✅ Inside Kyotu Technology’s ISO 9001 Certification: What a Quality Audit Checks in a Software Company
Kyotu Technology is ISO 9001:2015 certified - and of the two certificates we picked up this August, this is the quieter one. ISO 27001 gets the attention; "quality management" sounds like paperwork. It shouldn't: this is the certificate about the thing you actually buy from a software company - how work gets scoped, planned, delivered and measured. Below: what a quality audit really checks in a software house, why we run one management system for two standards, and where you'll feel the difference as a client.
9 min read
In this Article:
- ISO 9001:2015, certificate registration number 00082601306, issued by DEKRA Certification on 18 August 2026, valid to 17 August 2029 – checkable with the issuer, no trust required.
- One integrated audit covered ISO 9001:2015 and ISO/IEC 27001:2022 together and closed with no nonconformities in either standard.
- The certified scope covers the design, development, implementation, and maintenance of custom enterprise-class IT systems and AI/ML/LLM, Blockchain, and Big Data solutions, integration of IT systems, and DevOps services for IT and cloud infrastructure management.
- DEKRA’s auditors followed real projects end to end – from the requirement a client raised, through planning and delivery, to how the result was measured and what changed afterwards.
- Strengths named in the audit report: management working inside operations, structured project and service management, monthly financial monitoring, formal supplier qualification.
- Surveillance audits run in 2027 and 2028; recertification in 2029.
What is ISO 9001:2015?
ISO 9001:2015 is the world’s most widely adopted management standard: a certifiable framework for quality management systems (QMS). In plain terms, it sets the rules for how an organization captures what the client asked for, plans and controls the work, chooses who’s allowed to help, measures the outcome and fixes what drifts. The 2015 edition runs on risk-based thinking – rather than dictating procedures, it makes you identify what can go wrong in your processes and prove you keep those risks on a leash.
And to clear up the most common misreading: ISO 9001 is not a software quality badge. No auditor graded our code. What gets certified is the machinery around the code – requirements, planning, suppliers, feedback, improvement. Given that software projects fail on requirements and handoffs far more often than on syntax, that machinery is precisely the thing worth an external inspection.
Why did we do this – and what do we actually do better now?
Software projects rarely die of bad code. They die of a requirement nobody pinned down, scope that drifted without anyone deciding it should, a subcontractor nobody vetted, a lesson that evaporated the day the project closed. A quality system exists to keep exactly those failure modes visible – and we wanted ours graded by someone paid to be skeptical.
We didn’t build that system in 2026. 2026 is just the year we let an outsider inspect it. The habits underneath go back to the company’s first projects: listen before you code, decide fast when something hits a wall, stay flexible when scope moves. There’s a line in our values that fits this post almost too well – quality is everyone’s responsibility, not just the QA team’s. It was written as a description of how we already worked, not as an aspiration. Kaizen has been in the bloodstream from the start, long before anyone here said “clause 10.3” out loud.
What the months of ISO work added was translation: taking habits that lived in people’s heads and turning them into defined, measurable process. In practice:
- A requirement now has one life, not three. Captured once, traced through delivery, reviewed at the end – instead of existing simultaneously in an email, a chat thread and somebody’s memory.
- Every month, the numbers tell on us. Project status and financial results go through a fixed monthly review, so a drifting project surfaces while it’s still cheap to fix, not at the invoice.
- Nobody joins a project through the side door. Subcontractors and suppliers clear a formal qualification gate – contractual, confidentiality and data-processing requirements scaled to how much damage they could do.
- Risks carry name tags. One register of risks and opportunities, each entry with an owner and a follow-up date, reviewed as management routine rather than after something breaks.
- Retrospectives grew teeth. Internal audits and management reviews force lessons back into the process – and the external auditors confirmed both mechanisms genuinely operate.
Could we have done all of this without a certificate? Sure. Would it have been finished this year? Honestly, no. A booked audit date turns out to be an excellent deadline.
What does this mean for you – as our client, or a future one?
The unglamorous, practical version: what you asked for is written down and traceable, the health of your project is reviewed every month, and anyone we bring near your codebase has cleared a formal gate first. When a dispute or a scope question appears – and on long projects it eventually does – there’s a record to point at instead of competing recollections.
On the procurement side, ISO 9001 is the workhorse requirement: the certificate most often listed as a baseline in tenders and vendor onboarding, usually right next to ISO 27001 as a pass/fail pair. Yours to check, not to take on faith – one email to the issuer with registration number 00082601306 settles it. If a tender or RFP is where you’re headed, our Tenders & Procurement team lives inside these formal requirements and will hand over the certificate documentation for any proceeding.

Quality questionnaires are welcome too. Filling one used to be an archaeology project; now it’s a lookup.
Why one integrated audit for two standards?
Because a management system you run twice is a management system you run badly. From day one we built a single integrated system covering quality (ISO 9001) and information security (ISO 27001): one risk methodology, one document structure, one improvement loop, one management review. DEKRA examined it in one integrated process – five auditor-days in total, 1.25 on ISO 9001 and 3.75 on ISO 27001, across three days in our Wrocław office.

