For a growing number of organisations, particularly those looking for more cyber resilience, operating in a regulated sector, or handling sensitive data, Cyber Essentials is not enough and more is required. Clients and procurement teams are asking about risk management, data protection, physical security, business continuity and supplier governance. IASME Cyber Assurance addresses all of that, and more.
IASME Cyber Assurance is a structured information security framework built around 14 themes. Together, they cover how an organisation identifies, governs and reduces its cyber risk across people, processes and technology. RB Consultancy Ltd is an accredited IASME Cyber Assurance Certification Body at both Level 1 and Level 2. We assess and certify organisations at both levels, providing practical support throughout the process. If implementation is required, we can help with that too. You can benefit from our experience from start to finish.
Unlike a checklist of pure technical controls, IASME Cyber Assurance examines how security is embedded into how your organisation operates. The 14 themes are:
Both certifications cover all 14 themes. The main difference is that Level 1 is based on a verified self-assessment whereas Level 2 involves an independent audit to verify the requirements are implemented.
You complete an assessment across all 14 themes and submit it. We assess and review your submission and either certify you (on pass), or provide feedback on what needs to be addressed.
Level 1 is a great starting point for organisations that want a structured, documented approach to information security governance, assessed against an independent standard by an accredited assessor.
This builds on Level 1, with our accredited assessor carrying out an independent audit across all 14 themes examining your evidence, testing your controls and forming an independent view.
Level 2 provides extra assurance based on it being an assessment. Increasingly required in contracts and organisations where the self-assessment is not considered sufficient.
Three common motivations driving IASME adoption. Pick whichever resonates with your situation.
If your clients or procurement frameworks require evidence of information security governance that goes beyond Cyber Essentials, IASME provides that evidence in a format designed for SMEs. The 14 themes cover the areas compliance officers actually ask about.
For many smaller organisations, ISO 27001 is not proportionate to their size. IASME tailored the Cyber Assurance scheme for SMEs and made it flexible in the latest version. It can be accepted as equivalent by frameworks that would previously have specified ISO 27001.
Unsure which fits? That is exactly the call to book.
The Planning, Legal Landscape and Policies themes within IASME speak directly to how you manage your own suppliers and third parties. Achieving certification demonstrates that your approach to supply chain security is structured and documented, not informal.
Most organisations start at Level 1 and progress to Level 2 if a contract or framework specifically requires it. A short call usually makes the right path obvious.
Four routes depending on whether you need Level 1 or Level 2, with or without our support through the process.
You complete the self-assessment. Our assessor reviews it and certifies you on pass. Two attempts included.
We work with you through the self-assessment, calibrated to where you are starting from.
Our assessor conducts the independent audit across all 14 themes.
Full support through the Level 2 process, including documentation review and pre-audit preparation.
All reviews are independently verified on Google.
Remo guided us clearly at every step, making what initially seemed complex very easy to understand. Their friendly and approachable manner made the whole experience stress-free. Highly recommend.
It felt less like working with a consultant and more like having a trusted partner invested in our success. We passed both assessments smoothly and with confidence.
A subject matter expert who efficiently identified issues and provided the right level of support to achieve certification well within timescales.
The process was very smooth sailing and the advice was invaluable. Highly recommend, and I would happily work with RB Consultancy Ltd again.
They made what initially seemed complex very easy to understand. Highly recommend their services to anyone looking for expert and reliable Cyber Essentials support.
Excellent service. Very professional, very thorough — exactly what we needed to get over the line on our Cyber Essentials Plus assessment.
Remo guided us clearly at every step, making what initially seemed complex very easy to understand. Their friendly and approachable manner made the whole experience stress-free. Highly recommend.
It felt less like working with a consultant and more like having a trusted partner invested in our success. We passed both assessments smoothly and with confidence.
A subject matter expert who efficiently identified issues and provided the right level of support to achieve certification well within timescales.
The process was very smooth sailing and the advice was invaluable. Highly recommend, and I would happily work with RB Consultancy Ltd again.
They made what initially seemed complex very easy to understand. Highly recommend their services to anyone looking for expert and reliable Cyber Essentials support.
Excellent service. Very professional, very thorough — exactly what we needed to get over the line on our Cyber Essentials Plus assessment.
The process was very smooth sailing and the advice was invaluable. Highly recommend, and I would happily work with RB Consultancy Ltd again.
They made what initially seemed complex very easy to understand. Highly recommend their services to anyone looking for expert and reliable Cyber Essentials support.
Excellent service. Very professional, very thorough — exactly what we needed to get over the line on our Cyber Essentials Plus assessment.
Remo guided us clearly at every step, making what initially seemed complex very easy to understand. Their friendly and approachable manner made the whole experience stress-free. Highly recommend.
It felt less like working with a consultant and more like having a trusted partner invested in our success. We passed both assessments smoothly and with confidence.
A subject matter expert who efficiently identified issues and provided the right level of support to achieve certification well within timescales.
The process was very smooth sailing and the advice was invaluable. Highly recommend, and I would happily work with RB Consultancy Ltd again.
They made what initially seemed complex very easy to understand. Highly recommend their services to anyone looking for expert and reliable Cyber Essentials support.
Excellent service. Very professional, very thorough — exactly what we needed to get over the line on our Cyber Essentials Plus assessment.
Remo guided us clearly at every step, making what initially seemed complex very easy to understand. Their friendly and approachable manner made the whole experience stress-free. Highly recommend.
It felt less like working with a consultant and more like having a trusted partner invested in our success. We passed both assessments smoothly and with confidence.
A subject matter expert who efficiently identified issues and provided the right level of support to achieve certification well within timescales.
Quick answers to the questions we get most often. Anything else, ask us.
Yes. Either Cyber Essentials or IASME Cyber Baseline certification is required as a prerequisite. As an accredited certification body, we can take you through both certification schemes. We can be your one-stop shop for Cyber Essentials and IASME Cyber Assurance.
They are different standards with different origins and structures, but IASME Cyber Assurance can cover comparable ground. Whether it meets your specific requirement depends on who is asking and what they need to see. We can help you assess that before you commit to either path.
There’s a mapping document on the Gov.UK website for Boards, Directors and Chief Information Security Officers (CISOs) which illustrates the similarities and differences. It can be used as a reference point, rather than be authoritative or be taken as legal advice on compliance with the frameworks.
It depends. Timeline for certification can vary considerably by organisation. Key factors include the level of IASME Cyber Assurance required and how close an organisation is to meeting the controls. Let’s have a quick call and we can help you determine the likely timeline for Level 1 and/or Level 2. We also work to flag any issues early, to reduce impact and maximise efficiencies.
For organisations in regulated sectors, complex supply chains or bidding for contracts that require evidence of information security governance beyond Cyber Essentials, it is increasingly the practical answer. If a client or framework has specifically required it, that is a clear signal.
Book a free 30-minute call. We will talk through the IASME framework and a realistic path to certification.

Registered Address: 20-22 Wenlock Road, London, England, N1 7GU
Trading Address:Pioneer House, Pioneer Business Park, North Road, Ellesmere Port, Cheshire,
CH65 1AD
Registration Number: 14677066
VAT Number: 479590726
NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP