Protect your operations, relationships and reputation
Are you a SME trading in the UK?
Achieving IASME Governance certification is a cost-effective way to protect your growing business against cyber threats and comply with data privacy legislation.
IASME Governance is designed specifically to support UK SMEs. It includes the popular Cyber Essentials certification and drives compliance with the UK Data Protection Act (DPA) and the GDPR. There are two variants – self-assessed and audited (also known as IASME Gold).
Benefits of IASME Governance
Protect itself against 80% of cyber attacks
Safeguard valuable business data through GDPR and DPA compliance
Reassure stakeholders
Demonstrate technical and organisational measures as required by the ICO
Shortcut lengthy supplier questionnaires
Benefit from free cyber insurance
Transition more smoothly to ISO27001 when you need an internationally recognised certification
How we can help you achieve IASME Governance certification
With a 100% pass rate, including our own certification, we know exactly how to gather the information needed to benchmark your systems against the requirements.
Once your named consultant has audited your processes and existing measures, they’ll create a bespoke action plan to address any areas of weakness. Whilst you make improvements, they’ll prepare a draft submission, ensuring that all 160 questions are properly answered. Of course, we’ll provide telephone and email support throughout the process for additional peace of mind.
Getting started with certification
Approaching audits with confidence
How we can help you maintain compliance
IASME Governance certification lasts for one year. We’ll remind you before your certification is due to expire and help you update your self-assessment.
We can also provide expert advice relating to cyber security and data all year round as part of Compliance in a Service.
FAQs
The IASME Governance standard enables smaller companies to prove that they have taken meaningful steps to implement robust cyber security procedures and protect their customers’ information. It aligns with the Government’s 10 Steps to Cyber Security which is used by the majority of the FTSE350.
For smaller businesses, IASME is an affordable alternative to ISO27001, the Information Security Management Standard.
The IASME Governance standard includes assessments against Cyber Essentials and the GDPR as well as looking at the role of people and processes. The 22 topics include configuration, patching, firewalls, malware, business continuity, cloud services and data protection as well as risk management, leadership, supplier assurance and incident management.
There are two types of IASME certification – Self-assessed and Audited (sometimes known as Gold).
The self-assessment form of IASME involves completing a 43-page questionnaire about company’s cyber security and data management.
The Audited (Gold) version of IASME requires you to pass an on-site audit conducted by an IASME certified assessor.
For the majority of areas, the IASME Governance standard meets or exceeds the requirements of the NHS Digital Data Security Standards. In some areas an action, process or tool that is specific to the NHS is referenced by the NHS Digital Data Security standard and does not map directly to the IASME Governance standard. IASME Governance provides a great framework to meet the NHS requirements and, where there are gaps, our team will help to close these.
The thought of answering 160 questions about your cyber security and data protection may seem daunting but our step-by-step approach will help you achieve certification.
We’ll begin by explaining what the certification requires. Then, with your permission, we’ll liaise with your IT and HR teams (in-house or outsourced) to gather the information needed to compare your current performance against the assessment criteria. Once we’ve performed a gap analysis, we’ll create a step-by-step action plan for you to follow. Of course, you’ll always have our support via email or phone. Once we’re satisfied that you have completed your actions, we’ll ask you to review and approve the draft IASME submission which we’ll have prepared for you.
If you’ve already failed your IASME Governance certification, don’t worry. We have a 100% success rate! Simply contact us to explore how we can help.
If you ask us to support you through IASME Governance, we’ll make sure that you don’t just meet the requirements of the scheme but exceed them. After all, when it comes to protecting your business from cyberattack, cutting corners is a false economy. We want to ensure your business is properly protected against cyber risks and data loss.
Of course, if you choose not to work with us, you could attempt to fudge your answers. However, you would be committing fraud and putting your business at risk. There would also be a good chance that any misrepresentation would be picked up during the assessment process. The certification bodies are themselves assessed by IASME to ensure that the integrity of the certification is upheld.
Discover more in our blog on the credibility of self-assessed certifications.
We can normally help a client achieve IASME Governance within six to eight weeks. However, the actual time taken depends on various factors including the size of your business and the availability of key personnel.
We offer telephone and email support as part of our Compliance in a Service. This includes expert advice relating to cyber security, ISO, GDPR and H&S from our panel of experts.
Once your answers have been uploaded to the portal, you’ll normally hear the results within 72 hours. You will also receive a copy of your report after your assessment is complete.
Yes, you will receive an IASME Governance certificate and a Cyber Essentials certificate. The logos can be used on your website and in your marketing materials. We’ll provide you with a free copy of our Promotion Power Pack, a guide to promoting your certifications.
Your company name will also be added to the National Cyber Security Centre’s register of organisations holding the Cyber Essentials certification.
Your IASME Governance and Cyber Essentials certificates will be valid for 12 months. We will contact you before your renewal is due and help you through re-certification.
Absolutely. We have recognised four distinct benefits since first gaining our certification in 2015. Firstly, by ensuring we meet the requirements of IASME Governance, we continue to reduce the risk of our business being impacted by a cyberattack. Secondly, it allows us to demonstrate to the ICO that we have taken both technical and organisational measures to comply with the EU GDPR and UK DPA. It also saves us time and money by enabling us to shortcut many tedious supplier questionnaires when bidding for new business. Finally, and most importantly perhaps for us, it allows us to have informed conversations with prospective clients and differentiates us from the competition.
