Compliance should be a first-round filter when choosing a cloud hosting provider, not a final checkbox. Your provider becomes part of your own compliance position – their certifications, audit history, and data residency directly affect your regulatory exposure, your customers’ due diligence, and your ability to win contracts.
Why does compliance matter when choosing a cloud provider?
Cloud hosting compliance is the combination of independently audited certifications, data residency guarantees, and documented controls that lets a provider – and by extension its customers – prove that data is stored, processed, and protected to regulatory standards.
When you move workloads to a hosting provider, you do not transfer your compliance obligations with them. Under UK GDPR, your business remains the data controller – responsible for where personal data sits, who can access it, and how it is protected. Your provider becomes a processor within your supply chain, and regulators, auditors, and enterprise customers will all ask the same question: how did you assess them?
That makes provider selection a compliance decision in itself. A provider with independently audited certifications gives you evidence you can put in front of an auditor, a procurement team, or the ICO. A provider without them leaves you doing that assurance work yourself – or worse, unable to answer the question at all.
It also cuts the other way. Increasingly, compliance is a revenue issue, not just a risk issue. Public sector frameworks, NHS supply chains, legal and financial services clients all run supplier due diligence that asks directly about your infrastructure. The certifications your hosting provider holds – or does not hold – show up in your own tender responses.
What happens when a provider’s compliance falls short?
The costs of getting this wrong land on you, not the provider. They fall into four categories:
- Regulatory exposure – under UK GDPR, controllers are accountable for their processors. If personal data is mishandled by your hosting provider, the ICO’s questions come to you first, and fines can reach £17.5 million or 4% of global turnover.
- Lost contracts – failed supplier due diligence is one of the quietest ways to lose a deal. If a prospect’s security questionnaire asks where their data will be stored and audited, “we’re not sure” ends the conversation.
- Operational risk – certifications like ISO 22301 (business continuity) and ISO 20000-1 (service management) are proxies for whether a provider will still be running, and answering the phone, when something breaks.
- Remediation cost – migrating away from a non-compliant provider mid-contract is expensive, disruptive, and usually happens under time pressure.

Is a certified provider the same as being compliant yourself?
No – and this distinction matters more than any individual certification. Compliance in the cloud is a shared responsibility. Your hosting provider can hold ISO 27001, Cyber Essentials Plus, and CSA STAR Level 2, and that gives you a certified foundation to build on – but it does not make your business certified, and it does not discharge your own obligations under UK GDPR, the SRA’s rules, NHS DSPT, or any other framework you answer to.
What a certified provider does is remove a whole layer of risk and evidence-gathering from your side of the ledger. Physical security, infrastructure controls, business continuity, access management at the platform level – these are audited independently, every year, so you do not have to assess them yourself. Your compliance effort can then focus on the parts only you control: your applications, your users, your data handling policies.
Be wary of any provider that blurs this line. A trustworthy provider is clear about what their certifications cover and where your responsibility begins.

Which certifications should you look for?
Not all certifications carry equal weight, and the ones that matter depend on your sector. The table below maps the certifications most relevant to UK buyers to what they actually tell you about a provider.
| Certification | What it proves | Why it matters to you |
|---|---|---|
| ISO 27001 | An independently audited information security management system | The baseline. Answers most security questionnaire questions in one line |
| ISO 27017 | Cloud-specific information security controls, extending ISO 27001 | Confirms security practices are designed for cloud services, not just adapted from general IT |
| Cyber Essentials Plus | Technical controls verified by hands-on testing, not self-declaration | Mandatory or expected in most UK public sector supply chains |
| CSA STAR Level 2 | Cloud controls audited by a third party against the Cloud Controls Matrix | Assurance designed specifically for cloud services, beyond generic ISO scope |
| ISO 22301 | Audited business continuity management | Evidence the provider can keep running – and recover – through disruption |
| ISO 20000-1 | Audited IT service management | Signals mature support processes, not just secure infrastructure |
| G-Cloud | Approved supplier on the UK government cloud procurement framework | Pre-vetted route for public sector buyers; a trust signal for everyone else |
One note on G-Cloud: the framework is currently transitioning. G-Cloud 15 went live in August 2026, and G-Cloud 14 remains operational until 28 October 2026 – so check which iteration a provider is listed on, and whether they intend to stay on the framework.
For what each certification involves, current certificate numbers, and downloadable copies, see our certifications page.
What compliance questions should you ask before signing?
Certifications are the starting point, not the finish line. Before committing to a provider, ask:
- Where, physically, will our data be stored – and can you guarantee it never leaves the UK?
- Which legal jurisdiction does your company operate under, and could foreign legislation compel access to our data?
- Can you provide current certificates, scope statements, and the name of your certification body?
- How often are you audited, and by whom?
- What does your shared responsibility model look like – what do you cover, and what remains ours?
- What are your recovery time and recovery point commitments, and are they contractual?
- How will you support our own compliance obligations – GDPR, DSPT, SRA, or sector-specific frameworks?
A provider that answers these quickly and specifically is showing you their compliance posture in real time. Hesitation, vagueness, or “our certifications cover all of that” are warning signs.
How does BlackBox Hosting approach compliance?
BlackBox Hosting holds ten independently assessed certifications and accreditations: ISO 27001, ISO 27017, ISO 22301, ISO 20000-1, ISO 9001, ISO 14001, CSA STAR Level 2, Cyber Essentials Plus, G-Cloud approved supplier status, and an ISO 14068 carbon neutrality verification issued by BSI.

