If you’re looking into Cyber Essentials certification, you’ll probably come across several organisations and terms: the NCSC, IASME, Certification Bodies and Cyber Essentials Assessors.
It’s helpful to understand the difference between them, particularly if you’re deciding who to work with or trying to make sense of the certification process.
Cyber Essentials is a UK Government-backed certification scheme developed by the National Cyber Security Centre (NCSC), which sets the scheme’s technical requirements. IASME is the NCSC’s official Delivery Partner and manages how the scheme is delivered through licensed Certification Bodies.
These are the organisations businesses usually work with when seeking certification. Qualified assessors review applications and determine whether the requirements have been met.
You don’t need to become an expert in the scheme’s structure, but understanding who sets the standard, who manages its delivery and who you’ll deal with directly can help you make a more informed choice.
There are four main parts to the Cyber Essentials certification structure.
|
Organisation or role |
What it does |
|
National Cyber Security Centre (NCSC) |
Owns Cyber Essentials and sets the direction and technical requirements for the scheme. |
|
IASME |
Acts as the NCSC’s official Cyber Essentials Delivery Partner and manages delivery of the scheme. |
|
Certification Bodies |
Cyber security organisations licensed and assured by IASME to assess organisations and award certification. |
|
Cyber Essentials Assessors |
Qualified professionals who review assessments and determine whether an organisation meets the requirements. |
If you’re seeking certification, your Certification Body will usually be your main point of contact. You shouldn’t need to navigate the wider structure yourself, but knowing how it works can help you choose the right provider.
IASME is sometimes described as the Cyber Essentials accreditation body. This reflects the way the scheme was structured before April 2020, when several organisations were involved in its delivery.
Today, Cyber Essentials Delivery Partner is the more accurate description of IASME’s role.
IASME is the NCSC’s sole Cyber Essentials Delivery Partner. It oversees the network of Certification Bodies and helps ensure that certification is delivered consistently across the scheme.
So, if what you want to know is who manages the organisations delivering Cyber Essentials certification, IASME is the relevant body.
For most businesses, that’s the important distinction. You’re unlikely to deal directly with IASME during the day-to-day certification process, but the Certification Body you choose should operate within the IASME-managed scheme.
IASME manages much of the delivery infrastructure behind Cyber Essentials.
It licenses and assures Certification Bodies, sets requirements for assessors and supports quality assurance across the network. This helps create a consistent standard across the scheme, regardless of which provider an organisation chooses.
IASME also provides key parts of the certification infrastructure, including the Cyber Essentials Knowledge Hub and certificate search service.
It works with the NCSC as the scheme develops too. Cyber Essentials is reviewed regularly, allowing its detailed requirements to respond to changes in technology, working practices and cyber security risks.
From a business perspective, this means certification is based on a common framework rather than the individual interpretation of one provider.
A Certification Body, often shortened to CB, is a cyber security organisation licensed and assured by IASME to deliver Cyber Essentials certification.
This is the organisation you’ll usually work with directly.
Its assessors review your Cyber Essentials self-assessment and determine whether you’ve met the requirements. For Cyber Essentials Plus, the Certification Body also carries out independent technical testing to verify that the controls are working in practice.
All Certification Bodies work to the same Cyber Essentials requirements. Where they can differ is in the level of guidance and support they provide around the assessment.
If you already have strong internal IT or cyber security expertise, you may only need a straightforward assessment service. If the requirements are less familiar, or your IT environment is more complex, additional guidance can make the process easier to manage.
Areas such as scope, cloud services, devices, user access and security updates can create questions during an assessment. Having access to someone who can explain what the requirements mean in your environment can be useful.
A Certification Body is the organisation licensed by IASME to deliver Cyber Essentials certification.
A Cyber Essentials Assessor is the qualified professional who carries out the assessment on its behalf.
Assessors need to meet defined skills and experience requirements and complete the relevant training and assessment before they can assess organisations against the standard.
The assessor reviews your questionnaire and may ask for clarification or further information. For Cyber Essentials Plus, the assessor also carries out the required technical testing.
