Version 4 Effective Date: June 2023

Revisions:

Date:

Author:

Description:

March 2020

Emma Philpott

First Version Published

May 2021

Emma Philpott

Updated to remove interim measures accepted during transition.

May 2022

Emma Philpott

Updated to include requirement about CB name and requirement to use digital badges

June 2023

Emma Philpott

Addition of requirement for one person to attend in-person CB meeting

Certification Body Criteria

IASME Certification Bodies are companies that are authorised to offer assessment to Cyber Security standards including Cyber Essentials.

In order to be a Certification Body, candidate companies must be able to demonstrate to IASME’s satisfaction that they:

  • Have good cyber security and can keep client data secure

  • Are committed to achieving an excellent and consistent client experience by using a quality management system

These two aims set the requirements which are the basis for the Certification Body Criteria. The requirements are detailed below.

In addition, all Certification Bodies must retain at least one Cyber Essentials Basic assessor at all times in order to retain their status as a Certification Body.

Certification Bodies must not change the organisation name to anything that infringes IASME or Cyber Essentials intellectual property or would be likely to cause confusion.

Certification Bodies must use badges associated with the scheme as digital badges, if available, to enable central management of brand and authenticity.

A minimum of 70% of the CB’s certifications completed in any 12 month period (commencing with the date on which the CB is appointed by IASME) must be certifications of UK based Organisations unless agreed in writing by IASME.

At least one member of staff from the CB must attend at least one in-person CB meeting every year unless there is written consent from IASME.

1. Certification Body Security Requirements

All IASME Certification Bodies must provide independently verified evidence that they have achieved and maintain the objectives of the NCSC 10 Steps to Cyber Security.

This can be demonstrated through:

  • Achieving and maintaining independently verified ISO 27001 certification

  • Achieving and maintaining audited IASME Cyber Assurance Level 2 certification

The scope of the above certifications must cover all areas of the business that will be involved in certification or that will hold data that relates to certifications.

27001 certification must be through a UKAS Accredited Certification Body or an International Accreditation Forum (IAF) recognised equivalent.

Verification of the requirements

All Certification Bodies must demonstrate they meet the security requirements before signing the Certification Body contract with IASME unless agreed otherwise with IASME.

2. Certification Body Quality Requirements

All Certification Bodies must commit to achieving and maintaining a good quality management system.

This can be demonstrated through:

  • Achieving and maintaining independently verified ISO 9001 certification

  • Achieving and maintaining a compliant mark on all of the IASME Quality Principles as part of a successful IASME Cyber Assurance Level 2 certification

  • Achieving and maintaining the QG Quality Fundamentals+ certification

  • Achieving and maintaining appropriate 17000 series certification through UKAS assessment

The scope of the above certifications must cover all areas of the business that will be involved in certification or that will hold data that relates to certifications.

ISO9001 certification must be through a UKAS Accredited Certification Body or an International Accreditation Forum (IAF) recognised equivalent.

Verification of the requirements

All Certification Bodies must demonstrate they meet the quality requirements before signing the Certification Body contract with IASME unless agreed otherwise with IASME.