Certification

IASME Cyber Assurance Explained for UK SMEs

IASME Cyber Assurance is a UK cybersecurity certification scheme designed specifically for SMEs — covering governance, risk management, and security practices beyond the purely technical focus of Cyber Essentials. It is the recommended stepping stone toward ISO 27001 for businesses that need a structured security framework.

Call 0333 733 8050

Overview

IASME Cyber Assurance is a UK cybersecurity certification covering technical controls, governance, risk management, policies, and GDPR. It is designed for SMEs as an accessible alternative to ISO 27001 and includes Cyber Essentials within its framework. IASME is the NCSC's Cyber Essentials delivery partner.

Learn about Cyber Essentials

What Is IASME Cyber Assurance?

IASME (Information Assurance for Small and Medium Enterprises) is a UK body that developed a cybersecurity certification specifically designed for SMEs. IASME Cyber Assurance — sometimes called the IASME Gold standard — covers 149 controls across five domains: governance and risk management; information security policies; information security management; asset management; and technical security controls.

Importantly, IASME Cyber Assurance includes GDPR data protection controls as part of its framework, making it a single certification that addresses both cybersecurity and data protection obligations simultaneously. This makes it particularly relevant for businesses that process personal data and face both cybersecurity and compliance challenges.

How IASME Differs from Cyber Essentials

Cyber Essentials focuses on five specific technical controls — the controls needed to defend against the most common commodity cyber attacks. It does not address security governance, risk management, policies, or business continuity. IASME Cyber Assurance covers all of this — making it a more comprehensive certification that demonstrates not just that the right technical controls are in place, but that the organisation approaches security in a structured and managed way.

A business could hold Cyber Essentials (technically protecting itself) but have no written security policies, no risk assessment process, and no business continuity plan. IASME Cyber Assurance requires all of these, giving customers and partners greater confidence in the organisation's overall security maturity.

IASME Cyber Assurance vs ISO 27001

ISO 27001 is the international information security management standard and the gold standard for demonstrating security maturity. It is comprehensive, well-recognised globally, and highly credible — but it is also complex and expensive to achieve and maintain. For many SMEs, ISO 27001 is disproportionately demanding relative to their size and risk profile.

IASME Cyber Assurance provides approximately 70% of ISO 27001 coverage, scoped appropriately for SMEs. It is significantly less expensive to achieve and maintain, and the assessment process is more proportionate. For businesses that need to demonstrate security maturity to customers or supply chains but for whom ISO 27001 is excessive, IASME Cyber Assurance is frequently the right choice.

For businesses that plan to pursue ISO 27001 in the future, IASME Cyber Assurance provides a practical preparatory framework — implementing the policies, governance structures, and risk management processes that ISO 27001 will later require.

The Assessment Process

IASME Cyber Assurance is assessed via an online questionnaire reviewed by an IASME-approved assessor. The questionnaire covers all 149 controls, and responses must be supported by evidence — policies, procedures, records of training, and technical configuration documentation. Where evidence is not provided or controls are not in place, the assessor will identify gaps that need to be addressed before certification is awarded.

An independently verified version of IASME Cyber Assurance is also available, where an assessor conducts a more detailed review of evidence and may interview staff or review systems. This provides higher assurance and is appropriate for businesses with more demanding customer or regulatory requirements.

Key Considerations for UK SMEs

  • IASME Cyber Assurance includes Cyber Essentials — achieving IASME Cyber Assurance also covers the CE requirements
  • GDPR controls are embedded in the standard — IASME Cyber Assurance supports both security and data protection compliance
  • Evidence is required — start gathering policy documents, training records, and risk assessments before attempting the questionnaire
  • Certification takes longer to achieve than Cyber Essentials — AMVIA recommends allowing eight to twelve weeks for businesses starting from scratch
  • Annual renewal is required, but maintaining the underlying governance framework makes renewal less burdensome each year

How AMVIA Can Help

AMVIA supports UK businesses through IASME Cyber Assurance as part of its managed cybersecurity service. AMVIA implements the technical controls required, assists with policy development, and guides businesses through the evidencing and questionnaire process. For businesses pursuing IASME as a pathway to ISO 27001, AMVIA's approach builds the foundation that ISO 27001 will later build on — avoiding the need to start again. Contact AMVIA on 0333 733 8050 to discuss IASME Cyber Assurance for your business.

Key Points

What UK businesses need to know about IASME Cyber Assurance.

Beyond Technical Controls

IASME Cyber Assurance covers policies, governance, risk management, and GDPR compliance — not just the five technical controls of Cyber Essentials.

SME-Focused Design

Unlike ISO 27001, IASME Cyber Assurance is scoped and priced for SMEs — assessed via questionnaire with optional independent verification.

NCSC Recognised

IASME is the NCSC's Cyber Essentials delivery partner. IASME Cyber Assurance is widely recognised as a credible UK cybersecurity certification.

Pathway to ISO 27001

IASME Cyber Assurance covers approximately 70% of ISO 27001 requirements, making it an effective stepping stone toward full ISO 27001 certification.

IASME Cyber Assurance Readiness Checklist

Cyber Essentials five controls in place — CE is included in IASME Cyber Assurance

Written information security policy documented and communicated to staff

Risk assessment conducted and documented

Asset inventory maintained — all devices and software recorded

Staff security awareness training evidenced

GDPR data protection controls in place — privacy notices, consent management, breach response

Frequently Asked Questions

Achieve IASME Cyber Assurance

AMVIA guides UK businesses through IASME Cyber Assurance certification — implementing controls, developing policies, and managing the assessment process.