IASME Cyber Assurance Explained for UK SMEs
IASME Cyber Assurance is a UK cybersecurity certification scheme designed specifically for SMEs — covering governance, risk management, and security practices beyond the purely technical focus of Cyber Essentials. It is the recommended stepping stone toward ISO 27001 for businesses that need a structured security framework.
Overview
IASME Cyber Assurance is a UK cybersecurity certification covering technical controls, governance, risk management, policies, and GDPR. It is designed for SMEs as an accessible alternative to ISO 27001 and includes Cyber Essentials within its framework. IASME is the NCSC's Cyber Essentials delivery partner.
Learn about Cyber EssentialsWhat Is IASME Cyber Assurance?
IASME (Information Assurance for Small and Medium Enterprises) is a UK body that developed a cybersecurity certification specifically designed for SMEs. IASME Cyber Assurance — sometimes called the IASME Gold standard — covers 149 controls across five domains: governance and risk management; information security policies; information security management; asset management; and technical security controls.
Importantly, IASME Cyber Assurance includes GDPR data protection controls as part of its framework, making it a single certification that addresses both cybersecurity and data protection obligations simultaneously. This makes it particularly relevant for businesses that process personal data and face both cybersecurity and compliance challenges.
How IASME Differs from Cyber Essentials
Cyber Essentials focuses on five specific technical controls — the controls needed to defend against the most common commodity cyber attacks. It does not address security governance, risk management, policies, or business continuity. IASME Cyber Assurance covers all of this — making it a more comprehensive certification that demonstrates not just that the right technical controls are in place, but that the organisation approaches security in a structured and managed way.
A business could hold Cyber Essentials (technically protecting itself) but have no written security policies, no risk assessment process, and no business continuity plan. IASME Cyber Assurance requires all of these, giving customers and partners greater confidence in the organisation's overall security maturity.
IASME Cyber Assurance vs ISO 27001
ISO 27001 is the international information security management standard and the gold standard for demonstrating security maturity. It is comprehensive, well-recognised globally, and highly credible — but it is also complex and expensive to achieve and maintain. For many SMEs, ISO 27001 is disproportionately demanding relative to their size and risk profile.
IASME Cyber Assurance provides approximately 70% of ISO 27001 coverage, scoped appropriately for SMEs. It is significantly less expensive to achieve and maintain, and the assessment process is more proportionate. For businesses that need to demonstrate security maturity to customers or supply chains but for whom ISO 27001 is excessive, IASME Cyber Assurance is frequently the right choice.
For businesses that plan to pursue ISO 27001 in the future, IASME Cyber Assurance provides a practical preparatory framework — implementing the policies, governance structures, and risk management processes that ISO 27001 will later require.
The Assessment Process
IASME Cyber Assurance is assessed via an online questionnaire reviewed by an IASME-approved assessor. The questionnaire covers all 149 controls, and responses must be supported by evidence — policies, procedures, records of training, and technical configuration documentation. Where evidence is not provided or controls are not in place, the assessor will identify gaps that need to be addressed before certification is awarded.
An independently verified version of IASME Cyber Assurance is also available, where an assessor conducts a more detailed review of evidence and may interview staff or review systems. This provides higher assurance and is appropriate for businesses with more demanding customer or regulatory requirements.
Key Considerations for UK SMEs
- IASME Cyber Assurance includes Cyber Essentials — achieving IASME Cyber Assurance also covers the CE requirements
- GDPR controls are embedded in the standard — IASME Cyber Assurance supports both security and data protection compliance
- Evidence is required — start gathering policy documents, training records, and risk assessments before attempting the questionnaire
- Certification takes longer to achieve than Cyber Essentials — AMVIA recommends allowing eight to twelve weeks for businesses starting from scratch
- Annual renewal is required, but maintaining the underlying governance framework makes renewal less burdensome each year
How AMVIA Can Help
AMVIA supports UK businesses through IASME Cyber Assurance as part of its managed cybersecurity service. AMVIA implements the technical controls required, assists with policy development, and guides businesses through the evidencing and questionnaire process. For businesses pursuing IASME as a pathway to ISO 27001, AMVIA's approach builds the foundation that ISO 27001 will later build on — avoiding the need to start again. Contact AMVIA on 0333 733 8050 to discuss IASME Cyber Assurance for your business.
Key Points
What UK businesses need to know about IASME Cyber Assurance.
Beyond Technical Controls
IASME Cyber Assurance covers policies, governance, risk management, and GDPR compliance — not just the five technical controls of Cyber Essentials.
SME-Focused Design
Unlike ISO 27001, IASME Cyber Assurance is scoped and priced for SMEs — assessed via questionnaire with optional independent verification.
NCSC Recognised
IASME is the NCSC's Cyber Essentials delivery partner. IASME Cyber Assurance is widely recognised as a credible UK cybersecurity certification.
Pathway to ISO 27001
IASME Cyber Assurance covers approximately 70% of ISO 27001 requirements, making it an effective stepping stone toward full ISO 27001 certification.
IASME Cyber Assurance Readiness Checklist
Cyber Essentials five controls in place — CE is included in IASME Cyber Assurance
Written information security policy documented and communicated to staff
Risk assessment conducted and documented
Asset inventory maintained — all devices and software recorded
Staff security awareness training evidenced
GDPR data protection controls in place — privacy notices, consent management, breach response
Frequently Asked Questions
IASME Cyber Assurance is broader and more comprehensive than Cyber Essentials — it includes CE's five technical controls plus governance, risk management, policies, and GDPR. Whether it is 'better' depends on what you need it for. If you need to meet a government contract requirement, CE is what is specified. If you want to demonstrate overall security maturity to customers or a supply chain, IASME Cyber Assurance is the more credible standard.
Standard UK government contracts specify Cyber Essentials (or CE Plus) as the minimum requirement. IASME Cyber Assurance includes CE, so it meets and exceeds the CE requirement. However, tender documents specify CE specifically — IASME Cyber Assurance on its own may not be accepted unless CE is also included or explicitly accepted as an equivalent. AMVIA recommends confirming with the contracting authority before relying on IASME Cyber Assurance alone for contract purposes.
IASME Cyber Assurance assessment fees are set by the certifying body and vary by assessor. For most SMEs, the assessment fee is in the range of £500 to £1,500 depending on organisation size and the level of assessor involvement. This is the certification fee alone — the cost of implementing any missing controls, developing required policies, and AMVIA's support in preparing for assessment is additional. Contact AMVIA for a tailored quote based on your current position.
Achieve IASME Cyber Assurance
AMVIA guides UK businesses through IASME Cyber Assurance certification — implementing controls, developing policies, and managing the assessment process.
Related Resources
Cyber Essentials Guide
The NCSC-backed baseline certification managed by IASME — included within IASME Cyber Assurance.
Cyber Essentials Plus
The independently verified version of Cyber Essentials — required for MOD and sensitive contracts.
Managed Cybersecurity Services
AMVIA's managed security service that implements and maintains the controls IASME requires.