IASME Cyber Baseline
The IASME Cyber Baseline is an international certification scheme designed to address essential cyber security measures for organisations outside the UK. This standard provides a standardised and respected certification for global supply chains, demonstrating that these organisations have implemented crucial cyber hygiene practices.
The IASME Cyber Baseline aligns with several international cyber standards and best practices. Previously, there was no method to demonstrate compliance with these standards due to the lack of associated assessments and certifications.
For organisations outside the UK, the IASME Cyber Baseline can serve as a prerequisite for the more comprehensive IASME Cyber Assurance certification, which is risk-based and policy-driven. For UK-based organisations, Cyber Essentials is the recommended minimum certification.
What is IASME Cyber Baseline?
IASME Cyber Baseline consists of a verified self-assessment reviewed by an independent Assessor. After registering for certification, you are given access to the secure assessment platform where you will answer the verified self-assessment questions. A senior member of the board or equivalent from your organisation must e-sign a document to verify that all the answers are true and then our Assessment team will mark your answers.
We offer Emailed guided support packages to ensure a smooth first Time pass.
Cyber Baseline helps an organisation to
Align with data protection regulations such as PIPA
Identify, assess and mitigate cybersecurity risks more effectively
Demonstrate adherence to key Global cybersecurity standards, (such as Cobit, CIS controls V8 reassuring clients and stakeholders)
Tailored for small and medium-sized businesses with scalable requirements
Covers broader aspects of cybersecurity, including physical and operational security
Why Certify With us?
Human Support
Our friendly and helpful team of experts will be on hand with insights and useful advice to help boost your chances of a first-time pass.
Best Price In UK
Cyber Tec offers a best-price guarantee on like-for-like Cyber Essentials packages – so you’re sure to find one that works for your budget.
Assured Pass
Our guided certification packages are designed to assure your business obtains a first-time pass, giving you added peace of mind.
Speedy Turnaround
We understand that getting certified is a matter of urgency. That’s why we strive to help businesses achieve certification within 24 hours.
Remote Auditing
We complete all auditing remotely, so you can get on with business as usual – without the extra hassle of arranging on-site visits.
Human Support
Friendly faces and 1-2-1 support as you complete your assessment. For a techie company, we’re not big fans of robots!
Best Price In UK
We offer a best price guarantee on like-for-like Cyber Essentials packages so you can always get a great deal on certification.
Assured Pass
Our guided certification packages are designed to assure you a first time pass so you can have full peace of mind.
Speedy Turnaround
We know it's often a matter of urgency to get certified so we strive to help businesses achieve certification within 24 hrs.
Remote Auditing
No extra hassle organising on-site visits. We complete all auditing remotely so you can get on with business as usual.
Business Benefits
Showcase your organisation's alignment with worldwide cyber hygiene and cybersecurity frameworks, such as Cobit and CIS Controls v8.
Safeguard your organisation, data, and clients from large scale automated internet attacks.
Initiate the crucial initial stride towards achieving IASME Cyber Assurance certification, providing your organisation with access to procurement frameworks and the ability to compete for contracts.
The Eight Themes Of IASME Cyber Baseline
The IASME Cyber Baseline scheme allows every size of organisation in every sector to start their cyber security journey with simple cyber security measures set out across eight themes.
Organisation
Track all third-party engagements, including IT products, services, and personnel. A security gap in any third-party system can compromise your own security, no matter how robust it is.
Identifying and protecting assets
Understand your key information assets to know what to protect. Maintain an asset register for all information assets, including hardware, software, and cloud services. This helps clarify your attack surface and what’s at risk.
Secure Architecture
Systems are not secure by default, so it’s crucial to understand their configuration and integration. Apply technical controls to your devices to reduce the risk of cyber attacks.
People
Your greatest allies in protecting your organization’s information are your colleagues and suppliers. They play a crucial role in system protection but also pose a risk due to their privileged access.
Technical Intrusion
Device configurations, including the operating system, firewalls, and malware protection, create layers of defence against unauthorized access.
Backup and Restore
Regular backups and the ability to restore them are crucial for protecting your business from data loss due to accidental or malicious actions, hardware failure, or ransomware.
Managing Access
Grant users only the resources and data necessary for their roles, both digitally and physical.
Resilience: Business Continuity, Incident Management, and Disaster Recovery
Prepare to maintain operations and recover from deliberate attacks, accidental damage, and natural disasters, as no security measures are fool proof.
Why Work With Us
Being the top third Certification Body in the UK, we pride ourselves on our Consultative, hands-on approach—there are no pre–populated dashboards or AI when working with us!
Don’t take our word for it, though – our clients will tell you:
“My Assessor fully explained everything he was doing. Provided additional information outside of the assessment criteria which will give additional security to our environment.“

