IASME Cyber Assurance is a flexible, affordable standard that demonstrates your organisation has the right controls in place to manage cyber risk. Sophlee guides you through every step, from readiness to certification.
Trusted by SMEs, enterprises and public sector organisations across the UK.
A comprehensive, flexible and affordable way to achieve cyber resilience, recognised across industry sectors as proof that your organisation manages cyber risk within the supply chain.
Gaining certification provides a structured, realistic-cost way to show customers, partners and regulators that you take cyber risk seriously — without the complexity of broader international standards.
Want to see the standard itself first? IASME publish the official question sets, templates and downloadable standards directly.
The standard is broad in scope, so IASME tailors the depth of assessment to your organisation's size — reducing the compliance burden for smaller businesses.
Two-person partnerships and sole practitioners get a right-sized assessment, not the full enterprise standard.
Proportionate requirements for small teams, without the overhead built for much larger organisations.
A fuller set of themes and requirements, matched to a growing organisation's real risk profile.
The full depth of the standard, appropriate for organisations with more complex supply chains.
A risk-based standard made up of controls divided into fourteen themes, covering four major areas. Your organisation needs to meet the requirements of every theme that applies to your size.
Having a good understanding of your key information assets is essential in order to know what you need to protect.
Be aware of legal obligations, contractual requirements and agreements and ensure you are fulfilling your responsibilities.
Understand what the risks are to your business and manage them to keep an acceptable level of risk for you, your customers, and supply chain.
A clear structure is the foundation for effective security, including who is responsible for information safety and who is accountable when incidents happen.
Include information security within your planning — for projects, procurement, contracting, suppliers, and when dealing with partners and other interested parties.
Protect your information assets from physical threats such as theft or loss and environmental harm such as damage from temperature or humidity.
Thorough and consistent measures are required to screen and train all staff to understand and comply with the security responsibilities of their job.
Policies specify the rules, guidelines and regulations you require people to follow, and reflect the values and ethics at the heart of your business.
Best practice access control uses the law of 'least privilege' — giving users access to everything necessary for their role, but no more.
Develop capabilities to monitor and respond to unauthorised access and usage, including anti-malware solutions and insider-threat measures.
A well-documented procedure for operational and technological changes ensures smooth transitions and helps maintain business continuity.
Creating processes to track and monitor information systems is important in order to detect threats and analyse and act on that information.
Regularly backing up information, and having the ability to restore it, may be one of the most effective ways to protect against accidental or malicious tampering.
A resilient company is one that is able to respond to an incident, keep operating through it, and eventually recover.
We check your current controls and confirm your Cyber Essentials certificate is in place.
Complete the online self-assessment with our support, scaled to your organisation's size.
A senior member of your organisation e-signs to confirm the answers are accurate.
A qualified external Assessor reviews and marks your submission.
Optional — for organisations that need audited assurance, we support you through it.
We prepare the evidence and answers in advance, so sign-off is a formality, not a scramble.
A self-assessment reviewed by an independent Assessor — the starting point for every organisation.
An independent audit of your processes, procedures and controls, for organisations that need a higher bar of assurance.
Set by IASME, based on your organisation's size. Sophlee guides you through the whole process either way.
A valid Cyber Essentials certificate is a prerequisite. If you don't already hold one, it's added at checkout — also priced from £320 + VAT for a micro organisation. The scope of both certifications must cover your whole organisation. Level Two Audited pricing is quoted individually.
We help prepare your evidence and answers before submission, rather than just pointing you at a portal.
Since Cyber Essentials is a prerequisite, we can arrange both certifications through the same account.
From readiness review through to Level Two audit support, you deal with the same team throughout.
Certification doesn't last forever — we help make sure yours stays current, not lapsed and forgotten.
Tell us about your organisation, and we'll map out the right route to IASME Cyber Assurance certification.
Yes. A valid Cyber Essentials certificate with at least one month remaining is a prerequisite. If you don't already hold one, we can arrange it alongside your IASME Cyber Assurance application. Both certifications must cover the whole of your organisation, not just part of it.
Level One is a self-assessment reviewed by an independent Assessor. Level Two is a full audit of your processes and controls, and can only be applied for once Level One is complete.
Level One pricing is set by IASME based on your organisation's size, from £320 + VAT for micro organisations. Level Two Audited pricing is quoted individually depending on scope.
Yes. The standard is scaled down for sole traders and small partnerships, so the assessment stays proportionate to your size.
No. Level Two is optional, for organisations that need audited assurance rather than a verified self-assessment.
The Cyber Essentials prerequisite works a little differently outside the UK. Get in touch and we'll talk through how it applies to your organisation.