IASME Cyber Assurance
Broader than Cyber Essentials, considerably more achievable than ISO 27001, and built specifically for organisations that need to demonstrate real information security management without an enterprise budget.
Where it sits
Cyber Essentials covers five technical controls. ISO 27001 is a full information security management system with an audit regime and a cost to match. IASME Cyber Assurance occupies the space between: a genuine management standard covering governance, risk assessment, asset management, incident response, business continuity, staff awareness and data protection, scaled so that a thirty-person organisation can realistically achieve it.
It is aligned to the NCSC's Ten Steps to Cyber Security and incorporates UK GDPR requirements, which means it answers the data protection questions in client questionnaires as well as the security ones.
Two levels
Level 1: Verified Assessment
A self-assessment against the full standard, independently marked. Suitable for organisations that need to demonstrate a managed approach to information security to clients and insurers.
Level 2: Audited
Everything in Level 1 plus an onsite or remote audit by an assessor who verifies your evidence. Carries substantially more weight with sophisticated buyers, and is the appropriate choice where a contract explicitly requires audited assurance.
What it asks of you
More than Cyber Essentials, and mostly in areas that are documentation and process rather than technology:
- A risk assessment that identifies your actual risks and what you have decided to do about each.
- An asset register covering information, hardware and software.
- Documented policies that reflect what you genuinely do, not a downloaded template.
- An incident response plan, and evidence you have thought about how it works in practice.
- Business continuity and backup arrangements that have been tested.
- Staff awareness training with records.
- Data protection practice aligned to UK GDPR, including retention and lawful basis.
- Supplier and third-party risk management.
How we help
The failure mode here is a folder of generic policies that describe an organisation nobody works for. Assessors see it constantly and it does not pass at Level 2.
We work from how your organisation actually operates and document that, filling genuine gaps rather than manufacturing paperwork. Where a control does not sensibly apply at your size, the standard allows proportionality: knowing where that latitude exists, and where it does not, is most of the value of using an assessor who holds the certification themselves.
A note on why we hold it
Solusec is certified to IASME Cyber Assurance and IASME Quality Principles, both independently verifiable on the IASME register. We think a security provider asking you to demonstrate a standard should be able to demonstrate it themselves.
Ready to buy?
IASME Cyber Assurance pricing, in line with IASME’s fee bands. Cyber Essentials certification is a prerequisite and is priced separately. By default we give you access to the IASME portal to complete your assessment yourself. Your submission is reviewed by a qualified, certified assessor, never fed into AI. Need it faster? Add urgent turnaround below. Want us to review your setup against the controls before you apply? That is a gap analysis, quoted separately: ask for one using the contact button under the form. Buy Level 1 now, or request a quote for the audited Level 2.
An appointed IASME Certification Body: your certificate comes directly from us. Verify our credentials on the BlockMark registry, and find us listed on the IASME website.
Cyber Assurance by area
We work with organisations across the UK. Area guides: Shropshire, West Midlands, Staffordshire, East Midlands, Greater Manchester, North Wales, South Wales. Against a deadline? See urgent Cyber Assurance certification.
Cyber Assurance by sector
Sector guides: Schools, Colleges, Universities, Accountants, Law Firms, Charities, Manufacturers, Financial Services.
Common questions
Is this recognised instead of ISO 27001?
It depends on the buyer. Many UK organisations, particularly in the public sector and among SME supply chains, accept IASME Cyber Assurance as demonstrating proportionate information security management. Some contracts specify ISO 27001 explicitly and nothing else will substitute. Check the requirement before choosing, and we will help you read it.
Does it include Cyber Essentials?
Cyber Essentials certification is a component of Cyber Assurance, so achieving Cyber Assurance means holding Cyber Essentials as well. The two are normally pursued together.
How long does it take?
Level 1 typically three to eight weeks depending on how much documentation already exists. Level 2 longer, because evidence needs to be in place and demonstrable: three to six months is realistic for an organisation starting from very little.
Is it a stepping stone to ISO 27001?
It works well as one. The governance, risk assessment and asset management work transfers directly, so organisations that later pursue ISO 27001 find a significant proportion of the groundwork already done.
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.