IASME Consortium
IASME Consortium is a UK-based cyber security certification company and the sole delivery partner for the UK Government-backed Cyber Essentials and Cyber Advisor schemes, administering nine certification programmes across SMEs, defence, maritime, aviation, and IoT manufacturers via a partner network of 300+ Certification Bodies.
- Company typePrivate
- Founded2012
- HeadquartersMalvern, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What IASME Consortium does
IASME Consortium Ltd is a UK-based cyber security certification company, founded in 2012 and headquartered in Malvern, operating as the sole delivery partner for the UK Government's NCSC-backed Cyber Essentials and Cyber Advisor schemes. The company administers a portfolio of nine certification programmes spanning general organizational cyber security (Cyber Essentials and Cyber Essentials Plus), NCSC Industry Assurance schemes (Cyber Incident Exercising and Cyber Incident Response Standard Level), sector-specific frameworks (Defence Cyber Certification for UK MOD suppliers, Maritime Cyber Baseline for commercial vessels, Civil Aviation Authority ASSURE for aviation entities, IoT Cyber Baseline and Assurance for connected devices under the PSTI Act 2022), and IASME Cyber Assurance for SME information security. Certifications are delivered through a self-serve online assessment portal plus a partner channel of over 900 trained cyber security experts and more than 300 licensed Certification Bodies and Assured Service Providers across the UK and Crown Dependencies.
The technology backbone consists of an online assessment platform with scheme-specific portals, free readiness tools, a knowledge hub, and a public certificate search directory, supported by standard web infrastructure (WooCommerce, Cloudflare, PayPal). Certifications follow a two-tier structure (verified self-assessment and audited) with Cyber Essentials as a prerequisite gating scheme, producing a stepped renewal model anchored to annual cycles. The revenue model is primarily subscription-recurring across tiered pricing bands of £320 to £600 plus VAT for Cyber Essentials, with one-time-perpetual licensing for Maritime and Defence schemes, plus enhanced cyber liability insurance sold as an upsell underwritten by AIG.
The go-to-market combines direct-to-consumer self-serve purchases via the website with a channel-partner motion via Cyber Advisors and Certification Bodies, serving UK SMEs, defence suppliers, maritime operators, IoT manufacturers, aviation entities, and government contractors. The company is privately held by independent ownership under CEO Dr Emma Philpott MBE, with the social enterprise arm IASME Community delivering cyber security training to unemployed adults. Revenue is not publicly disclosed and the firm operates with a lean internal headcount of 1-10 employees, scaling delivery through its partner network to issue approximately 700 certificates per week.
IASME Consortium firmographics
Firmographics- Name
- IASME Consortium
- Legal name
- IASME Consortium Ltd
- Website
- https://iasme.co.uk
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- IASME Consortium is a UK-based cyber security certification company and the sole delivery partner for the UK Government-backed Cyber Essentials and Cyber Advisor schemes, administering nine certification programmes across SMEs, defence, maritime, aviation, and IoT manufacturers via a partner network of 300+ Certification Bodies.
- Ownership category
- akta.pro rank
IASME Consortium industry classification
Industry- Product category
- Cyber Security Certification
- NAICS
- Computer Training (61142)
- SIC
- Services-Services, Nec (8900)
- akta.pro primary industry
- Cybersecurity Awareness & Digital Safety Training for Security Personnel (BPAKAOAO)
- akta.pro secondary industries
- Information Technology (IT) & Cybersecurity Certifications (EDAAANAA), Legal, Governance, Privacy & Audit Certifications (EDAAANAN)
Keywords
Where IASME Consortium is headquartered
LocationHeadquarters
- HQ city
- Malvern
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
IASME Consortium business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Cyber Essentials Certification: Annual certification fees based on organization size. Pricing ranges from £320 + VAT for micro organizations (0-9 employees) to £600 + VAT for large organizations (250+ employees). Certification is valid for 12 months and must be renewed annually.
- IASME Cyber Assurance Certification: Two-level certification with Level One verified assessment and Level Two audited certification. Requires Cyber Essentials as prerequisite. Pricing mirrors Cyber Essentials tiered structure.
- IoT Cyber Certification: Certification for internet-connected devices against security controls, available at Baseline and Assurance levels with Level 1 (verified assessment) and Level 2 (audit) options. Price marked as TBC.
- Maritime Cyber Baseline Certification: Certification for commercial vessels available at two levels: Level One verified self-assessment (£750) and Level Two audited (£1,950). Level Two certification lasts three years with annual verified self-assessments required to maintain.
