IASME Cyber Assurance | Sophlee
UK Cyber Security Standard SOPHLEE COMPLIANCE

IASME Cyber Assurance

A Roadmap to Cyber Resilience

IASME Cyber Assurance is a flexible, affordable standard that demonstrates your organisation has the right controls in place to manage cyber risk. Sophlee guides you through every step, from readiness to certification.

A business handshake signifying a successful partnership, representing trust and certification

Trusted by SMEs, enterprises and public sector organisations across the UK.

AT A GLANCE

What is IASME Cyber Assurance?

A comprehensive, flexible and affordable way to achieve cyber resilience, recognised across industry sectors as proof that your organisation manages cyber risk within the supply chain.

  • A roadmap to cyber resilience for every organisation
  • Scaled to fit, from sole traders to large enterprises
  • Requires a valid Cyber Essentials certificate first
  • Available at two levels — Verified Assessment and Audited
WHY IT MATTERS

Cyber resilience, demonstrated

Gaining certification provides a structured, realistic-cost way to show customers, partners and regulators that you take cyber risk seriously — without the complexity of broader international standards.

  • Build genuine cyber resilience, not just a certificate
  • Provide assurance across your supply chain
  • Establish trust with customers and partners
  • Demonstrate legal and regulatory compliance

Want to see the standard itself first? IASME publish the official question sets, templates and downloadable standards directly.

TAILORED TO YOUR ORGANISATION

Scaled to fit, not one-size-fits-all

The standard is broad in scope, so IASME tailors the depth of assessment to your organisation's size — reducing the compliance burden for smaller businesses.

Sole Trader

1–2 People

Two-person partnerships and sole practitioners get a right-sized assessment, not the full enterprise standard.

Micro Business

3–9 People

Proportionate requirements for small teams, without the overhead built for much larger organisations.

Small Business

10–49 People

A fuller set of themes and requirements, matched to a growing organisation's real risk profile.

Medium / Large

50+ People

The full depth of the standard, appropriate for organisations with more complex supply chains.

THE STANDARD IN DETAIL

The fourteen themes of IASME Cyber Assurance

A risk-based standard made up of controls divided into fourteen themes, covering four major areas. Your organisation needs to meet the requirements of every theme that applies to your size.

Identify & Classify

5 themes

Identifying and protecting assets

Having a good understanding of your key information assets is essential in order to know what you need to protect.

Legal and regulatory landscape

Be aware of legal obligations, contractual requirements and agreements and ensure you are fulfilling your responsibilities.

Assessing and treating risks

Understand what the risks are to your business and manage them to keep an acceptable level of risk for you, your customers, and supply chain.

Organisation

A clear structure is the foundation for effective security, including who is responsible for information safety and who is accountable when incidents happen.

Planning information security

Include information security within your planning — for projects, procurement, contracting, suppliers, and when dealing with partners and other interested parties.

Protect

6 themes

Physical and environmental protection

Protect your information assets from physical threats such as theft or loss and environmental harm such as damage from temperature or humidity.

People

Thorough and consistent measures are required to screen and train all staff to understand and comply with the security responsibilities of their job.

Policy realisation

Policies specify the rules, guidelines and regulations you require people to follow, and reflect the values and ethics at the heart of your business.

Managing access

Best practice access control uses the law of 'least privilege' — giving users access to everything necessary for their role, but no more.

Technical intrusion

Develop capabilities to monitor and respond to unauthorised access and usage, including anti-malware solutions and insider-threat measures.

Change management

A well-documented procedure for operational and technological changes ensures smooth transitions and helps maintain business continuity.

Deter & Detect

1 theme

Secure business operations: monitoring and review

Creating processes to track and monitor information systems is important in order to detect threats and analyse and act on that information.

Respond & Recover

2 themes

Backup and restore

Regularly backing up information, and having the ability to restore it, may be one of the most effective ways to protect against accidental or malicious tampering.

