PassCyber
PassCyber / Guides

IASME, explained — and whether you need Cyber Assurance or Cyber Essentials

IASME is the body behind UK cyber certification: it delivers Cyber Essentials on behalf of the government, and it runs a broader standard of its own — IASME Cyber Assurance. Contracts increasingly name one, the other, or both. Here's what each actually covers and which your situation calls for.

Current question set: DanzellReading time 5 minutes

What IASME actually is

The IASME Consortium is the NCSC's delivery partner for the Cyber Essentials scheme: it accredits the certification bodies, trains and licenses the assessors, and issues the question sets every applicant answers. So when your organisation certifies to Cyber Essentials, IASME's machinery is behind the certificate regardless of which certification body you use. Separately, IASME operates its own certification — IASME Cyber Assurance (previously known as IASME Governance) — which goes wider than Cyber Essentials' technical baseline.

Cyber Essentials vs Cyber Assurance — the real difference

Cyber Essentials is a technical baseline: five control areas (firewalls, secure configuration, security updates, user access and MFA, malware protection), assessed annually. It answers the question “are the basic technical defences in place?” — and it's what most UK contracts and supply chains ask for. IASME Cyber Assurance assumes that baseline and adds the governance layer around it: risk assessment, security policy, data protection and GDPR alignment, backup and restore, incident response and business continuity, supplier security, and people processes. It answers a bigger question — “is security actually managed here?” — and for smaller organisations it functions as a proportionate alternative to heavyweight standards like ISO 27001.

The two levels of Cyber Assurance

Level 1 is a verified self-assessment: your organisation answers the standard's questionnaire, and a qualified assessor reviews and verifies the responses — the same working pattern as Cyber Essentials, applied to the broader question set. Level 2 is audited: an assessor examines your organisation's evidence directly and certifies on what they've verified, which carries more weight where a customer or regulator wants independent confirmation rather than attestation. Most organisations start at Level 1; Level 2 is driven by contractual demand.

Which one is your contract asking for?

Read the wording precisely. “Cyber Essentials” or “Cyber Essentials Plus” means the government scheme — see how to get it, start to finish and which level you need. “IASME Cyber Assurance”, “IASME Governance”, or a requirement to “demonstrate information security governance” points at the broader standard. Some tenders name both. If the wording is ambiguous, ask the buyer before you spend — or send it to us and we'll read it with you.

The sensible order for most small organisations

Cyber Essentials first — it's the near-universal contractual ask, the quicker certification, and its five controls are prerequisites inside Cyber Assurance anyway. Then Cyber Assurance when a contract, a regulator, or your own data-protection exposure calls for the governance layer — much of its documentation (policy, risk register, incident plan) is exactly the paperwork a well-run small organisation should hold regardless, and a good security policy is the natural first artefact.

PassCyber

Certification support for either route

We take small organisations through Cyber Essentials done-for-you, and prepare the governance groundwork Cyber Assurance builds on. Start by seeing where you stand.

Take the free readiness check  ·  hello@passcyber.co.uk

PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd

Scheme structures and names are set by IASME and the NCSC and are reviewed periodically; confirm current requirements before you begin. PassCyber is independent of IASME; certificates are awarded by accredited certification bodies.