- Defence Cyber Certification: Four-tier certification framework (Level Zero through Level Three) for UK defence suppliers, with increasing control requirements (3, 101, 139, and 144 controls respectively). Requires Cyber Essentials certification as prerequisite.
- Cyber Liability Insurance: Included free with Cyber Essentials certification for UK-domiciled organizations with turnover under £20m. Provides £25,000 limit of indemnity. Higher coverage limits (£100,000 or £250,000) available for purchase through Sutcliffe & Co Insurance Brokers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Cyber Essentials Micro (0-9 employees): £320 + VAT |
| Subscription | Annual | Cyber Essentials Small (10-49 employees): £440 + VAT |
| Subscription | Annual | Cyber Essentials Medium (50-249 employees): £500 + VAT |
| Subscription | Annual | Cyber Essentials Large (250+ employees): £600 + VAT |
| One time/ perpetual license | Pay-as-you-go | Maritime Cyber Baseline Level One: £750 (~$980/€880) |
| One time/ perpetual license | Pay-as-you-go | Maritime Cyber Baseline Level Two: £1,950 (~$2,630/€2,380) |
| Subscription | Annual | Cyber Liability Insurance - Standard (£25,000 limit): Free with Cyber Essentials |
| Subscription | Annual | Cyber Liability Insurance - Enhanced (£100,000 limit): £305.76-£1,347.36/year |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels6 records
IASME Consortium product offering
Product offeringCore offering
IASME Consortium delivers government-backed cyber security certification schemes, most prominently the NCSC Cyber Essentials programme, alongside NCSC Cyber Advisor, Cyber Incident Exercising, Cyber Incident Response Standard Level, Defence Cyber Certification, IASME Cyber Assurance, IoT Cyber Baseline and Assurance, Maritime Cyber Baseline, and CAA ASSURE aviation audits. Certifications are administered through a secure online assessment platform with both self-led and supported routes, delivered via a UK network of over 300 licensed Certification Bodies, Assured Service Providers, and NCSC-assured Cyber Advisors.
Product overview
IASME Consortium operates as a cyber security certification company administering multiple certification schemes in partnership with UK government bodies (NCSC, Ministry of Defence, Civil Aviation Authority) and independently. The core offering consists of nine distinct certification schemes: Cyber Essentials (with Plus tier) as the flagship UK government-backed scheme; Cyber Advisor for practical SME support; Cyber Incident Exercising and Cyber Incident Response Standard Level as NCSC Industry Assurance schemes; Defence Cyber Certification for defence sector suppliers; IASME Cyber Assurance (formerly Governance) for information security; IoT Cyber Baseline and IoT Cyber Assurance for connected devices; and Maritime Cyber Baseline for vessels; plus the Civil Aviation Authority ASSURE scheme for aviation. Supporting offerings include free readiness tools, knowledge hubs, assessment question sets, cyber liability insurance (bundled with Cyber Essentials), and community training programmes for employment barriers. The company delivers certifications through a network of over 900 trained Certification Bodies and Assured Service Providers across the UK and Crown Dependencies.
Differentiator
Problem solved
Functional benefit
Brands
- IASME Community: Community interest and social enterprise arm of IASME focusing on cyber security training and community outreach
Products and services
- Cyber Essentials UK government-approved (NCSC-backed) cyber security certification scheme centred on five technical controls, delivered as a self-assessment questionnaire for organisations of any size, with annual pricing from £320 + VAT (micro, 0-9 employees) to £600 + VAT (large, 250+ employees) and bundled cyber liability insurance for eligible UK organisations.
- NCSC Cyber Advisor NCSC-assured service providing small and medium organisations with practical, hands-on cyber security advice to implement Cyber Essentials technical controls, delivered by Advisors working for NCSC-approved Assured Service Providers with free 30-minute consultations and a strict code of conduct for proportionate advice.
- NCSC Cyber Incident Exercising NCSC Industry Assurance scheme helping organisations test their cyber incident response plans before an attack, delivered through NCSC-assured service providers offering tabletop or live-play exercises.
- NCSC Cyber Incident Response Standard Level NCSC Industry Assurance scheme providing incident response services for organisations that have been victims of a cyber attack, where providers assess incident extent, manage impact, fix system compromises, and deliver remediation reports.
- Defence Cyber Certification (DCC) Comprehensive, organisation-wide cyber security certification framework for UK defence suppliers, developed jointly with the UK Ministry of Defence and delivered through IASME's network of Assured Certification Bodies to enhance cyber resilience across the defence supply chain.
