Governance, Compliance & Assurance

Certification & Compliance, Made Straightforward

Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, DfE and NIS compliance — Sophlee is an accredited certification body, not just a consultant helping you apply elsewhere.

Reviewing cyber security governance and compliance
🏢 Est. 2008 🎓 Cyber Essentials & CE+ Certification Body 📜 IASME Cyber Assurance Certification Body 🇬🇧 ISO 27001

The Standards We Cover

Five certifications, one accredited partner

🎓

Cyber Essentials

A base-level appreciation of cyber security via an online questionnaire covering five key controls, examined by an accredited Cyber Essentials assessor against NCSC requirements.

🛡️

Cyber Essentials Plus

Builds on Cyber Essentials with an active, on-site assessment that validates a subset of the five control categories are genuinely implemented, not just declared.

📜

IASME Cyber Assurance

An affordable, achievable alternative to international standards, accepted by bodies including the UK Ministry of Justice — a legitimate way for SMEs to prove compliance.

🏫

DfE Compliance

Guidance under the Department for Education's cyber security standards for schools and colleges, updated for the current threat landscape as of January 2024.

⚖️

NIS Compliance

Support against the Network and Information Systems Regulations 2018 — 14 principles across managing risk, protecting against attack, detection and incident response.

What Is Governance, Compliance & Assurance?

Proof that your defences actually work

Cybersecurity assurance is about regularly assessing and validating your security controls, policies and procedures — instilling confidence in customers, partners and regulators.

It identifies gaps in your defences, drives continuous improvement, and ultimately helps you navigate the complex landscape of cyber risk with genuine evidence, not guesswork.

Compliance review meeting

“Secure Today, Secure Tomorrow, Secure Your Future”

Whether you're safeguarding basic contact details or confidential personal data, knowing others depend on you to protect it can feel overwhelming. Vulnerability scans, security software, audits, user education — the list is endless. We help you through the whole journey.

Our 3 Step Process

Alleviating the burden of compliance from your shoulders

1
💬

Get In Touch With Us

Reach out for a conversation about your business and which certifications matter to you. We'll determine the optimal plan.

2
📊

Agnostic Approach

After hearing your input, we'll recommend the certifications we believe offer the most value. You're welcome to propose adjustments.

3
🛠️

Design, Deploy & Support

As a reliable, independent partner, we'll guide you through every stage — from assessment to certification and ongoing renewal.

🎓 Cyber Essentials
🛡️ Cyber Essentials Plus
📜 IASME Cyber Assurance
🏫 DfE Compliance
⚖️ NIS Compliance

Glen was always able to provide prompt and professional advice and support, which is why we trust Sophlee with our annual Cyber Essentials renewals.

Nick BridelDirector, Tropical Marine Centre Ltd

FAQs

Frequently Asked Questions

Is Sophlee an actual certification body, or just a consultant?
Sophlee is an accredited Cyber Essentials and Cyber Essentials Plus certification body, and an IASME Cyber Assurance certification body. We assess and certify directly — you don't need to apply to a separate third party.
What's the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessed questionnaire covering five key controls, checked by an accredited assessor. Cyber Essentials Plus adds an active, on-site technical assessment that verifies those controls are genuinely implemented — and requires Cyber Essentials certification first.
Do you support schools and academy trusts with DfE compliance?
Yes. We provide insight into the DfE's cyber security guidance for schools and colleges, helping you meet the current standard and evidence your posture.
Can compliance work alongside your Managed SOC & SIEM service?
Yes. Our 5Eyes Managed SOC & SIEM service can provide supporting evidence around monitoring, vulnerability management and incident visibility for several of these standards.
How long does certification typically take?
It depends on the standard and your starting point. Get in touch and we'll assess your business and recommend the right plan and realistic timeline.

Ready to get certified, or want ongoing monitoring too?

Purchase Cyber Essentials directly, or see our fully managed 5Eyes SOC & SIEM platform.

Why wait?

Partner with Sophlee today and start your journey towards compliance excellence, fortified cybersecurity, and genuine peace of mind.

Let's Chat.

+44 (0) 1785 512210

support@sophlee.com

Contact Sophlee