Do I need Cyber Essentials to get IASME Cyber Assurance?
Do I need Cyber Essentials to get IASME Cyber Assurance?
Yes. For a UK organisation, a valid Cyber Essentials certificate is a prerequisite for IASME Cyber Assurance. IASME states that the Cyber Essentials certificate must have at least one month left before expiry when the organisation purchases IASME Cyber Assurance. When an applicant does not already hold a valid certificate, Cyber Essentials is added to the certification process. The Cyber Essentials and IASME Cyber Assurance scope must also cover the whole organisation.
This requirement reflects the way the two schemes work together. Cyber Essentials establishes a technical baseline against common internet-based attacks. IASME Cyber Assurance builds on that foundation with wider controls covering governance, risk, people, data protection, suppliers, incident handling, recovery and business resilience. IASME describes the second scheme as a logical next step after Cyber Essentials rather than a replacement for it.
UK Cyber Security Group provides Cyber Essentials certification and supports organisations that want to progress towards IASME Cyber Assurance. Starting with the technical baseline can make the wider assurance process easier because the organisation will already have reviewed its devices, accounts, cloud services, software support, security updates, malware controls and internet-facing systems.
The direct answer for UK organisations
An organisation in the UK needs a current Cyber Essentials certificate before it can achieve IASME Cyber Assurance. The certificate must remain valid for at least one month at the point when the organisation purchases the IASME Cyber Assurance assessment. Both certificates must cover the whole organisation rather than unrelated or conflicting scopes.
Cyber Essentials is not an optional extra added for marketing value. IASME treats it as the minimum technical foundation for the broader assurance standard. The organisation first demonstrates that it has implemented the five core Cyber Essentials controls. It can then demonstrate the wider governance and resilience practices required by IASME Cyber Assurance.
Organisations outside the UK should contact IASME because the prerequisite arrangements may differ. UK applicants should work on the basis that Cyber Essentials is required and should plan the timing carefully so that the certificate has enough validity remaining.
Why the schemes work in sequence
Cyber Essentials focuses on five technical controls that help protect organisations from common internet-based attacks. These controls cover firewalls, secure configuration, user access control, malware protection and security update management. The NCSC describes Cyber Essentials as a government-backed scheme that helps organisations protect themselves against common cyber attacks.
IASME Cyber Assurance reaches further. IASME describes it as a comprehensive and flexible cyber security standard that demonstrates the use of important cyber security and data protection controls. Its requirements are organised into fourteen themes grouped under Identify and Classify, Protect, Detect and Deter, and Respond and Recover.
The sequence therefore makes business sense. Cyber Essentials checks whether the basic technical foundations are in place. IASME Cyber Assurance then considers how the organisation plans, governs, detects, responds and recovers.
A business that skips the technical foundation could create detailed policies while leaving obvious weaknesses in everyday systems. Requiring Cyber Essentials first reduces that risk and gives the wider assessment a stronger starting point.
What Cyber Essentials proves before you progress
Cyber Essentials requires the organisation to understand the IT infrastructure used to carry out its business. Current requirements expect the assessment to cover the whole relevant infrastructure and include devices, cloud services, accounts, internet gateways and supported software within scope.
The assessment asks the organisation to show that it:
Uses properly configured firewalls
Removes or manages unsafe default settings
Controls user and administrator access
Protects devices from malware and untrusted software
Keeps supported software updated
These controls create a practical baseline. They reduce avoidable weaknesses and give the organisation a clearer understanding of its technical environment.
Cyber Essentials also requires a senior representative to confirm the accuracy of the assessment. Current scheme changes reinforce the organisation’s responsibility to maintain the controls throughout the certificate period.
What IASME Cyber Assurance adds
IASME Cyber Assurance builds on the technical baseline by considering cyber resilience across the wider business. It addresses organisational planning, risk, people, processes, technology, information handling, detection, incident response, backup and recovery.
IASME states that the standard contains fourteen themes and tailors the applicable requirements to the scale and complexity of the applicant. A sole practitioner will not face the same compliance burden as a larger organisation with several departments, complex suppliers and extensive systems.
