Compliance

Certifications, Standards & Regulatory Monitoring

The standards we work to, the certifications behind our hosting, and how we keep pace with UK regulation.

Trust & Compliance Centre · Last reviewed: February 2026

At a glance

Do you hold ISO 27001, ISO 9001, or other relevant certifications? Our practices align with ISO 27001 principles; formal ISO 27001 and ISO 9001 certification is held at our hosting layer by Microsoft Azure. We are a Microsoft Partner. ISO 27001 or Cyber Essentials Plus can be acquired for a specific engagement at additional cost.
Do you have processes to stay current with UK data protection and privacy regulations? Yes Ongoing monitoring of ICO guidance and UK GDPR / DPA 2018 developments, with periodic policy review

Our position on certification

Assemblysoft is a focused specialist consultancy rather than a large enterprise vendor, and we are transparent about what that means for certification: we operate our information security practices in alignment with ISO/IEC 27001 principles — risk-based controls, least-privilege access, documented incident response, and continuity planning — as described across this Trust & Compliance Centre.

Formal certification is held where it matters most: at the infrastructure layer. Customer solutions are hosted on Microsoft Azure, which is independently certified against ISO/IEC 27001, ISO/IEC 27017/27018, ISO 9001, SOC 1/2/3, and Cyber Essentials Plus, among others. Microsoft's certificates and audit reports can be verified directly via the Microsoft Service Trust Portal and the Azure ISO 27001 compliance offering — see Hosting & Data Residency for the full set of links.

We are a Microsoft Partner, reflecting our depth in the Microsoft technology stack used to deliver customer solutions.

Continuous compliance monitoring

We partner with Vanta, the trust-management platform, for continuous, automated auditing and compliance monitoring. Our controls — across the cloud estate, access management, device security, and supplier posture — are checked continuously and the supporting evidence collected automatically, so our compliance position is maintained between reviews rather than reconstructed for them.

The same partnership works for our clients: we guide client platforms through SOC 2 Type II, ISO 27001, and GDPR certification with Vanta — preparing the technical baseline, leading the initial remediation sprint, and keeping the SDLC aligned so certification compounds across frameworks instead of duplicating effort. The full picture, including how certification unlocks enterprise and regulated-sector deals, is in the Vanta Compliance Partnership section of our Client Playbook.

Certification on request

Where a project or framework requires formal certification at our level rather than the hosting layer, ISO 27001 can be acquired at organisational level for a specific engagement, and Cyber Essentials Plus can be obtained on the same basis — in each case scoped to the engagement and agreed as part of the commercial arrangement at additional cost.

This is more practical for us than for most suppliers: we operate fully remotely over secure VPN, and our estate and development environments are entirely cloud-based and protected — no on-premise servers, no office network holding customer data. That keeps the certifiable scope small, well-defined, and quick to evidence.

Staying current with UK regulation

We maintain an ongoing process to stay current with UK data protection and privacy regulation, covering:

  • UK GDPR and the Data Protection Act 2018 — the core framework governing personal data we and our customers process.
  • PECR — the Privacy and Electronic Communications Regulations, relevant to cookies, tracking, and electronic marketing on solutions we build.
  • ICO guidance — we monitor Information Commissioner's Office publications, codes of practice, and enforcement trends, and factor them into our advice and builds.
  • Emerging legislation — proposed changes to the UK data protection regime are tracked so customer solutions and our own policies can adapt ahead of enforcement dates.

Findings feed into a periodic review of our policies — privacy, security, and this compliance documentation — with each page showing its last review date.

Standards applied in delivery

  • OWASP guidance for secure web application development (see Secure Development & Change Management).
  • Microsoft Well-Architected Framework and Azure security baselines for cloud architecture.
  • Data protection by design and by default (UK GDPR Article 25) applied to solutions handling personal data.
  • WCAG accessibility guidance applied to user-facing builds where required by the engagement.

Questionnaire support

If your due-diligence process requires specific certification evidence or completion of a security questionnaire, contact hello@assemblysoft.com — we respond to supplier questionnaires as part of onboarding.

Back to the Trust & Compliance Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor