- Delivered by
- Certified IASME assessor
- Levels
- Level 1 & Level 2
- Prerequisite
- Cyber Essentials
- Built for
- Financial Services
Why financial services firms and IFAs certify to Cyber Assurance
For firms wanting to evidence genuine operational and information-security governance, to a network, the FCA lens or larger clients, Cyber Assurance is the SME-cost alternative to ISO 27001.
- Governance evidence. Cyber Assurance evidences a managed security system, not just technical controls, which is what networks and larger clients increasingly want.
- Regulated data. Level 2's GDPR assessment and audit suit firms handling sensitive client and financial data.
- ISO alternative. It answers those who might otherwise ask for ISO 27001, at a fraction of the cost.
Supported from scope to certificate
Solusec takes you from where you are to a Cyber Assurance certificate: honest scoping, the documentation and controls sorted with you, and a certified IASME assessor — qualified for both Cyber Essentials and Cyber Assurance — who tells you exactly what the standard looks for rather than leaving you to guess.
Level 1 and Level 2
Level 1 is a verified self-assessment across the standard's 13 themes, reviewed by an assessor. Level 2 adds an independent, in-depth audit of your governance, documentation and controls, includes a GDPR assessment, and carries international recognition; a Level 2 certificate is valid for up to three years, with Level 1 renewed annually. We will tell you which level your requirement actually needs.
One prerequisite: you must hold a valid Cyber Essentials certificate throughout the Cyber Assurance period. If you do not yet have it, we help you with both.
Where it fits
Cyber Essentials first (it is the prerequisite), then Cyber Assurance where clients or funders want more than the baseline, and full ISO 27001 only if a contract genuinely demands it. Most financial services firms and IFAs get everything they need from Cyber Assurance.
Common questions
Is Cyber Assurance enough for our network's due diligence?
In most cases, yes. Level 2 is independently audited and internationally recognised and evidences the information governance networks and providers look for, well below the cost of ISO 27001.
Is it a credible alternative to ISO 27001?
For most organisations your size, yes. Level 2 is independently audited and internationally recognised, and it satisfies many buyers who would otherwise ask for ISO. If you later need ISO 27001 itself, Cyber Assurance is a clean stepping stone toward it.
Do we need Cyber Essentials first?
Yes. A valid Cyber Essentials certificate is a prerequisite and must be held throughout the Cyber Assurance period. If you do not have it yet, we help you with both.
How do you help us achieve it?
We scope it with you, get the documentation and controls in shape, and — with a certified IASME assessor qualified for both Cyber Essentials and Cyber Assurance guiding you — support you through the assessment so you pass, rather than leaving you to work it out alone.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day