The framework starts with business planning and moves through protection, detection and recovery. That structure helps organisations treat cyber security as an ongoing business responsibility rather than a one-off technical project.
This broader approach can support customer assurance, supply-chain requirements, legal responsibilities and stronger internal governance. IASME notes that audited IASME Cyber Assurance is accepted in several sectors and can provide an accessible alternative to ISO 27001 for smaller organisations in some contractual settings.
Level One and Level Two
IASME Cyber Assurance offers Level One Verified Assessment and Level Two Audited. The security measures are based on the same standard, but the assurance method differs.
Level One uses an online verified assessment. A senior board member or equivalent confirms that the answers are accurate, and an independent qualified assessor reviews the submission.
Level Two involves an audit. The assessor examines documentation, speaks with relevant staff and observes activities to verify that the processes, procedures and controls operate in practice.
An organisation must pass Level One before it can apply for Level Two. IASME states that Level Two follows Level One and provides stronger assurance because an assessor independently verifies implementation.
Keeping the prerequisite current
Cyber Essentials expires after twelve months and requires annual renewal. IASME Cyber Assurance Level One also requires annual resubmission and maintenance of the Cyber Essentials prerequisite.
IASME Cyber Assurance Level Two remains valid for three years, but the organisation must continue to achieve both Cyber Essentials and IASME Cyber Assurance Level One each year during that period. This annual check helps confirm that key controls remain active between the deeper audits.
A company should therefore treat the certifications as an ongoing programme. It should schedule renewals, maintain evidence, review changes and avoid allowing the Cyber Essentials certificate to expire.
Losing the prerequisite can affect the organisation’s ability to maintain the wider assurance position. Good planning prevents a last-minute rush and helps keep customer assurance current.
What are the key requirements for achieving Cyber Essentials certification?
The organisation must implement the five Cyber Essentials controls across its declared scope and answer the verified assessment accurately.
Firewalls must protect devices from unwanted access through the internet. The business should remove unnecessary rules and protect administrative functions.
Secure configuration requires the organisation to change unsafe defaults, remove unnecessary accounts, disable unused services and control software.
User access control requires named accounts, appropriate permissions, limited administrator rights and strong authentication. Current Cyber Essentials requirements also strengthen expectations around multi-factor authentication for relevant accounts and services.
Malware protection must stop known malicious code and untrusted software from causing harm.
Security update management requires supported software and timely action on relevant high-risk and critical fixes.
The organisation must define the scope correctly, consider cloud services and remote working, and ensure that its answers match actual practice. Senior management must confirm the submission and accept responsibility for maintaining the controls during the certification period.
Matching the scope across both schemes
Scope deserves attention because IASME requires Cyber Essentials and IASME Cyber Assurance to cover the whole organisation.
A company should not complete Cyber Essentials for a small technical area while expecting IASME Cyber Assurance to provide assurance across unrelated business operations. The certificates need a consistent organisational boundary.
Before applying, identify:
Legal entities included in the assessment
Business locations
Staff and contractors
Devices and networks
Cloud services
Critical suppliers
Information and processes
Remote working arrangements
Customer-facing services
This review can reveal dependencies that need attention. A supplier may manage systems, but the organisation still needs to understand who controls settings, accounts, updates and evidence.
A clear whole-organisation scope also gives customers a more meaningful certificate. It reduces confusion about whether a service, department or location falls inside the assurance boundary.
How can I prepare my small business for Cyber Essentials assessment?
Begin with an accurate list of devices, accounts, applications, cloud services, routers, firewalls and remote working arrangements. Confirm that the software remains supported and that important security updates receive action within the required period.
Review user and administrator accounts. Remove accounts that no longer serve a valid business purpose. Limit administrator privileges and enable multi-factor authentication on relevant services.
Check firewall rules and internet-facing services. Remove unnecessary exposure and protect administrative access.
