Compliance

Certifications, Standards & Regulatory Monitoring

The standards we work to, the certifications behind our hosting, and how we keep pace with UK regulation.

Trust & Compliance Centre · Last reviewed: August 2026

At a glance

Cyber Essentials Plus is also held (assessed 4 August 2026 by Layer 7; certificate no. edf6e928-14bf-426f-9302-63f395a20af5).
Do you hold ISO 27001, ISO 9001, or other relevant certifications?
Do you have processes to stay current with UK data protection and privacy regulations? Yes Ongoing monitoring of ICO guidance and UK GDPR / DPA 2018 developments, with periodic policy review

Our position on certification

Assemblysoft is a focused specialist consultancy rather than a large enterprise vendor, and we are transparent about what that means for certification: we operate our information security practices in alignment with ISO/IEC 27001 principles — risk-based controls, least-privilege access, documented incident response, and continuity planning — as described across this Trust & Compliance Centre.

Assemblysoft Ltd holds Cyber Essentials certification at company level — achieved 28 July 2026 for the whole organisation (certificate no. a7275954-4dd7-415e-99ba-e9d2ac193194, profile v3.3, via FIG Group / IASME; recertification due 28 July 2027). Verify on the IASME registry.

Formal certification is also held at the infrastructure layer. Customer solutions are hosted on Microsoft Azure, which is independently certified against ISO/IEC 27001, ISO/IEC 27017/27018, ISO 9001, SOC 1/2/3, and Cyber Essentials Plus, among others. Microsoft's certificates and audit reports can be verified directly via the Microsoft Service Trust Portal and the Azure ISO 27001 compliance offering — see Hosting & Data Residency for the full set of links.

We are a Microsoft Partner, reflecting our depth in the Microsoft technology stack used to deliver customer solutions.

Continuous compliance monitoring

Our own compliance is self-managed: controls are self-assessed on a quarterly cycle against our documented policy set — information security, access control, incident response, continuity, and supplier management — with continuous posture signals between reviews from Microsoft Defender for Cloud secure score, Azure Policy compliance views, and Entra ID identity secure score. The supporting evidence — policies, registers, and dated logs — is maintained as a standing pack, available to customers under NDA.

For our clients, we are a Vanta partner: we guide client platforms through SOC 2 Type II, ISO 27001, and GDPR certification with Vanta — preparing the technical baseline, leading the initial remediation sprint, and keeping the SDLC aligned so certification compounds across frameworks instead of duplicating effort. The full picture, including how certification unlocks enterprise and regulated-sector deals, is in the Vanta Compliance Partnership section of our Client Playbook.

Certification on request

Where a project or framework requires formal certification at our level rather than the hosting layer, ISO 27001 can be acquired at organisational level for a specific engagement — scoped to the engagement and agreed as part of the commercial arrangement at additional cost. Cyber Essentials Plus is no longer on that basis: the audited assessment was carried out on 4 August 2026 by our certification body Layer 7 against Test Specification v3.2. The Cyber Essentials Plus certificate has been awarded (certificate no. edf6e928-14bf-426f-9302-63f395a20af5).

This is more practical for us than for most suppliers: we operate fully remotely over secure VPN, and our estate and development environments are entirely cloud-based and protected — no on-premise servers, no office network holding customer data. That keeps the certifiable scope small, well-defined, and quick to evidence.

Staying current with UK regulation

We maintain an ongoing process to stay current with UK data protection and privacy regulation, covering:

  • UK GDPR and the Data Protection Act 2018 — the core framework governing personal data we and our customers process.
  • PECR — the Privacy and Electronic Communications Regulations, relevant to cookies, tracking, and electronic marketing on solutions we build.
  • ICO registration — Assemblysoft Ltd is registered with the Information Commissioner's Office and pays the annual data protection fee, as required of controllers under the Data Protection (Charges and Information) Regulations 2018 — registration reference ZC213887, verifiable on the ICO's public register of fee payers.
  • ICO guidance — we monitor ICO publications, codes of practice, and enforcement trends, and factor them into our advice and builds.
  • Emerging legislation — proposed changes to the UK data protection regime are tracked so customer solutions and our own policies can adapt ahead of enforcement dates.

Findings feed into a periodic review of our policies — privacy, security, and this compliance documentation — with each page showing its last review date.

Standards applied in delivery

  • OWASP guidance for secure web application development (see Secure Development & Change Management).
  • Microsoft Well-Architected Framework and Azure security baselines for cloud architecture.
  • Data protection by design and by default (UK GDPR Article 25) applied to solutions handling personal data.
  • WCAG accessibility guidance applied to user-facing builds where required by the engagement.

Questionnaire support

If your due-diligence process requires specific certification evidence or completion of a security questionnaire, contact hello@assemblysoft.com — we respond to supplier questionnaires as part of onboarding.

Back to the Trust & Compliance Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor