The beautiful tip of the iceberg
Most of what we build you'll never see. This is the part you can.
The standards we work to, the certifications behind our hosting, and how we keep pace with UK regulation.
| Do you hold ISO 27001, ISO 9001, or other relevant certifications? | Cyber Essentials Plus is also held (assessed 4 August 2026 by Layer 7; certificate no. edf6e928-14bf-426f-9302-63f395a20af5).|
| Do you have processes to stay current with UK data protection and privacy regulations? | Yes Ongoing monitoring of ICO guidance and UK GDPR / DPA 2018 developments, with periodic policy review |
Assemblysoft is a focused specialist consultancy rather than a large enterprise vendor, and we are transparent about what that means for certification: we operate our information security practices in alignment with ISO/IEC 27001 principles — risk-based controls, least-privilege access, documented incident response, and continuity planning — as described across this Trust & Compliance Centre.
Assemblysoft Ltd holds Cyber Essentials certification at company level — achieved 28 July 2026 for the whole organisation (certificate no. a7275954-4dd7-415e-99ba-e9d2ac193194, profile v3.3, via FIG Group / IASME; recertification due 28 July 2027). Verify on the IASME registry.
Formal certification is also held at the infrastructure layer. Customer solutions are hosted on Microsoft Azure, which is independently certified against ISO/IEC 27001, ISO/IEC 27017/27018, ISO 9001, SOC 1/2/3, and Cyber Essentials Plus, among others. Microsoft's certificates and audit reports can be verified directly via the Microsoft Service Trust Portal and the Azure ISO 27001 compliance offering — see Hosting & Data Residency for the full set of links.
We are a Microsoft Partner, reflecting our depth in the Microsoft technology stack used to deliver customer solutions.
Our own compliance is self-managed: controls are self-assessed on a quarterly cycle against our documented policy set — information security, access control, incident response, continuity, and supplier management — with continuous posture signals between reviews from Microsoft Defender for Cloud secure score, Azure Policy compliance views, and Entra ID identity secure score. The supporting evidence — policies, registers, and dated logs — is maintained as a standing pack, available to customers under NDA.
For our clients, we are a Vanta partner: we guide client platforms through SOC 2 Type II, ISO 27001, and GDPR certification with Vanta — preparing the technical baseline, leading the initial remediation sprint, and keeping the SDLC aligned so certification compounds across frameworks instead of duplicating effort. The full picture, including how certification unlocks enterprise and regulated-sector deals, is in the Vanta Compliance Partnership section of our Client Playbook.
Where a project or framework requires formal certification at our level rather than the hosting layer, ISO 27001 can be acquired at organisational level for a specific engagement — scoped to the engagement and agreed as part of the commercial arrangement at additional cost. Cyber Essentials Plus is no longer on that basis: the audited assessment was carried out on 4 August 2026 by our certification body Layer 7 against Test Specification v3.2. The Cyber Essentials Plus certificate has been awarded (certificate no. edf6e928-14bf-426f-9302-63f395a20af5).
This is more practical for us than for most suppliers: we operate fully remotely over secure VPN, and our estate and development environments are entirely cloud-based and protected — no on-premise servers, no office network holding customer data. That keeps the certifiable scope small, well-defined, and quick to evidence.
We maintain an ongoing process to stay current with UK data protection and privacy regulation, covering:
Findings feed into a periodic review of our policies — privacy, security, and this compliance documentation — with each page showing its last review date.
If your due-diligence process requires specific certification evidence or completion of a security questionnaire, contact hello@assemblysoft.com — we respond to supplier questionnaires as part of onboarding.