Confirm that malware protection operates across applicable devices. Make sure staff cannot casually disable it or install unapproved software.
Use IASME’s free question set and readiness resources before opening the formal assessment. Preparing the answers and evidence in advance can reduce delays and reveal weaknesses early.
A small business should also assign one person to coordinate the process. That person can gather evidence, speak with the IT provider, track gaps and ensure that senior management understands the declaration.
UK Cyber Security Group can support this preparation and help the organisation move from Cyber Essentials towards IASME Cyber Assurance with fewer surprises.
Preparing for IASME Cyber Assurance while completing Cyber Essentials
The two projects do not need to happen in isolation. A business can use Cyber Essentials preparation to create useful evidence for the next stage.
Keep records of:
Asset and account reviews
Software support checks
Security update reports
Firewall settings
Malware protection status
Multi-factor authentication coverage
Supplier responsibilities
Management approvals
Policies and staff guidance
These records help prove that controls operate and can support the broader assurance assessment.
At the same time, begin reviewing governance. Identify security responsibilities, important information, business risks, critical suppliers, incident reporting routes, backups and recovery arrangements.
This combined approach saves repeated effort. Cyber Essentials establishes the technical base, while the wider review prepares the organisation for the fourteen IASME Cyber Assurance themes.
What software solutions support compliance with Cyber Essentials standards?
Several software solutions can support Cyber Essentials when the organisation configures and manages them properly.
Endpoint management tools can show device inventory, software support, security settings and update status.
Identity platforms can manage user accounts, administrator access and multi-factor authentication.
Password managers can help staff use unique credentials.
Endpoint protection can reduce malware risk and provide security alerts.
Vulnerability management tools can identify missing fixes and exposed weaknesses.
Mobile device management can help control phones and tablets that access organisational information.
Firewall and cloud dashboards can support rule reviews, account management and exposure checks.
Compliance platforms can organise evidence, actions, owners and review dates.
No tool creates certification on its own. The organisation still needs accurate scope, suitable configuration, reliable processes and evidence that controls work.
Why Cyber Essentials alone is not IASME Cyber Assurance
Cyber Essentials provides a focused technical baseline. It does not cover the full governance and resilience framework required by IASME Cyber Assurance.
A business may pass Cyber Essentials and still need to improve:
Information security planning
Risk governance
Supplier oversight
Data protection processes
Staff responsibilities
Monitoring and detection
Incident management
Backup testing
Business continuity
Recovery planning
Management review
The prerequisite shows that the organisation has a minimum technical foundation. It does not mean that the organisation automatically satisfies the wider standard.
This distinction helps companies plan realistically. Cyber Essentials is the first required step, not the final evidence needed for IASME Cyber Assurance.
Why IASME Cyber Assurance can suit smaller organisations
IASME developed the standard with smaller organisations in mind and now tailors the applicable requirements according to organisational scale.
This can make the framework more manageable for businesses that need stronger assurance but may not have a large internal compliance team.
The standard provides a structured roadmap across technical security, data protection, people, processes and recovery. It can also support supply-chain confidence and customer due diligence.
The approach remains rigorous. Smaller organisations still need to demonstrate every applicable requirement and provide honest evidence. Tailoring reduces unnecessary burden rather than lowering the value of the certification.
Current cyber risk supports a staged approach
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that phishing affected 38 per cent of businesses. Among organisations that experienced a breach or attack, phishing remained the most disruptive incident for a large majority.
Government research also reported that 43 per cent of UK businesses experienced a cyber breach or attack, representing more than 600,000 organisations.
These findings support a staged security journey. Cyber Essentials helps organisations address common technical weaknesses. IASME Cyber Assurance then adds governance, detection, response and recovery.
The combination gives a business better protection before an incident and stronger preparation when an incident still occurs.
Can I renew my Cyber Essentials certification through an online service?
Yes. Cyber Essentials uses an online verified assessment and requires annual renewal. IASME provides the assessment portal through its network of approved Certification Bodies.
