Framework · UK cyber resilience
IASME Cyber Assurance
The IASME cyber resilience standard, designed for organisations that require cyber assurance beyond the technical controls of Cyber Essentials. Covers information security, data privacy, and data protection across 14 themes.
WHERE THIS FRAMEWORK FITS
Where this framework fits at Goldline
Goldline does not deliver IASME Cyber Assurance as a standalone certification service. For organisations approaching this framework, we typically recommend a partner referral to an IASME-licensed Certification Body for the technical assessment, and where appropriate, we deliver the ISO 27001 implementation that gives you a broader information security management system foundation.
For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.
Book the Free DiagnosticWhat is IASME Cyber Assurance?
Cost-effective: an affordable approach to managing information security, implementing security measures, and achieving certification
Comprehensive: covers cyber security, data privacy, and data protection
Extensive: goes well beyond the five technical controls of Cyber Essentials, with applicants required to hold Cyber Essentials or IASME Cyber Baseline as a prerequisite
Level One: a verified self-assessment covering all 14 themes
Level Two: an independently audited assessment for further assurance
14 themes: assets, legal landscape, risk assessment, organisation, training, physical protection, planning, policies and procedures, managing access, technical intrusion, backup and restore, monitoring, change management, and resilience
The 14 themes
IASME Cyber Assurance organises its requirements across 14 themes covering cyber security, data privacy, and data protection. Every theme is assessed at both Level One and Level Two.
Assets
Understanding what to protect.
Legal landscape
Awareness of contractual and regulatory obligations.
Risk assessment
Acceptable level of risk assessment, management, and treatment.
Organisation
Clear structure for effective information security.
Training
Enabling people to understand and comply with security responsibilities.
Physical protection
Protecting information from physical threats.
Planning
Information security in projects, procurement, and supplier relationships.
Policies and procedures
Documented rules, guidelines, and regulations.
Managing access
Least-privilege principles.
Technical intrusion
Controls to prevent unauthorised access.
Backup and restore
Protecting information from accidents and tampering.
Monitoring
Detecting threats and acting accordingly.
Change management
Managing information system changes.
Resilience
Business continuity, incident management, and disaster recovery.
Level One versus Level Two
IASME Cyber Assurance is offered at two assurance levels. Both cover the same 14 themes; the difference is the depth of independent verification.
Level One
Self-assessed
Verified self-assessment covering all 14 themes
Signed off by senior representative
Lower cost, faster completion
Suitable for organisations building assurance maturity
Prerequisite: Cyber Essentials or IASME Cyber Baseline
Level Two
Independently audited
Independent audit of all 14 themes by IASME assessor
Deeper assurance for stakeholders and supply chain
Higher cost, longer engagement
Suitable for organisations demonstrating advanced cyber resilience
Prerequisite: Cyber Essentials Plus or IASME Cyber Baseline
Who IASME Cyber Assurance applies to
UK small and medium organisations seeking cyber resilience beyond Cyber Essentials
Organisations required to demonstrate cyber posture to enterprise customers or in supply chain due diligence
Public sector suppliers where IASME certification is recognised or preferred
Organisations pursuing GDPR-aligned information security demonstration
Organisations on the certification staircase from Cyber Essentials to ISO 27001
Related pages
IASME Cyber Assurance sits between Cyber Essentials and ISO 27001 on the UK cyber certification staircase. Explore the delivery programme and the frameworks that most Goldline clients progress to.
Frequently asked questions
Discuss where this framework fits your programme
IASME Cyber Assurance is not a service Goldline delivers as a standalone product. Book the Free Diagnostic to discuss the right route to certification and whether ISO 27001 implementation is the right foundation for your organisation.
