Some organizations are regulated by name. Others are regulated by their customers.
If the product is software, or the business runs on it, the toolchain is not a back-office concern. It is the thing a buyer, an auditor or a named customer will ask you to answer for — and the questions arrive whether or not a regulator ever put you on a list.
We sit in the first line. We do not perform validation, independent review or effective challenge on our own work, and nothing we deliver is designed to stand in for your second or third line.
There may be no supervisor with your name on a list. There is always a customer who treats you as if there were.
Nothing on this page depends on a regulator. It depends on the fact that your buyers have their own regulators, and the questions travel down the supply chain intact.
An estate nobody owns is not a tidiness problem. It is an operating risk, and it is one a buyer will find during diligence rather than one you will find first.
AskCould you describe the estate to a customer who intends to test it?
The answers have to come from the record rather than from a slide assembled for the request. Assembly is the cost, it repeats, and it never appears on the plan.
AskHow long did the last one take you?
The European Supervisory Authorities designated the first nineteen critical ICT third-party providers in November 2025, and the subcontracting RTS reached the Official Journal in July 2025. Questions that used to stop at your customer now reach you.
AskDo you know which of your customers are inside DORA?
A change proposed by a model is still a change, and somebody is still named as the person who accepted it. That name is the thing a questionnaire is eventually going to ask for.
AskWhen a machine proposes a change, who accepts it?
The questions arrive without a supervisor.
These are what software-dependent organizations are actually asked. We name them because they shape the work, and we claim nothing about your standing under any of them.
| What is measured | Whose figure, and when | Why it is on this page |
|---|---|---|
| SOC 2 Type II and ISO/IEC 27001 — the report and the certificate your customers ask for first, covering the design and operating effectiveness of controls over a period. | Reign Ops holds SOC 2 Type II. Current attestation and certification status is provided on request under non-disclosure. | Whether it satisfies a given buyer is their determination and not a claim we make here. Security and trust → |
| ISO/IEC 42001:2023 — an AI management system: stated policy, defined roles, risk assessment, documented controls, continual improvement that produces records. | Published 18 December 2023, unchanged. We hold no certification under it. | Procurement teams at regulated buyers are starting to require it of software suppliers. Treat any global certification count you are shown with suspicion; the circulating figures do not trace to ISO or an accreditation body. |
| Customer due diligence — right to audit, sub-processor lists, data-residency answers, and who can reach production. | Continuous. No publication date, and no version to be current with. | These are operating facts rather than documents. They should not take a project to assemble, and the fact that they usually do is the argument on this page. |
| DORA, indirectly — your regulated customers now carry named critical-provider obligations and a subcontracting standard. | Applying since 17 January 2025. First 19 critical providers designated 18 November 2025. | You are unlikely to be designated. You are very likely to be asked, by a customer who was. |
Naming a framework is not a claim of standing under it. Beyond the SOC 2 Type II attestation stated above and on security and trust, iTmethods holds no certification, authorization or accreditation under any framework named on this page.
We operate the estate and we record how the work was done.
We do not certify you to your customers and we do not sit in your second line. Your teams keep the tools they chose; what changes is that the estate has an owner and the record exists before somebody asks for it.
Where this sits against the rest of Reign.
Four motions at four different stages of maturity. We state the stage every time, because a buyer will ask which stage a thing is at, and the answer has to be the same every time.
A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both are available today, which includes deployment into your own cloud account; Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options →
Who holds what, when the questionnaire lands.
Written down before anything is deployed, so the boundary is a document rather than a discovery during somebody else’s diligence.
| Who | What they hold |
|---|---|
| iTmethods | Operate the delivery toolchain as a single-tenant dedicated instance, to your change control. Record what changed, who approved it and when. Keep the record readable without us. |
| You | Which tools your engineers use. Your code review, branch and release policy, unchanged. Every merge decision. What you tell a buyer, and whether the record answers what they asked. |
| Nobody, ever | We do not certify you to your customers, we do not sit in your second line, and we do not answer a questionnaire on your behalf. We supply the material the answer comes from. |
The questions that arrive every time.
Do you hold SOC 2?
Do you have ISO 42001?
Will this help us answer a security questionnaire?
What can you actually evidence today?
Which deployment shapes can we have?
Bring us the estate a buyer would ask about.
We will tell you what we would take on, what we would leave alone, and what the record would look like at the end of it.