- IASME Cyber Assurance Information security standard (formerly IASME Governance) designed for SMEs providing assurance on cyber security, privacy, and data protection measures, available at Level One (verified assessment) and Level Two (audited), and requiring Cyber Essentials as prerequisite.
- IASME IoT Cyber Baseline Certification for internet-connected devices against essential security controls aligned to the UK Product Security and Telecommunications Infrastructure Act 2022 and the top three provisions of ETSI EN 303 645, available at Level One (verified assessment) and Level Two (audit).
- IASME IoT Cyber Assurance Higher-grade certification for internet-connected devices aligned with all 13 provisions of the ETSI EN 303 645 standard and UK PSTI legislation, required for Secured by Design's Secure Connected Device accreditation and available at Level One (verified assessment) and Level Two (audit).
- Maritime Cyber Baseline Certification scheme for commercial vessels of all sizes providing affordable cyber security controls aligned with IMO Maritime Cyber Risk Management guidelines; Level One verified self-assessment priced at £750 and valid for 12 months, Level Two audited certification at £1,950 and valid for three years with annual verified self-assessments required to maintain status.
- Civil Aviation Authority ASSURE CAA's accredited cyber security audit scheme for aviation entities (UK airlines, airport operating businesses, air navigation service providers) operating under the Cyber Security Oversight Process and audited against the Cyber Assessment Framework for Aviation (CAF for Aviation) by accredited ASSURE Cyber Suppliers.
- Cyber Liability Insurance Cyber liability insurance included free with Cyber Essentials certification for UK-domiciled organisations with turnover under £20m, underwritten by AIG and administered by Sutcliffe & Co Insurance Brokers, providing £25,000 limit of indemnity covering liability, event management, extortion threats, regulatory investigations, and business/network interruption, with enhanced tiers (£100,000 or £250,000 limits) available for purchase.
Quantifiable outcome
- Approximately 700 certificates issued per week across all IASME certification schemes.
- +1 more outcomes
Companies that use IASME Consortium
Customer profileNamed customers5 records
Segments6 records
Ideal customer profiles5 records
IASME Consortium technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
IASME Consortium partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered flagship, core and minor.
- National Cyber Security Centre (NCSC)flagshipIASME is the sole delivery partner for NCSC's Cyber Essentials scheme and Cyber Advisor scheme. Additionally, IASME is one of two Delivery Partners for NCSC's Cyber Incident Exercising and Cyber Incident Response Standard Level schemes. The partnership involves assessment and onboarding processes to ensure providers meet NCSC's rigorous security and quality standards.
- Ministry of Defence (MOD)flagshipThe MOD partnered with IASME to develop the Defence Cyber Certification (DCC) scheme, an organization-wide cyber security certification framework for UK defence suppliers. IASME manages delivery of the DCC through its network of Assured Certification Bodies as part of the broader initiative to enhance cyber resilience in the UK's defence sector supply chain.
- Royal Institution of Naval ArchitectscoreThe Royal Institution of Naval Architects supports IASME's Maritime Cyber Baseline scheme and encourages all those involved in the maritime sector to use the certification as a practical way to reduce the disruptive impact of cyber attacks. The partnership provides institutional credibility for the maritime certification scheme.
- Civil Aviation Authority (CAA)flagshipThrough the CAA's ASSURE scheme, IASME provides the aviation industry with an audit mechanism to review and manage cyber security risks. IASME manages the accreditation of ASSURE Cyber Suppliers who conduct third-party audits of aviation entities against the Cyber Assessment Framework for Aviation.
- Secured By Design (Police Crime Prevention Initiative)coreIASME is working in partnership with Secured By Design, which operates an accreditation scheme on behalf of the UK Police Service. IASME IoT Cyber Assurance Level Two is one of the approved ways for manufacturers to achieve Secure Connected Device accreditation for innovative connected security products such as alarm systems and video products.
- CIISec (Champlain Information Security)minorIASME Community's cyber security training programme skills have been mapped against the CIISec skills Framework, enabling trainees to apply for Accredited Affiliate Membership of CIISec, an internationally recognized professional qualification.
- IoT Security FoundationminorIASME IoT Cyber Assurance aligns with the IoTSF Security Compliance Framework, providing additional credibility for the certification scheme's alignment with international IoT security best practices.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
IASME Consortium competitors and assessment
Company assessmentDirect peers
- CREST: UK-based not-for-profit accreditation body for cyber security professionals and companies, delivering government-aligned certifications such as CREST Cyber Security Incident Response (CSIR) and penetration testing approvals. Comparable to IASME as a UK government-adjacent cyber certification authority serving enterprises and regulators.
