IASME Cyber Assurance

IASME Cyber Assurance is a comprehensive and flexible cybersecurity standard that provides assurance that an organisation has put into place a range of important cybersecurity, privacy, and data protection measures.

The standard is designed to help organisations of all sizes manage their cybersecurity risks by providing an affordable and recognisable alternative to other international standards.

What is IASME Cyber Assurance?

A comprehensive, affordable alternative to ISO 27001 — covering security, privacy and GDPR across your whole organisation.

IASME Cyber Assurance is a flexible, UK Government-backed standard that shows you have put a real range of cyber security, privacy and data protection measures in place. It is designed for organisations of any size, but built with smaller businesses in mind.

It comes in two levels — Level 1 (Verified Assessment) and Level 2 (Audited) — and maps closely to ISO 27001, GDPR and the NIS Cyber Assessment Framework, so it gives customers the assurance they are really asking for without the cost of full ISO 27001.

The four controls

Certification starts with a risk assessment of your business, which guides the controls you put in place across four areas.

Identify and classify

Identify your assets and how important they are — taking in relevant legislation, physical security and the people involved.

Protect

Put good policies in place, control access to information, prevent technical attacks and back up your data.

Detect and deter

Put monitoring in place to spot and deter attacks, so you know quickly when something is not right.

Respond and recover

Plan how you would respond to an incident, with business continuity and disaster recovery ready to go.

Why it’s worth having

A practical way for smaller organisations to prove their security and open doors.

  • An affordable, achievable alternative to ISO 27001
  • A UK Government-approved scheme
  • Includes a GDPR readiness assessment
  • Helps you gain access to key supply chains

Frequently asked questions

Straight answers to the things people ask us most.

What is IASME Cyber Assurance?
A comprehensive but affordable alternative to ISO 27001. It covers cyber security, privacy and GDPR across your whole organisation, and is widely recognised across UK supply chains.
How does it compare to ISO 27001?
It is built on similar principles but is far more practical and affordable for small and medium organisations. For many businesses it provides the assurance a customer is really asking for, without the cost and overhead of full ISO 27001.
What are the two levels?
A verified self-assessment, or a full independent audit for stronger assurance. We help you choose the level that fits what your customers and contracts actually require.
Does it include Cyber Essentials and GDPR?
Yes. IASME Cyber Assurance includes Cyber Essentials as its technical foundation and includes a GDPR readiness assessment.
How much does IASME Cyber Assurance cost?
It depends on the size of your organisation and the level you choose. Get in touch for a quote — no obligation.

Ready to get IASME certified?

Book a free 30-minute call