Cognisys Group Ltd is a CREST-accredited UK cybersecurity firm holding CREST Penetration Testing, Application Security Testing and Mobile Application Security Testing accreditations plus ISO 27001 and UK NCSC Cyber Essentials Plus.
“Cognisys Group Ltd — CREST Accreditations: Penetration Testing, Application Security Testing (formerly OVS), Mobile Application Security Testing — Additional Certifications: ISO 27001, ISO 9001, UK NCSC Cyber Essentials, UK NCSC Cyber Essentials Plus, UK NCSC Cyber Essentials Assessor status — Membership Duration: 7 years”
What's verified. By what evidence. When.
The proof page lists every verification record contributing to this provider's standing. Date and level are public; client identity is anonymised unless the client opts in; underlying data sources are held in the evidence vault.
The record, level by level.
Every level this provider has earned, with what the records at that level actually are, not a generic description. Underlying artefacts live in the evidence vault; what's disclosable is shown here.
- L0Listed
Seeded from the public record. Not yet claimed by the provider.
- L1Claimed
A verified owner claims the listing and completes the structured profile.
Cross-referenced against public record.
Trustgent-attested checks of this provider's claims against independent public sources it does not control. Each item links to the source and shows when it was checked.
Verified privately. Displayed publicly.
Trustgent verifies privately and displays publicly. The evidence vault holds the underlying artefacts, analytics screenshots, exported CSVs, dashboard read-only access tokens, audited reports. The public proof page surfaces only what the client has agreed to disclose: typically the metric, the window, and an anonymised reference to the engagement.
Every record carries its last-verified date so recency is visible on the page. Automated decay + renewal is designed but not yet live, the schedule (~24 months for L3 ratings, 18 for L4, 12 for L5) ships with the concierge intake documented on how we verify. Until then, records can be revised or retracted via the correction flow, nothing here is set-and-forget.
