What we hold, and what each one is actually for
Most vendor credential pages are a wall of logos. This one says what each credential does for you, and it says plainly where each one stops. Where we hold nothing, it says that too.
A QA company that overclaims its own credentials is telling you how it will report your bugs. That is the whole reason this page reads the way it does.
NATO NCIA Basic Ordering Agreement
NCIA can order from us without running a fresh tender
That is the commercial mechanic, and it is the only part that matters to a buyer. We are already through the agency's vendor registration under NCAGE code 1JGAL, and the commercial terms are already agreed. For a defence or NATO-adjacent programme, that is weeks taken out of a procurement cycle. Very few QA firms our size hold one.
What it is not: a certification, an approval of our testing methods, or a security clearance. There is no such thing as being NATO certified, and a real defence buyer knows it. The agreement says so on its own first page: it obligates neither party to order or to supply anything.
Read the full case study or see how to engage us through NATO procurement.
Certifications and memberships
Four ISO certificates, one supply-chain membership, one third-party ranking. One of these is rare in QA and three of them are table stakes.
The rare one. Most QA vendors carry 9001 and 27001; almost none carry 13485. It is what lets a medical device manufacturer put us on a shortlist at all, because their own quality system has to account for who tests their software.
An audited information security management system. It covers how we handle your data, your credentials and your test environments.
Documented process for how work is planned, executed and reviewed. Expected of any serious supplier, and weak to lead with.
Environmental management. It shows up in tender scoring more often than it shows up in delivery.
Supply-chain qualification, used by large buyers to pre-screen contractors. We are a member of the consortium. Avetta does not issue a certification, so nobody is Avetta certified, including us.
Top 500 B2B companies globally. This is the one credential on the page we did not award ourselves, which makes it worth more than anything else here. The reviews are published and the clients are named.
BugBoard, Flows, NIS2 Manager and the rest run on our own client work before they reach anyone else. Not a certification, and the only item here that is evidence of what we can build rather than what we filed.
What we do not claim
Every item below is something we could have put on this page and cannot support. Some of them appear on competitor pages as schemes that do not exist.
SOC 2
No report exists, and there is no self-certification route to one. Our controls have been assessed against the SOC 2 Trust Services Criteria and that documentation is available under NDA. If a vendor tells you they are SOC 2 certified, ask for the report.
NIS2 certified
There is no NIS2 certification scheme, so nobody can hold one. What we can point at: we built NIS2 Manager, and our managing director passed the DNSC-standard cyber-security auditor examination in August 2026. The certificate itself is still pending.
NATO certified or cleared
Neither is a thing. We hold a commercial ordering agreement. We hold no security clearance, and we do not take work that requires one or work involving classified material.
ISTQB as a company credential
ISTQB certifies people, not organisations. Individual engineers here hold it. BetterQA does not, because it cannot.
Two things a procurement team should check
Both of these are readable off the certificates themselves. We would rather you find them here than find them halfway through a vendor assessment.
Who issued them
Our ISO certificates are issued by RS Cert, accredited by IMAB. If your procurement rules require a specific accreditation body, check ours against that requirement early rather than late.
What the scope says
The certificate scope reads "Computer consultancy activities. Computer programming activities." It does not name testing. So do not read our ISO 27001 as third-party assurance over a specific test engagement. It assures the management system, not the service. If you need assurance over the engagement itself, that is a separate conversation and we are happy to have it.
The certificates
Open any of them. If something here does not match what this page says, tell us and we will fix the page.
Ask us the awkward question
Bring the credential requirement from your procurement form. We will tell you which ones we meet, which ones we do not, and which ones are not real schemes.
Need help with software testing?
BetterQA provides independent QA services across manual testing, automation, security audits, and performance testing. ISO 27001, 9001, 14001 and 13485 certified.