For clients, the payoff is coherence. A change request gets weighed for delivery impact and security impact in the same motion, by the same system – no gap between two rulebooks for a contradiction to hide in. The security half of the story, from Stage 1 and Stage 2 mechanics to the surveillance cycle, lives in the ISO 27001 post.
What did the auditors examine at Kyotu Technology?
On the quality side, the audit walked the delivery chain the way a project actually flows: strategic and system management, sales and client requirements, project management and service delivery, software development, deployment and maintenance, personnel and competence, subcontractors and suppliers.
Certification auditing runs on representative sampling – real projects, real records, real people, pulled and traced from the original client requirement all the way to the measured result and whatever changed because of it. Two conclusions from the report carry particular weight: the system meets the applicable requirements and achieves the expected results, and our internal audit and management review processes are effective. Those two mechanisms are what keep a QMS honest for the 12 months between external visits.

The report also names strengths, and they read like a description of the day-to-day rather than a compliance summary: management working inside operations instead of above them, a structured organization-wide approach to running projects and services, business results tracked monthly, a formal qualification process for every service provider. One more we didn’t expect to see called out: climate criteria in supplier selection – we prefer, for example, data centers running on renewable energy, and the current edition of ISO 9001 explicitly expects climate change to be considered in the organization’s context. The audit confirmed it is.
Does certification guarantee good software?
No. Nobody’s code improved because a certificate arrived in the mail. What the certificate guarantees is narrower and more useful: when something goes wrong – and on real projects something always does – there is a working mechanism that catches it, corrects it and remembers it. Audits sample; they don’t read every line of every repo. Our system was certified in 2026 on foundations laid over years, and the surveillance audits in 2027 and 2028 exist to prove the improvement loop is still turning, not just documented.
ISO 9001 vs ISO 27001: which certificate should you check for?
Both, ideally – they answer different questions about the same vendor.
| ISO 9001:2015 | ISO/IEC 27001:2022 | |
|---|---|---|
| What it certifies | Quality management system: requirements, delivery, suppliers, improvement | Information security management system: risks, controls, incidents, continuity |
| The question it answers | Will the project be delivered in a controlled, repeatable process? | Will my data, code and environments be protected under a verified system? |
| Typical procurement role | Baseline requirement in most tenders and vendor onboarding | Pass/fail requirement in regulated industries and data-sensitive projects |
| Best fit when | You’re evaluating delivery reliability and process maturity | You’re evaluating security posture and data protection |
| At Kyotu | Certificate 00082601306, valid to 17-08-2029 | Certificate 00082600610, valid to 17-08-2029 |
Both Kyotu certificates come from the same accredited body (DEKRA under PCA), the same integrated audit and carry the same scope – so the two answers are consistent by construction.
FAQ
Is Kyotu Technology ISO 9001 certified? Yes. Kyotu Technology Sp. z o.o. is certified against ISO 9001:2015, certificate registration number 00082601306, issued by DEKRA Certification Sp. z o.o. on 18 August 2026, valid until 17 August 2029.
What is the scope of Kyotu Technology’s ISO 9001 certification? The certified scope covers the design, development, implementation, and maintenance of custom enterprise-class IT systems and AI/ML/LLM, Blockchain, and Big Data solutions, integration of IT systems, and DevOps services for IT and cloud infrastructure management – as stated on the certificate.
Who issued the certificate and how can I verify it? DEKRA Certification Sp. z o.o., an accredited certification body operating under the Polish Centre for Accreditation (PCA, accreditation AC 151) with IAF Multilateral Recognition Arrangement coverage. The registration number 00082601306 can be verified with the certification body, and we provide the certificate document in any formal procurement proceeding.
Did the audit find any nonconformities? No. The integrated certification audit in July 2026 closed with no nonconformities – neither major nor minor – across both ISO 9001:2015 and ISO/IEC 27001:2022, and DEKRA approved certificate issuance for both standards on 18 August 2026.
Does ISO 9001 mean the software itself is certified? No. ISO 9001 certifies the management process around delivery – requirements, planning, suppliers, measurement, improvement – not the code. It answers “is delivery controlled and repeatable”, not “is this specific codebase flawless”.
Is Kyotu Technology also ISO 27001 certified? Yes – both certificates come from the same integrated audit. The information security side is covered in detail in the ISO 27001 post.
What this changes for our clients
If you’ve worked with us before, nothing in this post will surprise you – the monthly reviews, the supplier gate, the requirement trail were all in place before DEKRA walked in. That’s precisely why the audit closed clean. What’s new is that none of it requires taking our word anymore: registration number 00082601306, issuer DEKRA under PCA accreditation, defined scope, validity dates – all checkable from the outside.
Need the certificate documentation, the scope statement or a filled quality questionnaire for a vendor evaluation? Contact us or go straight to the Tenders & Procurement hub – the team that makes certificates earn their keep in real tenders.