Sarah
information Technology and Services
“Always a pleasure to go through CE, or CE+, with My Assessors and dealing with the Cyber Tec team in general.”

Andy
Information Technology and Services
“As always prompt and efficient service. Thank you once again guys for your excellent and informative support. We’ll be working with you again for the coming year.”

Martin
Hospital & Healthcare
“As always, My Assessor was professional and practical and good humoured – an ideal combination …”

Tim
Management Consulting
“Attention to detail, clear, constructive feedback, and plenty of patience. My Assessor was exceptional.”

Chris
Management Consulting
“The Assessment Team have been responsive and helpful with all their responses to questions we have”

Andrew
Pharmaceuticals

Louis
Real Estate
“Clear instructions and advice at all times.”

Karen
Legal Services
“Communication was timely, concise and clear; very grateful for the intimate support provided.”

Kevin
Research
“Easy, seamless and clear process”

Rich
Education Management
“Efficient and to the point”

Mikhail
Construction
“Everything was explained clearly, and it made the process very simple and straightforward.”

Feargal
Telecommunications
“Excellent service as always. The Assessors are fast, clear and efficient. Couldn’t fault anything”

Andy
Information Technology and Services
“Excellent team, helpful and responsive to ensure we passed first time with ease”

Dan
Entertainment
“Extremely helpful, and written clearly and in a friendly supportive tone”

Stephen
Sports
“Fast response – very patient and helpful – thanks”

Rebecca
Research
“Friendly, helpful staff – supporting all the way”

Margaret
Education Management
“Good feedback on initial submission”

Graham
Research
“Great communication and support throughout the whole process!”

Garratt
Information Technology and Services
“Great feedback during the process of submitting”

Aaron
Education Management
“Great levels of support and provided some excellent guidance to help us through certain areas where we were unclear as to what was required. Very responsive from a timescales perspective too and overall we felt well supported throughout the process.”

Steve
Financial Services
“Great overall experience. The assisted application process is a complete no-brainer as a lot of the questions are quite poorly structured/worded leading a variety of (mis)interpretations. Being guided through this was critical. The assisted process was incredibly fast, clear and very helpful. Bravo all round.”

Kristjan
Real Estate
“Great response and very helpful”

Helen
Management Consulting
“Great service”

Richard
Accounting
“Great support from beginning to end. So much easier having last years completed questionnaire as a template.”

Scott
Leisure, Travel & Tourism
“Help always comes promptly and right to the point”

Balazs
Information Technology and Services
“Helpful and attentive throughout”

Ahmed
Hospitality
“I got plenty of assistance all the way through. “

Victoria
Accounting
“It was a simple process – all good”

Andy
Information Technology and Services
“It was quick, efficient and helpful, and with useful insights.”

Jurate
Defence & Space
“It’s been an absolute pleasure to work with My Assessor – he reviewed our responses speedily and gave clear guidance on remediation. A huge thank you from us!”

Katie
Professional Training & Coaching
“I’ve rated highly due to the level of support that has been provided, not only from My Assessor and My Auditor, but also the sales and admin team , who have all assisted each year we work with you, to provide quick and informative answers to our technical and non-technical questions. Thank you all, looking forward to working with you for CE+ and beyond.”

Chris
Fundraising
“My Assessor and the auditor are always available and provide us with excellent advice”

Gareth
Information Technology and Services
“My Assessor was awesome. Very understanding and extremely helpful. Made the whole process smooth “

Abbas
Legal Services
“My Assessor was polite, courteous and very experienced.”

Hifzulrehman
Research
“My Assessor was very useful and explained in detail what needed to be done to get us up to standard.”

Ryan
Real Estate
“Provided the right level of support to enable me to complete the assessment quickly and accurately.”