We have held ISO 27001 for over ten years, with annual audits by an independent certification body – and our most recent surveillance audit was passed with zero findings. Our CSA STAR Level 2 certification is independently assessed against the Cloud Security Alliance’s Cloud Controls Matrix on top of our ISO 27001 foundations, and our entry is publicly listed on the CSA STAR Registry. Every certification is current, verifiable, and published with certificate numbers on our certifications page.
All of this sits on UK-only infrastructure, operated by a UK-incorporated company – so the jurisdiction question that undermines so many compliance positions is answered before it is asked. If you are evaluating providers for a regulated workload, our sovereign cloud and private server hosting pages set out how our infrastructure supports your compliance obligations.
“Compliance is not a page on our website – it is how we run the business. We are audited every year, by independent bodies, across nine standards. When a customer sits in front of their own auditor or a procurement panel, our certifications are part of their evidence. That is a responsibility we take seriously.”
Matt Burden, Founder and Managing Director, BlackBox Hosting
Key takeaway: Your hosting provider’s compliance is your compliance evidence. Treat certifications as a first-round filter, verify them independently, understand where their responsibility ends and yours begins, and choose a provider whose audit history you would be happy to put in front of your own customers.
Quick reference: compliance checks before you sign
- Request current certificates, scope statements, and certification body names
- Verify certificates on the certification body’s public register and the CSA STAR Registry
- Confirm data residency and legal jurisdiction in writing
- Get the shared responsibility model documented before contract
- Check recovery time and recovery point commitments are contractual, not aspirational
Frequently asked questions
No. Under UK GDPR your business remains the data controller and keeps its own obligations. A certified provider gives you a compliant infrastructure foundation and audit evidence for your processor due diligence, but your policies, applications, and data handling remain your responsibility.
No. ISO 27001 certifies a specific organisation’s management system within a defined scope. Using an ISO 27001 certified provider strengthens your supply chain assurance and simplifies your own certification journey, but the certificate belongs to the provider, not to you.
Ask for the current certificate, the scope statement, and the name of the certification body, then check the certification body’s public register. For CSA STAR, check the publicly accessible STAR Registry. A genuine provider will supply all of this without hesitation.
Cyber Essentials is a self-assessment against five core technical controls. Cyber Essentials Plus covers the same controls but adds independent hands-on technical testing, including vulnerability scans. Plus is the stronger signal and is often required in public sector supply chains.
Data stored outside the UK can fall under foreign legislation, which complicates GDPR transfer requirements and supplier due diligence. UK-only infrastructure operated by a UK-incorporated company keeps your data under a single legal jurisdiction and simplifies your compliance position.
CSA STAR Level 2 is a third-party audited certification for cloud service providers, assessed against the Cloud Security Alliance’s Cloud Controls Matrix alongside ISO 27001. Unlike Level 1, which is a self-assessment, Level 2 requires an independent audit by an accredited certification body.
ISO 27017 is an international code of practice for cloud-specific information security controls. It extends ISO 27001 with guidance written for cloud service providers and customers, covering areas like virtual machine hardening, tenant separation, and the division of security responsibilities between provider and customer.
G-Cloud is the UK government’s procurement framework for pre-approved cloud service suppliers, letting public sector bodies buy cloud services without running a full tender. G-Cloud 15 went live in August 2026, replacing G-Cloud 14, which expires on 28 October 2026.
At minimum: current certificates with scope statements, the certification bodies and audit frequency, data residency and jurisdiction confirmation in writing, a clear shared responsibility model, and contractual recovery commitments. This evidence set answers most security questionnaires and supplier due diligence processes.
