:2015In process — self-certified practices

Quality Management System (QMS)

The world's most recognised quality standard: documented processes, defined responsibilities, corrective actions and continual improvement. Benefits: fewer defects, predictable delivery, faster onboarding of new staff. Use case: demanded in government tenders and enterprise vendor empanelment; the baseline signal that a supplier runs on process, not memory.

ISO/IEC 27001:2022In process — self-certified practices

Information Security Management (ISMS)

The global benchmark for protecting information: risk assessment, access control, incident response, supplier security and 90+ controls under Annex A. Benefits: demonstrable security posture, fewer incidents, DPDP-readiness. Use case: effectively mandatory for hosting/data-center providers and anyone handling client data at scale — our top certification priority.

ISO/IEC 20000-1:2018Practices adopted (ITIL-aligned)

IT Service Management (ITSM)

The service-management standard behind serious NOCs: incident, problem, change and SLA management done as disciplines. Benefits: tickets that resolve on pattern, not luck; measurable SLAs. Use case: managed-services and NOC contracts — how our 24×7×365 operation is structured internally.

ISO 22301:2019Practices adopted

Business Continuity (BCMS)

Keeping services alive through fire, flood, grid failure or cyber incident: impact analysis, recovery objectives (RTO/RPO), tested continuity plans. Benefits: disasters become procedures. Use case: central to our edge data-center design — DR is a product we sell, so continuity is a discipline we live.

SOC 2 (Type I/II)Roadmap — controls aligned

Service Organisation Controls

A CPA-audited attestation on security, availability, confidentiality, processing integrity and privacy. Benefits: the report enterprise and SaaS buyers (especially US-linked) ask for by name. Use case: selling our SaaS and hosting to startups whose own customers demand vendor SOC 2 reports. Note: SOC 2 requires an independent auditor — it cannot be self-issued, so we say "aligned", never "attested".

PCI-DSS v4.xSAQ-based self-assessment

Payment Card Data Security

The card industry's security standard. As a technology partner we design so that card data never touches our systems (tokenised via licensed gateways), keeping clients in the lightest compliance scope. Benefits: smaller audit surface, safer checkouts. Use case: every e-commerce and fintech build we deliver. PCI-DSS legitimately supports merchant self-assessment questionnaires (SAQ) at lower volumes — one standard where self-certification is the official mechanism.

CMMI v3.0 (Dev/Svc)Long-term roadmap

Capability Maturity Model Integration

A maturity ladder (Levels 1–5) for engineering organisations: estimation, verification, process discipline. Benefits: predictable large-project delivery. Use case: large government and enterprise software tenders often require CMMI Level 3+ — on our roadmap as the team scales.

DPDP Act 2023Compliance programme live

India's Data Protection Law

Not a certification but a legal obligation — consent, purpose limitation, grievance officer, breach response. Benefits: lawful processing, customer trust. Use case: baked into our Privacy Policy, contracts and hosting architecture (data residency in India, in-state options at the Lucknow edge).

Preparation guides and self-certification checklists for each standard are maintained in the certifications/ folder of this project — instruction sheets on how to prepare, implement and honestly self-declare conformance until accredited audits complete.

Why This Page Exists

Standards are how small firms earn big-firm trust

Clients rarely read our code, and they cannot sit in our NOC at 3 a.m. What they can do is ask: which frameworks do you run on, and can you show evidence? Practising these standards today — and certifying on a public timeline — is our answer. It also makes us better: every checklist in our certifications folder has already caught real gaps before customers ever felt them.

Team reviewing process documentation together

Internal audit day: evidence first, certificates second.

Quick Query

Need a partner who takes standards seriously?

Tell us what you are building or what is slowing you down — we reply with a clear, honest plan.

  • Response within one business day — usually much faster
  • You talk to engineers, not a sales script
  • Your details stay with us — see our Privacy Policy
Captcha code

By submitting, you agree to be contacted about your enquiry and accept our Privacy Policy. Your query is stored securely and never sold.

Get Started

Let's build something that lasts.

From a single landing page to a rack in our Lucknow edge data center — talk to a real engineer today and get a straight answer.