- APMG International: Global accreditation and certification body that administers schemes including Cyber Resilience, ISO 27001, and government-backed cyber programmes. Highly comparable to IASME as a scheme-delivery partner operating multiple government and standards-aligned cyber certifications.
- PeopleCert (formerly AXELOS): Global certification body administering ITIL, PRINCE2, and RESILIA cyber resilience certifications. Comparable to IASME as a delivery partner for vendor-neutral cyber resilience certifications aligned with government and enterprise demand.
Others
- NCC Group: UK-based cyber security services firm offering assurance, certification support, and managed security. Comparable to IASME in the UK cyber assurance ecosystem, particularly aviation and defence cyber audits, though NCC Group delivers consulting and technical services rather than scheme administration.
Broad incumbents
- Bureau Veritas: Global testing, inspection, and certification body offering ISO 27001 and sector-specific cyber certifications across multiple geographies. Comparable to IASME as a certification scheme administrator, but Bureau Veritas operates a much broader portfolio across industries and regions.
- (ISC)²: Global non-profit issuing CISSP, CCSP, and other information security certifications recognised across government and enterprise. Comparable to IASME as a globally recognised cyber certification authority, though (ISC)² focuses on individual professionals rather than organisational certifications.
- ISACA: Global professional association delivering CISA, CISM, CRISC, and CGEIT certifications widely mandated for governance, risk, and audit roles. Comparable to IASME in providing governance-and-control-aligned cyber credentials, though ISACA targets individual auditors and risk professionals.
- CompTIA: Vendor-neutral IT certification body offering Security+, CySA+, and PenTest+ credentials widely adopted by employers and government buyers. Comparable to IASME in delivering foundational cyber certifications but focused on individuals rather than organisational schemes.
- SGS: Swiss-based global certification, inspection, and testing company with extensive cybersecurity, ISO 27001, and supply chain assurance services. Comparable to IASME as a scheme-administration and certification authority, with significantly broader geographic and industry reach.
- BSI (British Standards Institution): UK national standards body operating as a certification, training, and assurance provider including ISO 27001 and cyber resilience programmes. Comparable to IASME as a UK-based certification authority, though BSI's portfolio extends well beyond cyber into quality, environmental, and safety standards.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
IASME Consortium social profiles
Digital presenceIASME Consortium financial estimates
Financial estimateRevenue estimate
Valuation estimate
IASME Consortium leadership team
Management profileNumber of profiles
Profiles5 records
IASME Consortium subsidiaries and ownership
Company hierarchySubsidiaries1 record
IASME Consortium funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
IASME Consortium M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about IASME Consortium
What does IASME Consortium do?
IASME Consortium delivers government-backed cyber security certification schemes, most prominently the NCSC Cyber Essentials programme, alongside NCSC Cyber Advisor, Cyber Incident Exercising, Cyber Incident Response Standard Level, Defence Cyber Certification, IASME Cyber Assurance, IoT Cyber Baseline and Assurance, Maritime Cyber Baseline, and CAA ASSURE aviation audits. Certifications are administered through a secure online assessment platform with both self-led and supported routes, delivered via a UK network of over 300 licensed Certification Bodies, Assured Service Providers, and NCSC-assured Cyber Advisors.
Is IASME Consortium a public or private company?
IASME Consortium is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was IASME Consortium founded?
IASME Consortium was founded in 2012. It employs 1 to 10 people.
Where is IASME Consortium based?
IASME Consortium is headquartered in Malvern, United States, in the North America region.
How does IASME Consortium make money?
Six revenue lines are on record. Cyber Essentials Certification is the primary driver. The others are IASME Cyber Assurance Certification, ioT Cyber Certification, maritime Cyber Baseline Certification, defence Cyber Certification and cyber Liability Insurance.
Who are IASME Consortium's main competitors?
Direct peers on record are CREST, APMG International and PeopleCert (formerly AXELOS). NCC Group is listed as an others. Broad incumbents are Bureau Veritas, (ISC)², ISACA, CompTIA, SGS and BSI (British Standards Institution).
Does IASME Consortium have an API?
No public API is recorded for IASME Consortium.
What industry is IASME Consortium in?
IASME Consortium's product category is Cyber Security Certification. Its primary akta.pro industry code is BPAKAOAO, Cybersecurity Awareness & Digital Safety Training for Security Personnel, with a secondary code of EDAAANAA, Information Technology (IT) & Cybersecurity Certifications. Its NAICS code is 61142 and its SIC code is 8900.