Tom
Legal Services
“Quick and efficient.”

Graham
Machinery
“Quick response time, clear guidance. Whole process made very easy”

Andrew
Non-Profit
“Quickly answered any questions and available to speak when needed.”

Marcus
Industrial Automation
“Really helpful & clear guidance.”

Dave
Information Technology and Services
“Responses to our queries very quickly, review quick and good advice. Thank you”

Manuel
Insurance
“Smooth as!”

Colin
Information Technology and Services
“Strong communications and reminders before, during and following the process. My Auditor in particular performed way above and beyond our expectations during the CE+ stage of the assessment. Thank you for your service.”

David
Information Technology and Services
“Superb as always. Clear and to the point. 100% would come back”

Grant
Information Technology and Services
“The Assessors communications were clear, concise and to the point. They helped me use my time effectively and efficiently.”

Airan
Information Technology and Services
“The Assessor was very helpful”

Martina
Hospital & Healthcare
“The Sales Team and My Assessor were both professional and extremely patient.”

Marc
Management Consulting
“The support I had was great. As a non technical person, everything was communicated really clearly, which was much appreciated.”

Lis
Non-Profit
“Their notes clarified the details and requirements of the assessment. They made it make sense..”

Gregor
Information Technology and Services
“Thorough and helpful”

Shirley
Business Supplies & Equipment
“Very helpful and insightful when providing feedback to help us pass the assessment.”

Graham
Recreational Facilities and Services
“Very helpful and responsive in a timely fashion.”

Asaf
Information Technology and Services
“Very Helpful!”

Brandon
Information Technology and Services
“Very helpful, fast responses. Thank you.”

Victor
Research
“Very helpful, Quick to respond, Made the process easy”

Curtis
Information Technology and Services
“Very prompt review and submission process. Big thanks to the auditors as they ensured to always get back to me within 2 business days with friendly and informative replies… we will continue to use CyberTec in the future.”

Jordan
Non-Profit
“We as a company have downsized as I’m on the flight path to retirement. I am the only employee and renewing the certificate filled me with dread. But both My Assessors were very patient and professional. It actually turned out to be an almost enjoyable experience. Well done guys, I very much appreciate your guidance and help.”

Stephen
Staffing & Recruitment
“You do what you say and in a timely manner!”

