shouldiuse.io

Categories

VERDICT

Should I use IASME?

UK certification body for Cyber Essentials and IASME Cyber Assurance - iasme.co.uk

Depends. Buy if you're a UK SME, charity, or school that needs Cyber Essentials or IASME Cyber Assurance to win contracts. Skip if you want security software — IASME certifies you, it doesn't protect you.

Confidence

Medium. Based on 40+ public sources; IASME is a certification body, not a software product, so fit is judged as a compliance purchase.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support-quality evidence in sources
  • Security posture

Pricing

By employee band

Cyber Essentials

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierNo
Cyber Essentials PlusQuoted; cost depends on scope
IASME Cyber AssuranceBy level and employee band

Best for

  • UK SMEs chasing government contracts
  • Charities and schools
  • Supply chains requiring CE badges
  • Firms wanting cheaper ISO 27001 alternative

Not for

  • Buyers wanting hands-on security tooling
  • Enterprises needing ISO 27001-level depth
  • Non-UK firms without UK contract pressure
  • Teams expecting a product, not an audit

Gotchas - check before you buy

medium

Price depends on employee band — growth raises your renewal cost

medium

Consultant fees are common beyond the certification fee itself

medium

Annual renewal required to keep the badge — recurring cost, one-off effort won't hold

low

Basic Cyber Essentials price increased from 1 April 2024

Pros and cons

Pros

  • Official NCSC Cyber Essentials partner
  • Simpler, cheaper alternative to ISO 27001 for SMEs
  • Wide standard range from Cyber Essentials to Defence certification
  • Public case studies including charity Sightsavers

Cons

  • Critics call Cyber Essentials box-ticking, not real security
  • Fees scale with headcount; prices rose April 2024
  • Consultants often needed to pass, adding cost
  • CE Plus criticised by practitioners for inconsistent value

Sources & method

Analyzed 10/05/2026 - 12 sources - No IASME-specific vulnerabilities found in the sources reviewed; a 2017 breach affected the wider UK.gov Cyber Essentials scheme.

official x7review x2security x1news x2
  • 2017 Cyber Essentials scheme breach, The Register reported a breach at's Cyber Essentials scheme exposing users to phishing attacks. Scheme-level, not proven IASME-specific.

Key stats

  • Value for money: 3/5

    Rating

  • By employee band

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 3/5. Cert fee plus common consultant costs
  • Ease of use: 4/5. Self-assessment with knowledge hub guidance
  • Feature depth: 4/5. CE, CE+, Cyber Assurance, Baseline, IoT, Defence
  • Support quality. No support-quality evidence in sources
  • Security posture: 3/5. No IASME findings; 2017 scheme breach reported
  • NCSC Cyber Essentials partner Scheme role Listed on ncsc.gov.uk
  • By employee band Pricing basis Cost depends on organisation size
  • April 2024 Last price rise Basic Cyber Essentials price increased
  • None Free tier Paid certification scheme

Pricing

Cyber Essentials

By employee band

  • Self-assessment questionnaire
  • Annual renewal

Cyber Essentials Plus

Quoted; cost depends on scope

  • External audit
  • Hands-on technical testing

IASME Cyber Assurance

By level and employee band

  • Level 1 and 2
  • Governance standard beyond CE

Security

No IASME-specific vulnerabilities found in the sources reviewed; a 2017 breach affected the wider UK.gov Cyber Essentials scheme.

  • 2017 Cyber Essentials scheme breachThe Register reported a breach at's Cyber Essentials scheme exposing users to phishing attacks. Scheme-level, not proven IASME-specific.⁹

What users say

Practitioner sentiment on Reddit is critical of the Cyber Essentials scheme's value, though posts discuss the scheme broadly rather than IASME specifically.

Companies that use it

  • Sightsavers12
  • Expert Investigations
  • Mymesh
  • Acorn Fostering (Guardian Saints)
Full analysis

Based on 40+ public sources; IASME is a certification body, not a software product, so fit is judged as a compliance purchase.

Certification body, not software: right if contracts demand Cyber Essentials; wrong if you want actual protection.

Methodology

Based on 40+ public sources; IASME is a certification body, not a software product, so fit is judged as a compliance purchase.

Sources

  1. IASME | NCSCncsc.gov.uk
    official
  2. official
  3. official
  4. official
  5. news
  6. review
  7. review
  8. official
  9. security
  10. IASME | Wikipediaen.wikipedia.org
    official
  11. news
  12. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.