
In critical national infrastructure, a certificate is no longer a differentiator — it is the floor a supplier must stand on before it is considered. ISO/IEC 27001 is a procurement prerequisite across UK CNI. ISO/IEC 42001 is emerging as the AI governance credential that regulated environments expect. The EU AI Act and the incoming Cyber Security and Resilience Bill have created a statutory layer above the standards. The Standards service builds the management system and readiness behind each of these — as a single, continuous, governed architecture.
Service: Standards · Reference: Service 03 · Pillar: SENTINEL · Published: April 2026 · Last updated: June 2026 · Reviewed quarterly
Reading time: 6 min read
Certification in critical national infrastructure has crossed a line. ISO/IEC 27001 is no longer evidence of maturity: in 2026 it is a baseline entry requirement, and a certificate with no operational system behind it fails on audit. ISO/IEC 42001 is the AI governance layer that procurement teams are beginning to require and that the EU AI Act points toward. The Standards service exists to make certification a real, defensible, multi-standard posture rather than a paper exercise.
Multi-standard architecture. A single management-system architecture that satisfies the relevant standards together: ISO 27001 as the security floor, ISO 42001 as the AI management layer, the EU AI Act and UK Cyber Bill mapped onto the same governance structure.
Certification readiness. The organisation built to the point where an independent, accredited certification body can assess it: scope defined, controls implemented, Statement of Applicability completed, and all required documentation in place.
Regulatory-compliance management. The EU AI Act and the incoming UK Cyber Security and Resilience regime mapped against the management system, with every instrument's legal status stated precisely.
Continuous-posture governance. The architecture run as a continuous, demonstrable state — surveillance-cycle readiness, control evidence maintained, and the posture live between formal assessments.
Direct Intelligence does not issue certificates, perform certification audits, or accredit organisations. Those functions belong to independent accredited certification bodies. The Standards service builds the system and readiness that makes certification achievable and defensible.
ISO/IEC 27001:2022 is the baseline. The 2013-to-2022 transition period closed on 31 October 2025, so a current certificate must be against the 2022 edition. The Standards service builds the ISMS — scope, risk assessment, Statement of Applicability, controls implementation, and operational evidence — to the point where an accredited certification body can perform an independent audit.
ISO/IEC 42001:2023 is the first international AI management system standard, published December 2023. It is a Type-A management system standard, third-party certifiable by independent accredited certification bodies, and certification is voluntary. The Standards service builds the AIMS as a governed layer sitting on the ISO 27001 foundation.
This layer maps statute onto the same management system, with legal status stated precisely. EU AI Act Article 50 transparency obligations take effect 2 August 2026. High-risk obligations were provisionally deferred in the 7 May 2026 Digital Omnibus agreement — standalone Annex III to 2 December 2027, product-embedded Annex I to 2 August 2028 — but this deferral is subject to formal adoption, expected July 2026. Until the Official Journal publication, the original 2 August 2026 date remains active law. The Cyber Security and Resilience Bill completed Commons passage on 10 June 2026; Royal Assent expected H2 2026 with phased implementation to 2028.
The final component is the handover: the organisation is taken to readiness and then routed to an independent accredited certification body for formal assessment. The Standards service does not conduct that audit. After certification, the posture is maintained continuously.
Standards maps to SENTINEL, the Assurance Engine — one of the six pillars of the DIRECT framework. SENTINEL governs the compliance perimeter across the DIRECT architecture.
ISO implementation, certification pathway design, multi-framework alignment
AI risk classification, bias assessment, explainability, responsible AI lifecycle governance
EU AI Act, Cyber Security and Resilience Bill, GDPR, sector-specific regulation, cross-border alignment
Cloud strategy, cyber security architecture, incident response, business continuity
Audit readiness, governance signalling, procurement documentation
Statement of Applicability, controls documentation, evidence architecture
Continuous compliance monitoring, control effectiveness tracking, assurance posture maintenance
Certification renewal, continuous improvement, regulatory evolution tracking
Treat ISO 27001 as the floor, not the destination. In 2026 it is procurement-prerequisite, and a certificate with no operational system behind it fails on audit.
Govern the regimes as one architecture, not four projects. ISO 27001, ISO 42001, the EU AI Act and the incoming UK cyber regime overlap. Managing them separately creates gaps, duplication, and a compliance posture that does not hold under scrutiny.
Build against each instrument's real legal status. EU AI Act Article 50 transparency obligations take effect 2 August 2026. The high-risk deferral is subject to formal adoption; the original 2 August 2026 date remains active law until the Official Journal publication.
Keep the certification independent and say so. The body that builds the system is deliberately not the body that certifies it. Independent certification is what makes the credential credible.
Run the posture continuously. Surveillance and recertification are the certification body's to conduct; keeping the system genuine between those events is the organisation's obligation.
No. Certification against ISO standards is performed by independent certification bodies accredited by national accreditation bodies such as UKAS. Direct Intelligence builds the system and readiness. The certification audit is performed independently.
ISO/IEC 27001:2022 is the floor, not sufficiency. In 2026 it is a procurement prerequisite across UK CNI and it substantively evidences a large part of DORA's ICT risk-management requirements, but it does not cover AI management, EU AI Act compliance, or the incoming Cyber Bill obligations. The Standards service addresses all of these as a single architecture.
ISO/IEC 42001:2023 is the world's first international AI management system standard, published December 2023. It is third-party certifiable, and certification is voluntary. If your organisation deploys, develops, or procures AI, ISO 42001 is the governance credential that regulated procurement environments are beginning to require.
EU AI Act Article 50 transparency obligations take effect 2 August 2026. High-risk obligations were provisionally deferred in the 7 May 2026 Digital Omnibus agreement — standalone Annex III to 2 December 2027, product-embedded Annex I to 2 August 2028 — but subject to formal adoption expected July 2026. The Cyber Security and Resilience Bill completed Commons passage on 10 June 2026; Royal Assent expected H2 2026 with phased implementation to 2028.
Last updated June 2026.
The Standards service rewards organisations that treat certification as an operational management system rather than a document, governed continuously rather than assembled for audit.
Request a Standards Mandate Brief →