Resilience: business continuity, incident management and disaster recovery

A resilient company is one that is able to respond to an incident, keep operating through it, and eventually recover.

HOW CERTIFICATION WORKS

From readiness to certified

📋

Readiness Review

We check your current controls and confirm your Cyber Essentials certificate is in place.

📝

Level One Assessment

Complete the online self-assessment with our support, scaled to your organisation's size.

✍️

Board Sign-Off

A senior member of your organisation e-signs to confirm the answers are accurate.

🔎

Independent Review

A qualified external Assessor reviews and marks your submission.

🛡️

Level Two Audit

Optional — for organisations that need audited assurance, we support you through it.

BOARD SIGN-OFF

A straightforward step, not a hurdle

We prepare the evidence and answers in advance, so sign-off is a formality, not a scramble.

CERTIFICATION LEVELS

Two levels, one standard

Level One

Verified Assessment

A self-assessment reviewed by an independent Assessor — the starting point for every organisation.

  • Online self-assessment questionnaire
  • Board-level e-signature confirming accuracy
  • Reviewed and marked by a qualified external Assessor
  • Requires a valid Cyber Essentials certificate
Level Two

Audited

An independent audit of your processes, procedures and controls, for organisations that need a higher bar of assurance.

  • Conducted by an IASME assured Assessor
  • Documentation review and staff interviews
  • Can be completed in person or remotely
  • Requires Level One certification first
LEVEL ONE PRICING

Priced by organisation size

Set by IASME, based on your organisation's size. Sophlee guides you through the whole process either way.

Micro

0 - 9 Employees
£ 320
+ VAT
Choose Plan

Small

10 - 49 Employees
£ 440
+ VAT
Choose Plan

Medium

50 - 249 Employees
£ 500
+ VAT
Choose Plan

Large

250+ Employees
£ 600
+ VAT
Choose Plan

A valid Cyber Essentials certificate is a prerequisite. If you don't already hold one, it's added at checkout — also priced from £320 + VAT for a micro organisation. The scope of both certifications must cover your whole organisation. Level Two Audited pricing is quoted individually.

WHY GO THROUGH SOPHLEE

Guided, not just assessed

Guided, not just assessed

We help prepare your evidence and answers before submission, rather than just pointing you at a portal.

Cyber Essentials, already sorted

Since Cyber Essentials is a prerequisite, we can arrange both certifications through the same account.

One point of contact

From readiness review through to Level Two audit support, you deal with the same team throughout.

Renewal reminders

Certification doesn't last forever — we help make sure yours stays current, not lapsed and forgotten.

Ready to build cyber resilience?

Tell us about your organisation, and we'll map out the right route to IASME Cyber Assurance certification.

01785 512210
FREQUENTLY ASKED QUESTIONS

Some questions we hear often

Do we need Cyber Essentials first?+

Yes. A valid Cyber Essentials certificate with at least one month remaining is a prerequisite. If you don't already hold one, we can arrange it alongside your IASME Cyber Assurance application. Both certifications must cover the whole of your organisation, not just part of it.

What's the difference between Level One and Level Two?+

Level One is a self-assessment reviewed by an independent Assessor. Level Two is a full audit of your processes and controls, and can only be applied for once Level One is complete.

How is pricing determined?+

Level One pricing is set by IASME based on your organisation's size, from £320 + VAT for micro organisations. Level Two Audited pricing is quoted individually depending on scope.

Can sole traders apply?+

Yes. The standard is scaled down for sole traders and small partnerships, so the assessment stays proportionate to your size.

Do we have to complete Level Two?+

No. Level Two is optional, for organisations that need audited assurance rather than a verified self-assessment.

What if our organisation is based outside the UK?+

The Cyber Essentials prerequisite works a little differently outside the UK. Get in touch and we'll talk through how it applies to your organisation.

© Sophlee. IASME Cyber Assurance.