You are choosing who builds your software. So far you have a portfolio, two case studies, three referees who all said lovely things, and a call that went well.
Every one of those was produced by the supplier.
That is not an accusation. It is the normal shape of a sales process, and we do exactly the same thing. But it means that at the point you sign, almost everything you know about the company comes from the company. We made this argument about AI vendors in August — that most evaluation checklists ask you to verify things you can't. This is the other half of it, and for a UK software supplier the answer is better than you'd expect.
There are five public registers. They are free. They took us about thirty minutes to work through on a real company, and none of it requires telling the supplier you're looking.
One number for why it's worth the half hour. The five-year survival rate for UK businesses born in 2019 is 38.4% — three in five were gone inside five years. You are not buying a project. You are buying a relationship that has to outlast the build, the warranty, and the years of enhancement that follow it.
The five registers
Register | What it costs | What it tells you |
|---|---|---|
Companies House | Free | Age, ownership, who's really behind it, filing discipline, borrowing, whether it's about to be struck off |
ICO register of fee payers | Free | Whether a company that will hold your customers' data has registered to do so |
Cyber Essentials certificate search | Free | Whether the certification on their footer is real and still valid |
Check a UK VAT number (HMRC) | Free | That the VAT number on the invoice belongs to the company you think you're paying |
The Gazette | Free | Strike-off and insolvency notices, which appear here first |
Most people check one of these, badly, and stop. The value is in reading them together.
Companies House: what to actually read
Everyone knows to "look them up on Companies House". Almost nobody knows what they're looking at. Here is the order we go in.
Incorporation date and previous names. A company can be new without being inexperienced — people leave agencies and start their own. But a name change is worth a second look, particularly a recent one, and particularly if the old name is hard to search. Companies House shows every previous name with the dates.
The officers tab, including resigned officers. Three directors appointed and resigned in eighteen months tells you something a team page never will. So does a sole director who is also the sole shareholder — not a problem, but it means the bus factor on your project is one person, which is a legitimate thing to plan around.
Persons with significant control. Who actually owns it. If the PSC is another company, follow it. If the PSC entry says nothing can be identified, ask why.
Identity verification — and this one is new. Since 18 November 2025, anyone becoming a director or PSC must verify their identity with Companies House, and existing directors provide their personal code with the company's next confirmation statement. Companies House is explicit that "not complying with identity verification requirements on time is an offence", with financial penalties, referral to the Insolvency Service and prosecution available. More than 1.5 million people had verified before the deadline. What this means for you in 2026: the register is, for the first time, telling you something about whether the people named on it are real.
Accounts — and specifically the filing history. Private companies file within 9 months of the accounting reference date (first accounts, 21 months from incorporation). Late filing triggers an automatic penalty on a published scale:
How late | Penalty |
|---|---|
Not more than 1 month | £150 |
1–3 months | £375 |
3–6 months | £750 |
More than 6 months | £1,500 |
And: "the late filing penalty will be doubled if accounts are filed late in 2 successive financial years."
One late filing is an admin problem and almost every small company has had one. Two in a row is a different signal, and it now carries a doubled penalty the company chose to pay rather than file on time. You are about to ask this organisation to hit deadlines on your behalf.
What the accounts won't show you, yet. If they file micro-entity or small company accounts — most small agencies do — you will not see turnover or profit. You'll see a balance sheet and not much else. That is legal and normal, so don't read it as evasion. It does change from April 2028, when small and micro companies must file a profit and loss account, the abridged option is removed, and filing moves to software-only iXBRL, with the web and paper services closed. Until then, the balance sheet is what you have: look at net assets, and whether they are going up or down across three years.
Charges. Registered charges show secured borrowing. An invoice finance facility or an asset charge is ordinary commercial life. A pile of recent charges against a company pitching you a fixed-price build is worth understanding.
Any Gazette notice. If the registrar has begun compulsory strike-off, it shows in the filing history and in The Gazette, and the notice states that "at the expiration of 2 months from the date of the notice the name of the company mentioned in it will, unless cause is shown to the contrary, be struck off the register and the company will be dissolved." Two months. It is the single most time-sensitive thing on the register and it is free to check.
The ICO register: the one almost nobody checks
If a supplier is going to hold your customers' personal data — and a software supplier with production access holds all of it — they are processing personal data. Most UK controllers who do that must pay the ICO's data protection fee, and the ICO publishes the names of all fee-paying organisations on the register of fee payers, searchable by name, postcode or registration reference.
The fee is not large. It is £52 for a micro organisation (turnover up to £632,000 or no more than 10 staff), £78 up to £36 million turnover or 250 staff, and £3,763 above that. Failure to pay when you need to can be fined up to £4,000.
So the check takes ninety seconds, and the inference is narrow but real. Not all controllers must pay — exemptions exist and the ICO says so plainly. But a software agency running client systems is an unlikely candidate for one. If they're not on the register, that is a question rather than a verdict: which exemption are you relying on? An answer of "our accountant handles that" is the answer you were looking for.
There is a second-order point here that matters more than the £52. A supplier who has never thought about their ICO registration has probably never thought about the contract you need from them either — which is the next section.
Cyber Essentials and the VAT number: two ninety-second checks
Cyber Essentials. If a supplier's website footer carries the badge, the NCSC certificate search run by IASME will confirm it: company name, certificate reference, level, certification date, expiry and score, for certificates issued in the last 12 months. Certificates last a year, and the most common finding is not a fake badge — it's a real one that expired fourteen months ago and nobody took off the site.
