Supplier assurance

Independent assurance for appointing MaxIron

Five external signals help procurement establish the supplier baseline: independently certified security and quality systems, a UK Government Cyber Essentials assessment, an IBM relationship you can verify, and a public-sector buying route with published terms.

Current assurance

Five external signals, each with a different job

Management systems

Information security
ISO/IEC 27001:2022 certification for the MaxIron information security management system, issued by ISOQAR, UKAS-accredited Certification Body 0026. Verify certificate 27274.
Quality management
ISO 9001:2015 certification for how MaxIron plans, reviews and improves IBM Maximo services and MaxIron Cloud, under the same ISOQAR certificate. Verify certificate 27274.
Cyber hygiene baseline
Cyber Essentials certification for Maxiron Ltd, whole-organisation scope, under the NCSC scheme. View the digital certificate or search the NCSC register.

Partner and procurement status

IBM relationship
IBM Gold Partner, listed for IBM Maximo Application Suite across service provider, software, integration, managed service and security roles, with MAS resale authorisation. View the IBM Partner Plus profile.
Public-sector route
MaxIron services are available through UK Crown Commercial Service G-Cloud 14 framework terms. View the Digital Marketplace listing.

These signals establish a supplier baseline. They do not replace the engagement-specific review of scope, controls, service levels, commercial terms or delivery evidence.

Decision support

The procurement question each external signal answers

Start with the question your approval process needs to settle. Then use the evidence for that decision, without stretching it into a claim it cannot support.

  1. A1

    Does the supplier operate a recognised information security management system?

    Independent evidence
    ISO/IEC 27001:2022, independently certified by ISOQAR within a published scope.
    Decision supported
    MaxIron has a control system that is audited against the standard. Your security review still needs to confirm the engagement scope and shared responsibilities.
  2. A2

    Is delivery governed by a repeatable quality system?

    Independent evidence
    ISO 9001:2015, independently certified by ISOQAR for the design and delivery of IBM Maximo services and MaxIron Cloud.
    Decision supported
    Planning, review, corrective action and continual improvement sit inside an audited management system. The certificate does not predict your programme outcome.
  3. A3

    Is MaxIron recognised by IBM for the work and licensing in scope?

    Independent evidence
    IBM Partner Plus Gold status and the Maximo Application Suite roles shown in IBM's directory.
    Decision supported
    The IBM relationship and relevant authorisations can be checked independently. Delivery capability should then be assessed through the proposed team, plan and comparable work.
  4. A4

    Can a UK public-sector organisation buy through an established framework?

    Independent evidence
    Crown Commercial Service G-Cloud 14 supplier listing with published service definitions and framework terms.
    Decision supported
    A compliant call-off route is available. The listing is a procurement mechanism, not a government endorsement or supplier ranking.
  5. A5

    Does the supplier meet the UK Government Cyber Essentials baseline?

    Independent evidence
    Cyber Essentials, whole-organisation scope, under the NCSC scheme. Certificate a1861082-1657-425c-9aae-4f553f71aae2.
    Decision supported
    MaxIron was assessed as meeting the Cyber Essentials implementation profile against commodity cyber attacks. The certificate is not Cyber Essentials Plus, does not replace ISO 27001, and does not guarantee remaining defence.

References A1 to A5 are stable for questionnaire responses. Where this page and the source register disagree, rely on the source register and ask MaxIron to correct this page.

The threshold, not the verdict

These assurance signals reduce the work needed to qualify MaxIron. They do not make the appointment decision for you.

After qualification, assess the proposed scope, named team, service levels, control ownership, commercial terms and comparable delivery evidence against the consequence of failure on your estate.

Engagement diligence

What remains contract-specific

Your service scope
The Maximo applications, integrations, cloud regions, data categories and division of responsibilities belong in the service description. The Trust Centre provides the starting control model.
Service levels and recovery
Support hours, response targets, recovery objectives, backup retention and maintenance windows must match the operational consequence of failure on your estate.
Commercial and legal terms
Pricing, liability, data-processing terms, intellectual property, transition assistance and exit obligations are agreed for the engagement, not inferred from a certificate.
Evidence from comparable work
The proposed team, delivery plan and relevant outcomes matter after supplier qualification. Start with the published case studies, then request references appropriate to the scope.

For your assurance workflow

Supplier assurance pack

Current evidence, supplied against your questionnaire

  • Current ISO certificates and the certified scope statement
  • Current Cyber Essentials certificate, whole-organisation scope
  • Direct IBM Partner Plus and G-Cloud verification links
  • Security control summary, sub-processor list and shared-responsibility position
  • Statement of Applicability under NDA where Annex A mapping is required

Send the questionnaire, decision date and scope under review. MaxIron answers in your format and identifies any item that must be settled in the contract.

Qualify MaxIron against your requirements.

Bring the supplier standard, security questionnaire and intended buying route. We will return evidence against each requirement and identify what still belongs in the engagement terms.

Useful for the first exchange

  • Your supplier assurance or pre-qualification questionnaire
  • The security and quality standards your approval panel requires
  • The IBM Maximo services, environments and data categories in scope
  • Your procurement route and decision date