

IASME Cyber Assurance
Certification:
Demonstrate Your Security, Privacy and Data Protection Measures.
Achieve IASME Cyber Assurance certification in partnership with OCM Communications.
OCM are a licensed certification body for Iasme Cyber Assurance (ICA)

Let OCM help you
Why choose OCM as your IASME Cyber Assurance Partner & Assessor?
What is IASME Cyber Assurance ?
IASME Cyber Assurance is a flexible and affordable cybersecurity standard designed primarily for SMEs, involving a systematic evaluation of an organisation’s cybersecurity controls, policies, and management.
Developed through a government-funded project and in consultation with SME's, it serves as a viable alternative to ISO 27001 by focusing on Information Security Management Systems (ISMS).
This certification provides a pragmatic assessment of security and data privacy practices at an affordable price, enabling smaller organisations to meet high security demands and compete for contracts in sectors like government and military.
About Cyber Essentials
What are the benefits of IASME Cyber Assurance Certification?
Protection from Cyber Attacks
By implementing the thirteen core controls, you significantly reduce your vulnerability to common cyber attacks like phishing, malware, and ransomware. This helps protect your sensitive data, systems, and ultimately your business operations.
​
​
Cost-Effective Security
IASME Cyber Assurance is designed to be accessible and affordable for businesses of all sizes, providing a strong foundation of protection without requiring extensive financial resources.
​
​
​
​
Affordable Price
Affordable and achievable alternative to ISO 27001: IASME Cyber Assurance offers a more cost-effective and less complex alternative to ISO 27001, making it more accessible to SMEs.
​
​
​
​
​
Increased Customer Trust & Reputation
ICA certification demonstrates to your customers, partners, and suppliers that you take cybersecurity seriously. This builds trust and can give you a competitive advantage in the market.
​
​
​
Eligibility for Goverment Contracts
A growing number of UK and international industry sectors now accept IASME Cyber Assurance Level 2 audited certification as an alternative to other international standards. These include the UK Ministry of Justice and the Government of Jersey and Bermuda.
​
Marketing Advantage
Displaying the Cyber Assurance certification on your website and marketing materials can attract new customers and partners who prioritise security. It's a clear demonstration of your commitment to protecting sensitive data.
​
​
Cyber Essentials technical requirements
The IASME Cyber Assurance standard is structured around 13 themes that guide organisations in establishing and maintaining robust information security practices.
These themes cover a wide range of areas, starting with planning and organisation, then moving on to asset management, risk assessment, and legal compliance. The standard also addresses physical and environmental protection, personnel security, policy implementation, access control, and technical security measures. Additionally, it emphasises the importance of backup and recovery, secure business operations, monitoring and review, and incident response and business continuity.
By addressing these 13 themes, organisations can systematically enhance their cybersecurity posture and protect their valuable information assets.
A prerequisite to applying for IASME Cyber Assurance; you must hold a valid Cyber Essentials certificate.
For the Level One certification, organisations are given access to a secure portal to complete their application and provide details against the Question Set.
IASME Cyber Assurance Level Two involves an audit of your processes, procedures and controls required by the standard. The audit is independent and conducted by OCM as IASME Certification Body and Assessor.
What does IASME Cyber Assurance cover?
-
FirewallsCreate a security filter between the internet and your network. Firewalls are essential for protecting your internet connection. They act as a barrier between your internal network and external networks (such as the internet), preventing unauthorised access to your systems and data. Organisations must ensure that all devices that connect to the internet are protected by a properly configured firewall.
-
Secure ConfigurationSecure configuration involves setting up computers and network devices to reduce vulnerabilities. This includes changing default settings, disabling unnecessary features, and ensuring that only essential software is installed and running. Organisations need to ensure that devices and software are configured securely from the outset to minimise security risks.
-
User Access ControlUser access control ensures that only authorised individuals have access to systems and data. This involves implementing user accounts with appropriate privileges and using strong, unique passwords. It also includes restricting administrative privileges to only those who need them for their role.
-
Malware ProtectionMalware protection involves deploying anti-malware solutions to detect and prevent malicious software from infecting systems. This includes using antivirus software and other security tools to scan and protect against malware. Organisations must ensure that their anti-malware software is up-to-date and configured to scan for malware regularly
-
Software Security UpdatesSecurity update management, or patch management, ensures that software and devices are kept up-to-date with the latest security patches and updates. This reduces vulnerabilities that could be exploited by attackers. Organisations need to implement a process to regularly update and patch systems to protect against known threats.
IASME Cyber Assurance Certification in 3 Simple Steps
Choose the right option for your business
IASME Cyber Assurance Level 1
Audit and Certification
from £320-£600
single annual fee
Prove that the IASME Cyber Assurance themes are correctly implemented
-
Expert help to guide you through the ICA process
-
Access to the on-line assessment platform to enable you to begin your certification
-
Free resit if required
-
IASME Cyber Assurance Level 1 Certification
-
Telephone support
​
​
​
​
​
IASME Cyber Assurance Level 1
Supported Package
from £100
per month
for 12 months
Pre-assessment meeting & review, feedback, and unlimited remote telephone support.
Pass first time, guaranteed*.
​
-
Expert help to guide you through the ICA process
-
Template policy documents
-
Pre submission review
-
cyber security remote support across the 13 themes
-
IASME Cyber Assurance Level 1 Certification
-
Year round expert advice
​​
​
​
​
​
​
IASME Cyber Assurance Level 1 and 2
Fully Managed
from £150 per month
for 12 months
OCM manage everything so you can certify quickly and easily with no stress, and guarantee you pass* first time.
-
Cyber security audit with recommendations and guidance
-
Personalised policy documents
-
Pre submission review
-
Completed self assessment
-
IASME Cyber Assurance Level 1 and 2 certification
-
Year round expert advice and remote support across the 13 themes
​​
*Provided you follow our advice and implement all the 13 themes of course
Price includes Cyber Essentials certification fees which start at £320 +VAT
We are happy to create a bespoke solution designed to your exact business needs if our current options do not meet your requirements.
Frequently Asked Questions
-
FirewallsCreate a security filter between the internet and your network. Firewalls are essential for protecting your internet connection. They act as a barrier between your internal network and external networks (such as the internet), preventing unauthorised access to your systems and data. Organisations must ensure that all devices that connect to the internet are protected by a properly configured firewall.
-
Secure ConfigurationSecure configuration involves setting up computers and network devices to reduce vulnerabilities. This includes changing default settings, disabling unnecessary features, and ensuring that only essential software is installed and running. Organisations need to ensure that devices and software are configured securely from the outset to minimise security risks.
-
User Access ControlUser access control ensures that only authorised individuals have access to systems and data. This involves implementing user accounts with appropriate privileges and using strong, unique passwords. It also includes restricting administrative privileges to only those who need them for their role.
-
Malware ProtectionMalware protection involves deploying anti-malware solutions to detect and prevent malicious software from infecting systems. This includes using antivirus software and other security tools to scan and protect against malware. Organisations must ensure that their anti-malware software is up-to-date and configured to scan for malware regularly
-
Software Security UpdatesSecurity update management, or patch management, ensures that software and devices are kept up-to-date with the latest security patches and updates. This reduces vulnerabilities that could be exploited by attackers. Organisations need to implement a process to regularly update and patch systems to protect against known threats.