IASME Cyber Assurance

Hands-on start-to-finish support for both Level 1 and Level 2 of Cyber Essentials' sister standard in governance, risk, and policy.

Book a chat

What is IASME Cyber Assurance?

The IASME Cyber Assurance standard is a cyber security standard designed and maintained by IASME on behalf of the National Cyber Security Centre. It provides assurance that an organisation has put in place a range of important cyber security, privacy, and data protection measures, looking mostly at your policies and procedures.

Becoming certified allows small and medium-sized enterprises in a supply chain to demonstrate their level of cyber security for a more realistic cost than alternatives like ISO 27001. It aims to indicate that they are taking good steps to properly protect their customers' information.

It involves a self-assessment at Level 1, confirmed but not audited by a certifying body, and then an audit at Level 2. That audit is a conversation-driven show-and-tell of the system, to validate that all the appropriate measures and policies are in place.

IASME Cyber Assurance is unique in that it has adaptive requirements based on the size and maturity of your organisation. It's comparatively a lot easier to satisfy than ISO 27001, and demonstrates a similar level of resilience and cyber maturity. It's also prescriptive rather than risk-based, which means you have to meet certain requirements and produce certain documents, rather than conducting a risk assessment to avoid certain controls as you would under ISO 27001. That makes IASME Cyber Assurance a very effective way to develop a cybersecurity roadmap without an administrative overhead.

How does it work?

The scheme is owned by the UK Government and managed by a group called IASME. Turtledove Cyber (that's us) have been assessed and certified as a Certification Body, so we provide start-to-finish support and assessment for IASME Cyber Assurance Level 1 and Level 2.

The pricing for Cyber Assurance Level 1 is set in stone by IASME to make sure it's accessible. That means the decision of who should support you on your journey should always come down to who you'd like to work with, and how easy they can make it for you. The best resource to learn about the scheme is the official IASME page.

A proper approach that starts where you need it to

We can provide:

  • Support in understanding the standard and its requirements.
  • Hands-on development and support of a management system for the standard, with policy templates available.
  • Tabletop exercises and training to ensure your system is business-ready as well as certification-ready. This includes making sure staff understand how to use any relevant policy or procedure produced by your assessment preparation.
  • Direct input to ensure you effectively communicate the effectiveness of your management system in assessment.

Why choose Turtledove Cyber?

Believe it or not, the cybersecurity market in the UK is largely unregulated, so picking a provider with the right experience really does matter. Reputation is everything. Here's why you should pick Turtledove Cyber.

Direct contact

We're a small business with excellent reviews. You'll be working directly with Savva.

The spirit of the work

The only thing you need to know when you reach out is that you want the standard. We have taken plenty of organisations there from a standing start.

No sales teams

You only work with the people who deliver your exact outcome. No sales teams, no email tennis, no fluff. One point of contact from start to finish.

Lorem ipsum dolor sit?

Get in touch to learn more, and we'll work out together which level fits your organisation.

Book a chat
Brand palette preview