- Delivered by
- Certified IASME assessor
- Levels
- Level 1 & Level 2
- Prerequisite
- Cyber Essentials
- Coverage
- the East Midlands, UK-wide (remote)
Why East Midlands businesses certify to Cyber Assurance
IASME Cyber Assurance is the step up from Cyber Essentials, and organisations reach for it for a commercial reason: bigger buyers want to see more than a baseline. From Nottingham and Leicester's professional services to Derby's aerospace and rail supply chains, East Midlands primes increasingly mandate certification. Where a tender or a prime asks for evidence of an actual information-security management system, Cyber Assurance answers it, without the cost and time of full ISO 27001.
- It opens contracts the baseline can't. Some buyers and frameworks now want assurance beyond Cyber Essentials. Cyber Assurance provides it, and Level 2 carries international recognition.
- It stands in for ISO 27001 at SME cost. Mapped to ISO 27001 and the Government's 10 Steps to Cyber Security, it satisfies many buyers who would otherwise ask for ISO, at a fraction of the price and timeline, and it is a clean stepping stone if you do pursue ISO later.
- It answers data-protection due diligence. Level 2 includes a GDPR assessment, which is exactly what buyers handling personal or financial data want to see before they contract with you.
- It is a genuine competitive edge. Far fewer of your competitors hold it than hold Cyber Essentials, so it marks you out as a more serious supplier and partner.
Supported from scope to certificate
Solusec takes you from where you are to a Cyber Assurance certificate: honest scoping, the documentation and controls sorted with you, and a certified IASME assessor — qualified for both Cyber Essentials and Cyber Assurance — who tells you exactly what the standard looks for rather than leaving you to guess.
Level 1 and Level 2
Level 1 is a verified self-assessment across the standard's 13 themes, reviewed by an assessor. Level 2 adds an independent, in-depth audit of your governance, documentation and controls, includes a GDPR assessment, and carries international recognition; a Level 2 certificate is valid for up to three years, with Level 1 renewed annually to maintain it. We will tell you which level your buyers actually need.
One prerequisite: you must hold a valid Cyber Essentials certificate throughout the Cyber Assurance certification period. If you do not yet have it, we help you with both.
How it works across the East Midlands
Level 1 is completed on the IASME portal with our support, so East Midlands organisations pay no travel. Level 2's audit is scheduled around you and can be delivered remotely or onsite. We keep the paperwork proportionate and the language plain enough to take to a board.
Where it fits
Cyber Essentials first (it is the prerequisite), then Cyber Assurance where buyers want more than the baseline, and full ISO 27001 only if a contract genuinely demands it. Most East Midlands SMEs get everything they need from Cyber Assurance.
Common questions
What is IASME Cyber Assurance, in business terms?
An affordable, UK-developed information-security standard from IASME, mapped to ISO 27001 and the Government's 10 Steps. It lets you evidence a real security management system to buyers without the cost of full ISO 27001.
Is it a credible alternative to ISO 27001?
For most SMEs, yes. Level 2 is independently audited and internationally recognised, and it satisfies many buyers who would otherwise ask for ISO. If you later need ISO 27001 itself, Cyber Assurance is a clean stepping stone toward it.
Do we need Level 1 or Level 2?
Level 1 (verified self-assessment) is enough for many supplier requirements. Level 2 (independent audit, with a GDPR assessment) is what buyers handling sensitive personal or financial data tend to want. We check what your contract actually asks for.
Do we need Cyber Essentials first?
Yes. A valid Cyber Essentials certificate is a prerequisite and must be held throughout the Cyber Assurance period. If you do not have it yet, we help you with both.
How do you help us achieve it?
We scope it with you, get the documentation and controls in shape, and — with a certified IASME assessor qualified for both Cyber Essentials and Cyber Assurance guiding you — support you through the assessment so you pass, rather than leaving you to work it out alone.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day