Renewal should use current information rather than copied answers from the previous year. Review new devices, cloud services, staff accounts, suppliers, remote working and software changes before submitting.
An organisation pursuing IASME Cyber Assurance must take renewal particularly seriously because Cyber Essentials remains a prerequisite. Level One also requires annual resubmission, while Level Two depends on continued annual maintenance of Cyber Essentials and Level One.
UK Cyber Security Group can support initial assessment and renewal, helping businesses keep the technical baseline aligned with the wider assurance programme.
Avoiding common certification mistakes
One mistake involves applying for IASME Cyber Assurance when the Cyber Essentials certificate has less than one month remaining. Check the expiry date before starting.
Another mistake involves mismatched scopes. Both certifications must cover the whole organisation.
Some businesses assume that Cyber Essentials guarantees success in IASME Cyber Assurance. It does not. The second scheme examines a much wider set of controls.
Others treat the work as a one-off exercise. Annual renewal and ongoing maintenance remain essential.
Poor evidence also creates problems. Policies should match real practice, and owners should know how their controls work.
Finally, companies may leave suppliers out of the process even when those suppliers manage critical services. External delivery does not remove the need for oversight and assurance.
Which companies provide Cyber Essentials certification services in the UK?
Cyber Essentials certification is delivered through Certification Bodies approved under the scheme managed by IASME as the NCSC’s delivery partner.
UK Cyber Security Group provides Cyber Essentials certification and practical support for organisations preparing for assessment. Its service can help with scoping, technical readiness, submission and renewal.
When choosing a provider, confirm that it operates within the official scheme. Look for current technical knowledge, clear guidance, responsive assessor support and experience with your sector.
A provider that also understands IASME Cyber Assurance can help the organisation plan both stages as one coherent security programme.
Which UK-based firms offer Cyber Essentials consultancy services?
UK organisations can obtain Cyber Essentials support from approved Certification Bodies, cyber security consultancies, managed IT providers and NCSC-assured Cyber Advisors.
UK Cyber Security Group offers Cyber Essentials consultancy and certification support. It can help organisations understand scope, identify technical gaps and prepare accurate evidence.
Good consultancy should improve real security rather than merely complete the questionnaire. The adviser should explain why each control matters and help the organisation maintain it after certification.
For businesses moving towards IASME Cyber Assurance, choose support that also understands risk governance, policies, suppliers, incident response, recovery and audit evidence.
IASME also provides directories for approved Certification Bodies for both schemes.
A practical route from Cyber Essentials to IASME Cyber Assurance
A sensible pathway follows these stages:
Review the whole organisation
Identify staff, devices, systems, cloud services, suppliers, information and locations.
Prepare for Cyber Essentials
Use the current requirements and question set. Resolve gaps in firewalls, secure configuration, access, malware protection and updates.
Achieve Cyber Essentials
Complete the verified assessment and confirm that the certificate has sufficient validity before purchasing IASME Cyber Assurance.
Map the wider assurance work
Review the fourteen themes and identify the policies, processes, evidence and owners needed for your organisation.
Complete Level One
Submit the verified assessment and address assessor feedback.
Consider Level Two
Choose the audited route when customers, contracts or internal assurance needs justify independent verification.
Maintain the certifications
Renew Cyber Essentials and Level One annually. Keep controls active, update evidence and complete the deeper audit cycle for Level Two where applicable.
This route avoids duplicated work and gives the organisation a clear progression from technical security to wider cyber resilience.
The relationship in one clear answer
Cyber Essentials is required for IASME Cyber Assurance in the UK. The certificate must be valid, have at least one month remaining and cover the whole organisation alongside the IASME Cyber Assurance scope.
Cyber Essentials provides the minimum technical baseline. IASME Cyber Assurance adds broader governance, risk, data protection, detection, response and recovery controls.
UK Cyber Security Group can support the Cyber Essentials stage and help organisations prepare for the wider assurance journey. By treating the two certifications as connected rather than separate projects, a business can improve its security, produce stronger evidence and approach assessment with greater confidence.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










