Skip to content

Digital ISO 27001 certificates with real-time status control

3CT Security use BlockMark Registry to issue and manage their ISO 27001 certificates.

About 3CT Security
3CT Security is a UK-based cyber security consultancy specialising in affordable, practical protection for organisations of all sizes. Alongside Cyber Essentials and Cyber Essentials Plus, GDPR compliance and cyber security awareness training, 3CT Security provides ISO 27001 consultancy — helping clients implement an Information Security Management System (ISMS) and guiding them through certification and ongoing audit. On occasions 3CT Security are the auditors for ISO 27001 accreditation. With more than 15 years of combined industry experience, the team has built a reputation for combining rigorous standards with a genuinely people-first approach, working with organisations across the globe.

The Challenge
ISO 27001 certificates are typically issued for a three-year term, but that validity isn’t unconditional. Certified organisations must pass annual surveillance audits to demonstrate their ISMS remains effective, and if a client fails an audit, or a serious non-conformity comes to light, the certificate needs to reflect that immediately — not just at renewal.

A static PDF certificate can’t do this. Once issued, it says the same thing for three years regardless of what happens in between, leaving 3CT Security with no reliable way to change a certificate’s status mid-term or to make sure anyone relying on it — clients, auditors, or a certified organisation’s own customers — sees the current picture rather than a historic snapshot.

3CT Security needed a way to issue ISO 27001 certificates that stayed live for the whole three-year cycle: certificates that could be suspended or revoked the moment a problem was confirmed, and reinstated just as easily once it was resolved.

The Solution
3CT Security now issues its ISO 27001 certificates through BlockMark Registry, giving each certified client a digital certificate that stays connected to its real-world status throughout the full three-year term. Where an annual audit raises a concern, or a non-conformity needs to be addressed, 3CT Security can suspend or revoke the certificate directly on the platform. The change is reflected instantly on the certificate’s live status page, so anyone checking it — during that window — sees an accurate, current result rather than an out-of-date “valid” status.

The effect carries through to how the certificate is displayed elsewhere, too. Certified organisations can embed a smart badge on their own website or email footer, showing their ISO 27001 status at a glance. If 3CT Security suspends or revokes the underlying certificate, the badge disappears automatically until the issue is resolved and the certificate is reinstated — with no manual follow-up required from 3CT Security to have it removed.

This turns what used to be a fixed, point-in-time document into a live record of certification status, giving 3CT Security a straightforward way to enforce the ongoing conditions behind an ISO 27001 certificate, not just the initial award.

Results

  • Full three-year lifecycle management for ISO 27001 certificates, not just a one-off issuance at the point of award
  • Mid-term suspension and revocation, giving 3CT Security a direct way to act when an annual audit uncovers a problem
  • Real-time status reflected on each certificate’s live page, so the certificate always shows the current position
  • Automatic removal of smart badges on suspension or revocation, without any manual intervention by 3CT Security or the client
  • Greater confidence for stakeholders that an ISO 27001 badge or certificate in front of them is currently valid, not simply valid when first issued

Looking Ahead
As more of 3CT Security’s clients build ISO 27001 into how they demonstrate trust to their own customers, having certification that updates in step with real-world compliance — rather than a static document — gives 3CT Security a stronger, more defensible way to stand behind every certificate it issues.

“Our clients’ ISO 27001 certificates, and the stakeholders that rely on them, need to mean something for the full three years, not just on the day we issue them. BlockMark Registry lets us act immediately if an audit raises a concern, all from an intuitive platform that gives us centralised control and visibility.”

Cameron Lewis, Co-founder & CEO, 3CT Security

 

Give it a go, or find out more?

If you’re feeling confident sign in and create your first scheme. Here’s our knowledge base and our price list.

If you’d like some help first or want to discuss your requirements, just get in touch…