IASME Cyber Assurance
Introducing the IASME Cyber Assurance Standard: A Flexible, Affordable, and Comprehensive Approach to Cybersecurity.
The IASME Cyber Assurance standard is designed to provide an affordable and accessible alternative to other international cybersecurity standards. Tailored for small and medium-sized enterprises (SMEs), it allows organisations within a supply chain to demonstrate their commitment to cybersecurity and data protection at a reasonable cost.
To achieve IASME Cyber Assurance certification, organisations must hold a valid Cyber Essentials certificate throughout the certification period. The IASME Cyber Assurance certification offers two levels of assessment:
- Level 1: Verified Assessment – A self-assessment verified by an IASME-approved certification body.
- Level 2: Audited Assessment – An in-depth, independently audited assessment that carries international recognition.
This certification highlights that robust cybersecurity and data protection measures are in place, building trust with customers and partners while safeguarding sensitive information.
As with the Cyber Essentials certification, there are two levels of this accreditation:
IASME Cyber Assurance- Level 1
IASME Cyber Assured is a risk-oriented standard and covers ensuring best practise in core areas of security such as:
- Incident management
- Personnel recruitment
- Planning and operations
- GDPR compliance
Level 1 is the first step in the IASME Cyber Assurance standard.
IASME Cyber Assurance – Level 2
This level of the standard requires an audit of your governance systems and operations, The audit is independent and conducted by a Certified body or assessor. IASME Cyber Assurance Level 2 requires you to have completed Level 1. Level 2 covers 13 themes across 4 areas of control
- Identify and Classify
- Protect
- Detect and Deter
- Respond and Recover
The new standard has simplified the process whilst maintaining the approach to strong cyber security
IASME Cyber Assured is a risk-oriented standard and covers ensuring best practise in core areas of security such as:
Incident Management
Personnel Recruitment
Planning and Operations
IASME Cyber Assured requires a Cyber Essentials evaluation, it is a self-assessed review of your organisations processes.
IASME Cyber Assured- Level 1
This level of the standard requires an on-site audit of your governance systems and operations, which are then assessed against the IASME Cyber Assured standard by a certification assessor or body.
IASME Cyber Assured Level 2 covers 13 themes across 4 areas of control :
Identify and Classify
Protect
Detect and Deter
Respond and Recover
It has a comparable degree of assurance to the globally recognised ISO 27001 standard, but it is much easier to implement.
IASME Cyber Assured- Level 2