Skip to main content

Framework · UK cyber resilience

IASME Cyber Assurance

The IASME cyber resilience standard, designed for organisations that require cyber assurance beyond the technical controls of Cyber Essentials. Covers information security, data privacy, and data protection across 14 themes.

WHERE THIS FRAMEWORK FITS

Where this framework fits at Goldline

Goldline does not deliver IASME Cyber Assurance as a standalone certification service. For organisations approaching this framework, we typically recommend a partner referral to an IASME-licensed Certification Body for the technical assessment, and where appropriate, we deliver the ISO 27001 implementation that gives you a broader information security management system foundation.

For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.

Book the Free Diagnostic

Browse all frameworks

What is IASME Cyber Assurance?

  • Cost-effective: an affordable approach to managing information security, implementing security measures, and achieving certification

  • Comprehensive: covers cyber security, data privacy, and data protection

  • Extensive: goes well beyond the five technical controls of Cyber Essentials, with applicants required to hold Cyber Essentials or IASME Cyber Baseline as a prerequisite

  • Level One: a verified self-assessment covering all 14 themes

  • Level Two: an independently audited assessment for further assurance

  • 14 themes: assets, legal landscape, risk assessment, organisation, training, physical protection, planning, policies and procedures, managing access, technical intrusion, backup and restore, monitoring, change management, and resilience

The 14 themes

IASME Cyber Assurance organises its requirements across 14 themes covering cyber security, data privacy, and data protection. Every theme is assessed at both Level One and Level Two.

Theme 1

Assets

Understanding what to protect.

Theme 2

Legal landscape

Awareness of contractual and regulatory obligations.

Theme 3

Risk assessment

Acceptable level of risk assessment, management, and treatment.

Theme 4

Organisation

Clear structure for effective information security.

Theme 5

Training

Enabling people to understand and comply with security responsibilities.

Theme 6

Physical protection

Protecting information from physical threats.

Theme 7

Planning

Information security in projects, procurement, and supplier relationships.

Theme 8

Policies and procedures

Documented rules, guidelines, and regulations.

Theme 9

Managing access

Least-privilege principles.

Theme 10

Technical intrusion

Controls to prevent unauthorised access.

Theme 11

Backup and restore

Protecting information from accidents and tampering.

Theme 12

Monitoring

Detecting threats and acting accordingly.

Theme 13

Change management

Managing information system changes.

Theme 14

Resilience

Business continuity, incident management, and disaster recovery.

Level One versus Level Two

IASME Cyber Assurance is offered at two assurance levels. Both cover the same 14 themes; the difference is the depth of independent verification.

Level One

Self-assessed

  • Verified self-assessment covering all 14 themes

  • Signed off by senior representative

  • Lower cost, faster completion

  • Suitable for organisations building assurance maturity

  • Prerequisite: Cyber Essentials or IASME Cyber Baseline

Level Two

Independently audited

  • Independent audit of all 14 themes by IASME assessor

  • Deeper assurance for stakeholders and supply chain

  • Higher cost, longer engagement

  • Suitable for organisations demonstrating advanced cyber resilience

  • Prerequisite: Cyber Essentials Plus or IASME Cyber Baseline

Who IASME Cyber Assurance applies to

  • UK small and medium organisations seeking cyber resilience beyond Cyber Essentials

  • Organisations required to demonstrate cyber posture to enterprise customers or in supply chain due diligence

  • Public sector suppliers where IASME certification is recognised or preferred

  • Organisations pursuing GDPR-aligned information security demonstration

  • Organisations on the certification staircase from Cyber Essentials to ISO 27001

Related pages

IASME Cyber Assurance sits between Cyber Essentials and ISO 27001 on the UK cyber certification staircase. Explore the delivery programme and the frameworks that most Goldline clients progress to.

Frequently asked questions

Discuss where this framework fits your programme

IASME Cyber Assurance is not a service Goldline delivers as a standalone product. Book the Free Diagnostic to discuss the right route to certification and whether ISO 27001 implementation is the right foundation for your organisation.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.