IASME Cyber Assurance is a UK cyber security standard that demonstrates that an organisation has appropriate controls in place to manage cyber risk, protect data, and provide business resilience. It provides a structured and credible approach to improving cyber security beyond basic technical controls.
The scheme is designed to be flexible and proportionate, with requirements scaled to organisational size and complexity. This makes it suitable for organisations of all sizes, including SMEs, while still offering a meaningful level of assurance to customers, partners, and stakeholders.
IASME Cyber Assurance helps organisations build trust by demonstrating that cyber security is being taken seriously and managed in a structured, proportionate way. Independent certification provides reassurance to customers, partners, and stakeholders that appropriate security controls are in place.
The standard supports improved understanding and management of cyber risk by encouraging organisations to identify what they need to protect and where their key risks lie. This helps reduce the likelihood and impact of cyber incidents, supports supply chain requirements, and complements wider governance, assurance, and compliance activities.
As an experienced IASME Certification Body we can provide accreditation for Cyber Assurance Level 1 and Level 2.
Our services can include support and pre-audit consultancy for those organisations laying the foundations for good information security governance, or those maturing organisation require additional support.
Yes. A valid Cyber Essentials certification is required before achieving IASME Cyber Assurance and must be maintained for the duration of the certification. Cyber Essentials provides the technical baseline upon which IASME Cyber Assurance builds.
Timescales vary depending on organisational size, readiness, and whether Level 1 or Level 2 is pursued. We can provide an indicative timeline following an initial discussion and can begin the assessment process as required.
IASME Cyber Assurance Level 1 is suitable for organisations seeking assurance beyond Cyber Essentials, covering cyber security, data protection, and organisational controls in a proportionate and accessible way.
Level 2 is designed for organisations requiring higher levels of assurance through in-depth, externally assessed validation.
No. IASME Cyber Assurance reduces cyber and information risk by assessing controls, governance, and data protection practices, but it does not eliminate all risk. It provides assurance rather than a guarantee of security
Yes. IASME Cyber Assurance is designed to be scalable and proportionate, making it suitable for small businesses, sole traders, and growing organisations that require credible, independently verified assurance.
IASME provides a range of guidance, templates, and supporting materials to help organisations prepare for IASME Cyber Assurance. These resources explain the scheme requirements, expected evidence, and how to approach both Level 1 and Level 2 certification. Additional support and guidance are also available directly from IASME and through accredited Certification Bodies. Further information can be found on the IASME website at https://iasme.co.uk.
IASME Cyber Assurance is increasingly accepted across a wide range of industry sectors as a proportionate alternative to ISO/IEC 27001 for smaller organisations. Some public sector bodies, including the Ministry of Justice and the Government of Jersey, recognise audited IASME Cyber Assurance certification. This helps smaller organisations meet contractual security requirements, improve supply-chain accessibility, and unlock new commercial opportunities.