Version 3 Effective Date: February 2026

Revisions:

Date:

Author:

Description:

March 2022

Emma Philpott

First Version Published

April 2022

Emma Philpott

Change to data retention timescales to reflect agreement with NCSC

February 2025

Wendy Reeves

Updated template to V2

February 2026

Wendy Reeves

Addition of Clause 3.3 ‘Log-In Credentials’

February 2026

Wendy Reeves

Updated to V3

March 2026

Wendy Reeves

Corrected IASME Governance to IASME Cyber Assurance

Certification Body Security Requirements

  1. Introduction

  • IASME are committed to achieving a consistent high standard across companies and systems that assess and certify CE compliance

  • This document sets out the security requirements for all Certification Bodies (CBs) delivering Cyber Essentials.

  • These requirements are in addition to the Certification Body (CB) achieving the security certifications detailed in the Certification Body Criteria. These include Cyber Essentials certification and achievement of either IASME Cyber Assurance Level 2 or ISO27001 awarded by a third-party UKAS-accredited body.

2.0 Security Principles

All CBs must, at minimum, meet the following 10 security principles which are directly linked to the NCSC 10 Steps to Cyber Security guidance. Achievement of the IASME Cyber Assurance standard or ISO27001 for the whole organisation will usually be sufficient to demonstrate achievement of these principles.

2.1. Risk Management

The CB must carry out regular, at least annually, risk assessments that are linked to the company’s information assets. The CB must embed a Risk Management Regime across their organisation, supported by the board and senior managers.

2.2 Secure Configuration

The CB shall install all high-risk and critical patches for application software and operations systems within 14 days of the patch being released.

The CB must keep an accurate record of business information assets, including ownership and disposal shall be maintained. Each information asset (hardware or data) shall have a named custodian who shall be responsible for the information security of that asset. When hardware is no longer required by the business, all data shall be securely wiped from it using an industry standard tool.

Where possible, the CB shall identify particularly valuable or sensitive information assets through the use of data classification.

In order to minimise loss of, or damage to, all assets, equipment shall be physically protected from threats and environmental hazards. Physical security accreditation should be applied if necessary.

Only authorised personnel who have a valid and approved business need shall be given access to areas containing information systems or stored data

2.3 Network Security

CBs shall have firewalls at the boundaries to all networks and shall ensure that firewalls are managed properly including ensuring that only necessary ports are opened and that firewall management interfaces are appropriately protected.

2.4 Managing user privileges

Access to information shall be based on the principle of “least privilege” and restricted to authorised users who have a business need to access the information.

2.5 User Education and Awareness

Information security awareness training shall be included in the staff induction process and shall be carried out on an ongoing basis for all staff.

An on-going awareness programme shall be carried out in order to ensure that staff awareness of information security is maintained and updated as necessary.

The CB shall maintain and regularly review (at least annually) a security policy which sets out the rules governing the secure management of CB information assets and, in particular, the Cyber Essentials data. This policy should apply to all information/data, information systems, networks, applications, locations and staff of the CB or supplied under contract to it.

2.6 Incident management

The CB shall establish an incident management capability including incident management plans.

If required as a result of an incident, data must be isolated to facilitate forensic examination.

Information security incidents shall be recorded in a Security Incident Log and investigated to establish their cause and impact with a view to avoiding similar events. The organisation shall ensure that incident management plans are produced for all mission critical information, application, systems and networks.

IASME must be notified immediately about security incidents that affect (or are likely to affect) Cyber Essentials data. The CB shall in the first instance contact IASME’s CEO, CTO or CIO using the main telephone number (03300 882752) or using relevant mobile numbers. If the CB is unable to contact IASME via this method, then the CB must attempt to contact IASME using all other reasonable methods.

The CB must provide sufficient resource and cooperation to support IASME’s investigation of any security incidents relating to the CB.

2.7 Malware prevention

The CB shall have malware protection in place across all devices (servers, laptops, desktops, phones and tablets) in accordance with the Cyber Essentials anti-malware requirements.

2.8 Monitoring

The CB shall review regularly the access logs and alerting provided by all hardware firewalls, servers, anti-virus solutions and, where possible, all cloud-based services containing sensitive data

The CB shall have a yearly vulnerability scan carried out by an external body. The business shall act on the recommendations of the external company following the vulnerability scan in order to reduce the security risk presented by any significant vulnerabilities

2.9 Removable media controls

The CB shall control all access to removable media and limit media types and usage to only those required for the business.

2.10 Mobile and Home Working

The CB shall provide guidance and train staff on mobile working. All data must be protected at rest and in transit.

3.0 Additional security requirements

3.1 Data Storage

All Cyber Essentials Data must be stored in the UK unless the Certification Body has written permission from IASME

3.2 Supply Chain

All suppliers and contractors to the Certification Body should attain the Cyber Essentials certificate unless agreed with IASME.

3.3 Log-In Credentials

Login credentials provided to an individual by IASME for accessing platforms associated with the Cyber Essentials scheme must never be shared with another person unless with written permission from IASME.

3.4 Data Retention

The CB shall only retain data relating to the Cyber Essentials scheme for the following timeframes:

  • CE basic feedback report – 18 months from final report generated (pass or fail)

  • CE+ assessment report – 18 months from final report generated (pass or fail)

  • IASME Cyber Assurance L1 feedback report – 18 months from final report generated (pass or fail)

  • IASME Cyber Assurance L2 audit report – 3 years from final report generated (pass or fail)

  • Declarations and Branding agreements – 18 months from final report generated (pass or fail)

Data within the Pervade Assessment platform will be subject to these timeframes automatically.

Data held by the CB outside the Pervade Assessment Platform shall be securely deleted using an industry standard tool according to the timeframes above.

A set of anonymised data to assist with research and analysis of the scheme will be taken automatically from every assessment at the time of the final report and stored in a separate research database. The timeframes for retention of this data will be decided by IASME and NCSC.

3.5 Social Media

The Certification Body shall have a social media policy which is shared with all staff. Through this policy the Certification Body must aim to prevent social media posts from staff or contractors which may bring the Cyber Essentials scheme, NCSC or IASME into disrepute.

3.6 Confidentiality

The CB shall not disclose the details of organisations that IASME may be partnering with, locations of partner/client offices or details of work carried out unless agree in writing with IASME.