Tom
Retail
IASME Cyber Baseline Certification Packages
Reseller rates also available. Ask about reseller pricing.
IASME Cyber Baseline Level 1:
Self-Assessment
- Align to IASME's standard including key security elements like incident response, staff training, planning and operations.
- Meet GDPR Requirements
- One re-attempt if you fail first time
- No support
From
£315
$409
IASME Cyber Baseline Level 1:
Guided Assessment
- All benefits of the Self-Assessment package and...
- Assured pass *
- Dedicated Account Manager
From
£469
$609
IASME Cyber Baseline Level 1:
Managed
- All benefits of guided assessment, and...
- 1-2-1 video calls and screensharing with assessor who will take you through the process step by step
From
£669
$869
* Assured pass assumes you follow our consultant’s advice and ensure that all the required controls are put in place.
Keep in constant Compliance with our Monthly Vulnerability Assessments at only £100/$130
Our Complementary Security Services
Cyber Insurance
A specialist cyber insurance policy can give your business maximum protection. Choose from a range of flexible options from market-leading providers.
Penetration Testing
Our monthly or one-off penetration tests simulate an attack on your systems to see how far hackers could go, followed by a detailed report and recommended remedies.
Vulnerability Assessment
Uncover potential gaps and weaknesses in your cybersecurity infrastructure before they can be exploited by online criminals with a vulnerability assessment. Use to stay compliant with cyber certificates such as CE and ICA
Managed Threat Detection
Our threat detection software protects your business against cyberattacks 24/7, with real-time monitoring, SOC analysis and CE Plus alignment.
Incident Response
By using the services of our CREST accredited incident response delivery partner, Pen Test Partners LLP, the impact of any breach or incident can be minimised and business continuity maintained by the provision of services in line with your company’s specific needs, regardless of your cyber maturity level.
Cyber Insurance
A specialist cyber insurance policy can give your business maximum protection. Choose from a range of flexible options from market-leading providers.
Penetration Testing and Vulnerability Assessment
Our monthly or one-off penetration tests simulate an attack on your systems to see how far hackers could go, followed by a detailed report and recommended remedies. Uncover potential gaps and weaknesses in your cybersecurity infrastructure before they can be exploited by online criminals with a vulnerability assessment. Use to stay compliant with cyber certificates such as CE and ICA
ISO 27001
Safeguard your business and strengthen your online defences with ISO 27001 certification. Cyber Tec’s experts will provide helpful guidance at every step
Managed Threat Detection
Our threat detection software protects your business against cyberattacks 24/7, with real-time monitoring, SOC analysis and CE Plus alignment.
Incident Response
By Leveraging our relationship with our partner PTP - As a CREST-accredited incident response team, we will to help you minimise the impact of any breach or incident and maintain business continuity by providing services in line with your company’s specific needs regardless of your cyber maturity level.
Lets get Secure together
- Jersey: +44 1534 715260
- UK: +44 117 457 3331
- Bermuda: +1 441 279 7101
- [email protected]
-
Kensington Chambers, 46/50
Kensington Place, St Helier, Jersey JE1 1ET
Frequently Asked Questions
Here’s a combined list of frequently asked questions that cover both the general and technical aspects of the IASME Cyber Baseline Certification. These FAQs provide a comprehensive understanding of the certification, suitable for organizations seeking to bolster their cybersecurity practices on an international scale.
What is International Cyber Baseline Certification?
International Cyber Baseline Certification is designed to standardize cybersecurity practices across organizations operating outside the UK, ensuring they adhere to fundamental cyber hygiene in line with international standards.
Who should consider obtaining the International Cyber Baseline Certification?
This certification is ideal for any organization operating internationally that needs to demonstrate a commitment to cybersecurity to partners, regulators, and customers, especially those involved in global supply chains or industries where security compliance is critical.
What are the main themes covered by the International Cyber Baseline Certification?
The certification covers eight crucial themes: Device Security, Data Security, Staff Awareness, Physical Security, Network Security, Malware and Virus Protection, Backup and Recovery, and Incident Management.
How does the International Cyber Baseline Certification benefit an organization?
It helps standardize cybersecurity practices across international operations, enhances global compliance and interoperability, and builds trust with international stakeholders by demonstrating a proactive approach to cyber hygiene.
Is the International Cyber Baseline Certification recognized globally?
Yes, it is designed to be internationally recognized, providing a standardized approach to cybersecurity that facilitates business and regulatory compliance across borders.
How does the certification ensure secure data transmission and storage?
The certification requires the use of encryption for data at rest and in transit, adhering to best practices for secure data storage and communications.
What requirements are there for network security under this certification?
Organizations must implement robust network security measures, including firewalls, intrusion detection systems, and secure VPNs for remote access, along with regular security assessments to identify and mitigate vulnerabilities.
How does the certification address malware and virus protection?
The certification mandates the deployment of comprehensive anti-malware and antivirus solutions that are regularly updated, along with training for employees to recognize and handle potential malware threats.
What are the specifications for asset management under the Cyber Baseline certification?
An up-to-date asset register must be maintained, listing all physical and information assets, their locations, ownership details, and security measures in place to protect these assets.
How does the certification approach incident management?
Organizations must establish and maintain effective incident management procedures, including the identification, reporting, management, and resolution of security incidents, with an emphasis on minimizing impact and learning from each incident to prevent future occurrences.
What does the certification process involve?
The process typically involves a self-assessment against the Cyber Baseline standards, followed by an external audit to verify compliance. This ensures that all security measures are properly implemented and effective.
How long does it take to achieve the International Cyber Baseline Certification?
The timeframe can vary but generally involves several weeks to a few months, depending on the existing level of cybersecurity maturity within the organization.
How often must the certification be renewed?
Similar to other cybersecurity certifications, it is recommended to review and renew the International Cyber Baseline Certification annually to ensure ongoing compliance and to adapt to any new security threats.
Where can organizations find a provider to help with obtaining the International Cyber Baseline Certification?
Organizations should look for accredited certification bodies that offer the International Cyber Baseline Certification. These providers are often listed on official cybersecurity and standards websites, or they can be recommended through industry associations.