The Certification Body is responsible for delivering the service and issuing certification when the requirements have been met.
When choosing a Certification Body, it can therefore be worth considering the expertise and accessibility of the people behind the service, not just the certification itself.
If questions come up during the process, being able to speak to someone who understands both the standard and your situation can make a noticeable difference.
Cyber Essentials and Cyber Essentials Plus are part of the same NCSC and IASME structure. Both are based on the same five technical control areas:
The difference between them is the level of assessment.
Cyber Essentials is based on a verified self-assessment, with responses reviewed by an independent assessor. Cyber Essentials Plus adds independent technical testing, giving you added assurance that the controls have been implemented effectively.
There is no separate accreditation route for Cyber Essentials Plus. Instead, you need to choose a Certification Body that is licensed and able to deliver the appropriate level of assessment.
It’s also worth thinking about whether you’re ready for the technical assessment. A good Certification Body should be able to explain what’s involved and where preparation may be needed before testing begins.
Our guide to The Difference Between Cyber Essentials and Cyber Essentials Plus explains how the two certification levels compare.
No. IASME isn’t a government department. It’s an independent organisation that works as the NCSC’s Cyber Essentials Delivery Partner.
The NCSC is part of GCHQ, and Cyber Essentials remains a UK Government-backed certification scheme.
In practice, this means the NCSC owns and oversees the scheme, while IASME manages how it is delivered through the Certification Body network.
For businesses, the more useful point is that there is a defined structure behind the certification and a recognised framework for the organisations delivering it.
Cyber Essentials hasn’t always operated through its current structure.
Before April 2020, the scheme was delivered by five Accreditation Bodies, including IASME. From April 2020, IASME became the NCSC’s sole partner responsible for managing and delivering the scheme.
This created a single delivery model and placed responsibility for the Certification Body network, assessor requirements and scheme infrastructure with one organisation.
It also explains why IASME may still be described as an accreditation body. That was part of the scheme’s previous structure, but IASME’s current role is as the NCSC’s Cyber Essentials Delivery Partner.
Yes. Cyber Essentials continues to evolve.
The five core technical controls remain central to the scheme, but the detailed requirements and assessment questions are reviewed regularly. Changes have reflected developments in areas such as cloud services, remote working, multi-factor authentication and security update management.
The current Cyber Essentials Requirements for IT Infrastructure document is version 3.3, published in April 2026. The updated requirements apply to assessment accounts created after 26 April 2026. Organisations with an active assessment account created before that date have six months to complete certification under the previous requirements.
If you’re preparing for certification now, make sure your preparation reflects the current requirements and question set, including the 2026 Danzell update.
The Cyber Essentials standard should be consistent whichever licensed Certification Body you use. What can differ considerably is the support around it.
Before choosing a provider, it’s worth considering:
There’s no benefit in paying for support you don’t need. Equally, choosing the most basic route can become a false economy if you then spend significant internal time trying to interpret the requirements.
For some businesses, Cyber Essentials is primarily a requirement from a customer, tender or supply chain. For others, it’s an opportunity to review their foundations and identify gaps that might otherwise have gone unnoticed.
A good starting point is to consider what expertise you already have internally and where external guidance would add value.
Cyber Tec Security is an IASME Certification Body. We assess organisations against the Cyber Essentials scheme and issue certification when the requirements are met, and we know the process can feel more complicated than it needs to be, especially the first time round. Every organisation's starting point is different. Some already have a strong grip on the requirements and just want a straightforward, efficient route through assessment. Others are working with a more complex IT environment, a tighter deadline, or simply want someone on hand to explain how the requirements apply to their setup before they commit an answer.
That's where we come in. Our team can talk you through what's actually involved, help you work out where you already meet the requirements and where the gaps are, and recommend the right route - standard or guided - for your situation.
If you're working towards Cyber Essentials or Cyber Essentials Plus, speak to Cyber Tec Security today. A short conversation now can save you time, uncertainty and last-minute changes later - get in touch to find out how we can support your certification.