IASME Cyber Assurance for Schools

The step up from Cyber Essentials that opens bigger work. For multi-academy trusts and larger schools, Cyber Assurance is the step up that evidences real information governance — an ISO 27001 alternative at SME cost, and we get you there with expert, plain-English support.

Delivered by
Certified IASME assessor
Levels
Level 1 & Level 2
Prerequisite
Cyber Essentials
Built for
Schools

Why schools and academy trusts certify to Cyber Assurance

For multi-academy trusts and larger schools, Cyber Essentials is the baseline and Cyber Assurance is the next step: it evidences an actual information-governance system across the trust, which is what auditors, funders and larger data-sharing partners increasingly expect.

  • Trust-wide governance. A multi-academy trust is a data-heavy organisation; Cyber Assurance evidences governance across all its schools, not just technical controls.
  • Beyond the baseline. Where a partner, funder or auditor wants more than Cyber Essentials, Cyber Assurance answers it without ISO 27001 cost.
  • Pupil and staff data. Level 2 includes a GDPR assessment, directly relevant to the personal data a trust holds at scale.

Supported from scope to certificate

Solusec takes you from where you are to a Cyber Assurance certificate: honest scoping, the documentation and controls sorted with you, and a certified IASME assessor — qualified for both Cyber Essentials and Cyber Assurance — who tells you exactly what the standard looks for rather than leaving you to guess.

Level 1 and Level 2

Level 1 is a verified self-assessment across the standard's 13 themes, reviewed by an assessor. Level 2 adds an independent, in-depth audit of your governance, documentation and controls, includes a GDPR assessment, and carries international recognition; a Level 2 certificate is valid for up to three years, with Level 1 renewed annually. We will tell you which level your requirement actually needs.

One prerequisite: you must hold a valid Cyber Essentials certificate throughout the Cyber Assurance period. If you do not yet have it, we help you with both.

Where it fits

Cyber Essentials first (it is the prerequisite), then Cyber Assurance where clients or funders want more than the baseline, and full ISO 27001 only if a contract genuinely demands it. Most schools and academy trusts get everything they need from Cyber Assurance.

Common questions

We're a trust, not a company - is Cyber Assurance overkill?

Not for a larger trust. You are effectively a data-heavy organisation running many schools, and Cyber Assurance evidences governance across all of them at a cost built for the sector, well below ISO 27001.

Is it a credible alternative to ISO 27001?

For most organisations your size, yes. Level 2 is independently audited and internationally recognised, and it satisfies many buyers who would otherwise ask for ISO. If you later need ISO 27001 itself, Cyber Assurance is a clean stepping stone toward it.

Do we need Cyber Essentials first?

Yes. A valid Cyber Essentials certificate is a prerequisite and must be held throughout the Cyber Assurance period. If you do not have it yet, we help you with both.

How do you help us achieve it?

We scope it with you, get the documentation and controls in shape, and — with a certified IASME assessor qualified for both Cyber Essentials and Cyber Assurance guiding you — support you through the assessment so you pass, rather than leaving you to work it out alone.

Related

Evidence more, win more

Tell us the client or funder asking for more than Cyber Essentials. We'll tell you honestly whether Level 1 or Level 2 fits.