Compliance

IASME

IASME Consortium

IASME (originally Information Assurance for Small and Medium Enterprises) is a UK organisation, structured as IASME Consortium, that operates as the National Cyber Security Centre's appointed delivery partner for the Cyber Essentials and Cyber Essentials Plus certification scheme.

Why IASME matters in a Microsoft estate

IASME matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.

How IASME shows up in practice

It manages the accreditation of the certification bodies that actually assess and certify applicant organisations, rather than performing every individual assessment itself. In practice this means IASME sits in the middle of the scheme's structure: the NCSC sets the scheme's requirements and overall direction, and IASME accredits and licenses a network of certification bodies (assessors) across the UK who are authorised to review Cyber Essentials self-assessment questionnaires and carry out Cyber Essentials Plus technical verification. Those certification bodies are the ones an applicant organisation typically deals with directly when applying for certification, submitting evidence, and receiving their certificate.

Beyond its role in Cyber Essentials, IASME also owns and develops its own separate standard, the IASME Cyber Assurance standard (the successor to what was previously called IASME Governance). This is a broader cyber security and data protection standard covering a wider set of controls than Cyber Essentials alone, including elements more closely aligned with GDPR compliance. It is available at both a self-assessed and, since 2024, an audited assurance level, giving smaller organisations a more comprehensive certification path than Cyber Essentials without requiring a jump straight to ISO/IEC 27001.

For UK IT teams and MSPs, the practical relevance of IASME is mostly indirect: organisations pursuing Cyber Essentials certification will encounter IASME's name on their certificate and in scheme documentation. Their actual day-to-day interaction is normally with a specific licensed certification body rather than IASME centrally. Confusion sometimes arises from assuming IASME performs assessments directly, when it is, in the great majority of cases, the accreditor rather than the assessor. IASME is also directly relevant to MSPs specifically because it operates a Cyber Essentials partner and reseller-style scheme for organisations that want to become a certification body or a Cyber Essentials-badged partner themselves.

This is one route by which MSPs offering compliance support to their own clients formalise that relationship, rather than simply pointing clients at the scheme independently. Since Cyber Essentials and Cyber Essentials Plus have become an effective baseline expectation across UK public sector procurement, cyber insurance underwriting, and increasingly commercial supply chains, understanding that IASME is the scheme's delivery infrastructure rather than a certification in its own right (aside from its separate Cyber Assurance standard) is worth getting right. It helps avoid the common error of treating "IASME certified" and "Cyber Essentials certified" as different things when, for the base scheme, they describe the same certificate delivered through IASME's accredited network.

Glossary