Two honest caveats. Cyber Essentials is not a legal requirement outside certain government contracts, so its absence proves nothing about a good supplier. And the search exists for verification only — IASME states it "is solely for the use of checking certification and must not be used for marketing, data research, or any other purpose." Check your supplier, not a list of prospects.
The VAT number. HMRC's Check a UK VAT number service confirms whether a number is valid and shows "the name and address of the business the number is registered to". Thirty seconds, and it catches the mismatch that matters: an invoice whose VAT number belongs to a different entity than the one on your contract. If you are VAT registered yourself you can also "prove when you checked a UK VAT number", which is worth doing on a first invoice from anyone.
Reading the register honestly
Most "red flags when choosing a developer" content is written to make you frightened. The register rewards calibration instead. Here is what each finding actually supports.
What you find | What it means | What it doesn't mean |
|---|---|---|
Incorporated 14 months ago | The company is young. Ask what the team did before it, and don't buy a three-year support commitment from a one-year-old balance sheet | That they can't build it |
Accounts filed late once | Admin slipped, like everyone | Financial distress |
Accounts late two years running | A pattern, and one they paid double for | Insolvency — but now ask about it directly |
Micro-entity accounts, no turnover shown | Legal and standard for a small company | That they're hiding something |
Sole director, sole PSC | Your project's continuity rests on one person | That the work will be worse |
Recent name change | Worth understanding. Search the old name too | Wrongdoing |
Not on the ICO register | A question with a legitimate answer | Automatic non-compliance |
Expired Cyber Essentials on the site | Housekeeping, usually | A security incident |
First Gazette notice for strike-off | Stop. Two months on the clock | Anything you can resolve by ignoring it |
Net assets falling three years running | A conversation to have before a deposit | That they'll go under |
The useful reframe: none of this decides anything on its own. It tells you which questions to ask in a meeting you were going to have anyway — and asking a specific question you already know the answer to is the fastest way to find out how a supplier handles being asked.
The three things no register will tell you
Public records stop at the company. They say nothing about the work. Three asks close most of that gap, and all three are documents a competent supplier already has.
1. The data processing contract, before you sign anything. If they process personal data on your instructions, UK GDPR requires a contract, and Article 28(3) sets out what must be in it. The ICO's list is effectively a checklist you can hold their draft against: processing only on documented instructions, a duty of confidence, appropriate security measures, no sub-processor without "prior specific or general written authorisation" and the same obligations passed down to them, help with data subject rights, assistance with security, breach notification and DPIAs, deletion or return of all personal data at the end of the contract, and an obligation to "allow for, and contribute to, audits and inspections."
Ask for their standard version. A supplier who has one sends it the same day. A supplier who says they'll "get something drawn up" has told you that nobody has asked before.
2. The sub-processor list. That written-authorisation requirement has a practical use: it entitles you to know who else touches the data. Hosting, error monitoring, analytics, an AI API, a subcontractor in another country. The list is usually short and completely reasonable. What matters is whether it exists, because it's the difference between a supplier who knows where your data goes and one who will find out when you ask.
3. Who is actually going to do the work, and what they carry. Named people, days each, and whether they are employees or subcontractors. Then: professional indemnity insurance, level of cover, and whether it's current. None of that is on a register — it's a certificate they either produce or they don't.
Notice what these three have in common with the exit question we apply to every supplier: they're all answerable in writing, today, before there is any money or any relationship at stake. Leverage is a thing you spend, and you have the most of it right now.
The thirty-minute version
Companies House (15 min) — incorporation date, previous names, officers including resignations, PSC, filing history for late filings, charges, any Gazette notice. Read three years of accounts, not one.
ICO register of fee payers (2 min) — search the company name. Registered, or a question to ask.
Cyber Essentials search (2 min) — only if they claim it. Check the expiry date, not just the name.
Check a UK VAT number (1 min) — does the number match the entity on the contract?
Their own site (5 min) — this one isn't a register, it's a sample of their work. Does the contact form send anywhere? Does it work on a phone? Is there a registered office address, a company number and the part of the UK it's registered in — which a company is required to disclose on its website, not merely encouraged to?
Then ask for three documents (5 min to send the email) — the Article 28 contract, the sub-processor list, and the PI insurance certificate.
Whatever comes back, you now know more about the supplier than the supplier told you. That is the entire point.
The short version
Everything in a pitch is written by the person pitching. Five free UK registers aren't, and thirty minutes with them is the cheapest due diligence available to a business buying software.
Companies House is the substantial one: age, previous names, officer churn, who really owns it, and above all the filing history — one late filing is admin, two in a row is a pattern that cost them double. Since November 2025 the register also tells you whether the people on it have verified their identity. The ICO register tells you whether a company about to hold your customers' data has registered to do so. The Cyber Essentials search tells you whether the badge on the footer expired last year. The VAT checker tells you the invoice belongs to the company on your contract.
None of it decides who to hire. It decides what to ask. And the three things no register covers — the Article 28 contract, the sub-processor list, the insurance certificate — are documents a good supplier can send you before lunch.
We'd rather you ran this on us first. Symentic Technologies Limited, company number 12330122, incorporated 25 November 2019 — which makes us part of the same 2019 cohort as that survival statistic. We build custom software for hospitality and small business. Look us up before the call, not after, and ask us the questions the register raises. If you've been sent a proposal by someone else, we're happy to read it with you, whether or not we're one of the people who sent one. See what we've built, or tell us what you're trying to do.
Related reading: Nobody can price your software from a blog post · Every supplier looks the same until you try to leave · Most AI vendor checklists ask you to verify things you can't · In 2029, the invoice stops being a document