We know that our IASME Governance clients experience and appreciate the same benefits.
Don’t worry, this happens! IASME Governance may not be as well-known as ISO27001 but it bears up well under scrutiny. We’ve already helped many IASME Governance certified clients convince procurement teams that it’s a robust and credible alternative to ISO27001.
IASME Governance is not mandatory, however it can help you win new business and protect your assets, making it a worthwhile investment. Achieving IASME Governance supports compliance with the technical and organisational measures necessary for GDPR compliance.
As your business expands, you may consider implementing internationally recognised ISO management standards. ISO9001, the Quality Management Standard, is one of the most popular as it ensures that your growing business remain focused on customer satisfaction. If you decide to implement ISO9001, you could replace your IASME Governance certification with ISO27001 as this will enable you to save time and money by operating the two ISO certifications as part of an integrated management system. If you handle large volumes of customer data, you could also seek certification to ISO27701, the Privacy Information Management Standard. This is an extension to ISO27001, and we suspect it’s going to become an increasingly common requirement in tenders over the next few years.
As well as helping other businesses achieve ISO, we’re certified to ISO9001, ISO27001 and ISO27701 and will happily talk to you about our experiences. Alternatively, you can read our own ISO9001, IASME/Cyber Essentials and ISO27001/ISO27701 case studies.
IASME Governance is a UK standard relevant for the SME market. In contrast, ISO27001 is a standard which is recognised globally. IASME is a self-assessment scheme whereas ISO27001 requires an external audit. The scope of the two certifications also differs, for example, IASME Governance incorporates Cyber Essentials and has a more granular requirement to achieve specific aspects of compliance with the UK Data Protection Act which ISO27001 does not. Finally, there is a difference in price with consultancy and the external audit for ISO27001 starting with a price tag of £10,000 compared to IASME Governance at less than half the price.
Achieving IASME Governance allowed us to be approximately 85% compliant with the ISO standards, smoothing our transition to ISO27001. IASME Governance therefore is a great ‘stepping-stone’ to ISO.
The cost of our support depends upon the complexity of your network. As a guide, our fixed price consultancy service starts at £3,795.
The cost of IASME Governance Self-assessed is £400+VAT. The cost of an IASME Governance Audited (Gold) assessment will depend on the size and complexity of your IT structure.
For more information, please contact us.
We have been IASME Governance certified (including Cyber Essentials) since 2015. We are also ISO27001/ISO27701 certified.
We have a 100% success rate in supporting businesses and charities through IASME Governance certification. Our experience includes accountants, consultancies, software developers and private investigators.
Please get in touch. We’ll be delighted to explain more about the IASME Governance certification and explain how it can help your organisation.
Anonymous
Friendly and informative.
- Jay's Logistics (South West) Ltd
Anonymous
Our ISO9001 certification has enabled us to deliver logistics services to Hinckley Point and to its suppliers as well as operating at a more efficient and safe level. The power station isn’t due for completion until 2025 so this contract has provided stability at a time of great for the logistics industry.
Anonymous
We are in a safer place now than we were 12 months ago. Starting with two factor authentication. The culture of the organisation is in a better place and we were in a better place for lockdown too.
Anonymous
Customer feedback gained as part of our ISO9001 certification has led to the development of popular new services including GDPR Critical Friend.
Anonymous
ISO9001 was an achievement, an even bigger deal was to raise the health and safety culture of the organisation.
Anonymous
GDPR compliance will increase our value to clients.
- Transcription City
- Sam Wood
- Director
It made a massive difference to have ISO explained in layman’s terms. It’s very easy to ask questions and you aren’t left understanding less! You just call or email and it’s in a way that’s simple to understand.
Anonymous
Our clients appreciate that we practice what we preach and can share real-life experience of running an ISO certified business. We’re certified to ISO9001 and were the first UK client of NQA to certify to both ISO27001 and ISO27701.
Anonymous
Helen represents the small business community effectively and with vigour as the Cyber Crime Ambassador for FSB Coventry and Warwickshire, working alongside local and national government to ensure small businesses have a voice.
Anonymous
Very quietly thrilled to bits to get our accreditation under the new standard without any issues. Helps the business with proposals to blue chip clients.
- Transcription City
- Sam Wood
- Director
It was more work than I’d expected. I soon realised I needed help to fully understand the requirements and embed the standards so they would work for my business. I approached British Assessment Bureau for help. They recommended Risk Evolves. Twelve weeks later, we passed our remote audit and achieved certification.
Anonymous
Cyber security is scary! Helen gave me the confidence to know we could… minimise these types of risks. She has given me peace of mind.
- SIS Systems (UK) Ltd
- Adam Middleton
- Managing Director
We do recommend Risk Evolves. Not only do they offer great service and value for money they have also imparted valuable knowledge, understanding and belief across the organisation. The net result is more business.
Anonymous
The internal audit and IASME application has been a positive experience for The Changing Education Group… made possible by the high quality support and guidance offered by the Risk Evolves team.