Introduction

With an ever increasing dependency on technology , information security is more critical than ever. Cyber Essentials can act as a great starting point for most organisations, but what’s next? In this blog, we explore how IASME Cyber Assurance goes beyond Cyber Essentials and can be a great step for organisations looking for more comprehensive security. We explain how an organisation can choose to implement the measures based on its size and risk appetite. We also show how IASME Cyber Assurance can support other frameworks such as ISO 27001 and the UK government code of practice.

 

What Is IASME Cyber Assurance?

IASME Cyber Assurance is a flexible and affordable information security standard, designed with smaller organisations in mind. It builds on Cyber Essentials and covers 14 themes that are aimed at making organisations more cyber resilient. Each theme has a set of requirements (security measures) that can be applied based on organisational size and risk. IASME Cyber Assurance can therefore be ideal for small to medium-sized organisations looking for an alternative, or the next step towards ISO 27001. There are two levels to the IASME Cyber Assurance scheme:

  • Level One involves a verified self-assessment 
  • Level Two is an independent audit, involving a detailed review of security policies, procedures, and controls
  • Both levels go well beyond Cyber Essentials (with Cyber Essentials being a valid prerequisite) and can help organisations further demonstrate their commitment to information security.
  • Certification can be gained for both levels of the scheme
FeatureIASME Cyber Assurance Level OneIASME Cyber Assurance Level Two
Assessment Verified self-assessmentAudit
TestingAssessor reviews self-assessmentThe assessor carries out the audit, and the IASME moderator reviews
Controls14 themesSame 14 themes
Certification12-month certificate3-year certificate, with annual (Level One) renewals

This table shows the key differences between IASME Cyber Assurance Level One and Two

 

Why choose IASME Cyber Assurance?

  • Cyber Essentials can be a great starting point; however, organisations often look beyond that scheme for more security measures (based on risk) – examples include:
    • Data Backup
    • Asset Management
    • Business Continuity and Disaster Recovery
    • Legal and Regulatory
  • Organisations can benefit from the (very clear) guidance provided through the IASME Cyber Assurance scheme, which can help reduce uncertainty and set out each requirement in detail
  • Organisations often consider ISO 27001, then realise the benefits of IASME Cyber Assurance as either a next step or a pragmatic alternative

 

What does IASME Cyber Assurance cover?

  • IASME Cyber Assurance covers 14 themes 
  • Each theme has some requirements (security measures)
  • An organisation can choose to implement the requirements, based on size and risk
ThemesFurther insight into the aim of the theme Number of requirements
PlanningConsider information security for day-to-day activities and projects1
OrganisationHave a clear structure and foundation for effective security4
AssetsUnderstand what you have and how to protect it6
Legal and Regulatory Consider contractual obligations, data protection requirements, and more4
RiskIdentify threats, treat and manage them appropriately9
Physical and environmentalPrevent theft, loss, or damage and ensure protection from temperatures or humidity7
PeopleConsider education, awareness, training, and least privilege4
Policy For ‘right-sized’ security controls7
Managing AccessImplement appropriate access to resources and data4
Technical IntrusionLeverage tools to detect and prevent unauthorised access2
Change ManagementControl and manage key changes1
Security OperationsTake action based on warnings and alerts5
Backups and RestoresHave regular and segregated data backups – test to ensure recovery4
ResilienceBusiness continuity, incident management, and disaster recovery7

The table shows the 14 themes, along with a brief outline of the aim of each theme, and shows the number of requirements for each theme 

 

How is IASME Cyber Assurance applied?

  • Depending upon organisational size and risk appetite, each of the 14 themes, with their detailed security controls, will be applicable. 
  • The latest version of the standard (V7) provides a set of mandatory requirements, based on organisational size. 
  • A risk assessment can be carried out to determine whether the non-mandatory controls should also be applied.
Number of employeesMandatory RequirementsNon-Mandatory Requirements (considered based on risk)
1 – 2 people2045
3 to 9 people 3233
10 – 49 people 4817
50 or more people650

This table shows how the total number of requirements can be applied, based on organisational size

 

How does IASME Cyber Assurance compare with other frameworks?

  • Cyber Essentials is a valid prerequisite for IASME Cyber Assurance and covers just 5 technical requirements, compared to 14 themes for IASME Cyber Assurance and up to 65 requirements
  • ISO 27001: a mapping exercise from 2022 shows how version 6 of the IASME Cyber Assurances covers all the ISO 27001 requirements (at an achieved or partially achieved level) and almost all the ISO 27002 controls (either explicitly or implicitly)
  • UK Government Code of Practice: a mapping exercise from 2025 recognises how IASME Cyber Assurance meets the requirements of the Cyber Governance Code of Practice

How RB Consultancy Ltd Help?

As an Assessor and Certification Body for IASME Cyber Assurance, we carry out assessments and issue certificates for both levels of the scheme. Holding a Certified Information Systems Security Professional (CISSP) certification, we can also help organisations implement the security measures and provide support through the process. We have templates and documentation to leverage that can also assist with each theme, and can therefore provide completed packages to support.

 

Conclusion – how Cyber Assurance goes beyond Cyber Essentials

IASME Cyber Assurance can be a great next step beyond Cyber Essentials. It provides additional confidence and assurance that a variety of security measures are in place to protect organisations. These security measures can be applied based on organisational size and risk. Mapping exercises carried out show how IASME Cyber Assurance can support ISO 27001 and the UK Government Code of Practice. With our credentials and experience, we help organisations through both levels of the scheme and issue the associated certificates. If you would like more information or any support with IASME Cyber Assurance, please contact us.

 

Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional and cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only.

 

FAQs

  1. What’s the difference between IASME Cyber Assurance Level One and Two?
    Level One is a verified self-assessment, and Level Two is an audit
  2. How long does certification take?
    Timescales can vary significantly, depending on organisational size, priorities, and preparedness.
  3. What does a Level 2 audit involve?
    Testing includes reviewing evidence, carrying out interviews, and ensuring processes are in place.
  4. Can RB Consultancy Ltd help?
    Absolutely! RB Consultancy Ltd provides expert guidance and support. Contact us for more information.

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Benefits of Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP