Version 5 Effective Date: 21 May 2026

Revisions:

Date:

Author:

Description:

March 2020

Emma Philpott

First Version Published

May 2021

Emma Philpott

Interim accepted qualifications removed and some rewording to make requirements more clear.

January 2022

Emma Philpott

Changes to ensure all CE+ assessors also qualify as CE assessors

Removal of some legacy wording about the transition to Cyber Essentials Partner

Removal of requirement for attending in-person CB meetings

Removal of duplicate requirements now all CE+ Assessors also need to be CE Assessors

Include requirement for ongoing training and assessment for Assessors

June 2023

Emma Philpott

Addition of CPENT certification to Lead Assessor qualifications. Addition of requirement for CPD points for all assessors. Removal of requirement for all assessors to attend CB meetings

Wendy Reeves

Changes to Assessor Criteria for CE and CE+. Option ‘C’ added to CE.

CE+ List A changes –

Tiger Scheme Check Team Leader and Check Team Member removed.

Practitioner, Principle or CST under UK Cyber Security Council added.

18 May 2026

Ben Cross

To facilitate the introduction of the Trainee Cyber Essentials Assessor (“TCEA”) scheme, a new section 4 has been inserted, which sets out the requirements for a TCEA; details the mentor requirements under the scheme; explains the various applicable timelines for the scheme; and the steps for applying to become a mentor.

Various changes made to ensure consistency of terms and to facilitate the implementation of the TCEA.

Changes made to section numbering.

  1. Assessor Criteria

IASME requires that anyone who applies to become a Cyber Essentials (“CE”) Assessor must have a suitable level of skills in cyber security. They must also attend the appropriate Assessor Training Course for the category of Assessor they wish to attain.

There are three categories of Assessor:

  • Cyber Essentials Assessor;

  • Cyber Essentials Plus (“CE+”) Assessor; and

  • Trainee Cyber Essentials Assessor (“TCEA”) working under the guidance of a Mentor.

An individual can be just a CE Assessor. If they are a CE+ Assessor, they must also be a CE Assessor as well. They need to meet the entry skill requirements and have attended the appropriate training course and passed the associated course exams.

The required skills for each level of Assessor are defined against the IISP and CyBok skills frameworks and require a broad spread of cyber security knowledge to enable skilled judgements to be made on an organisation’s answers to the assessment questions.

  1. Cyber Essentials

All CE Assessors must have achieved at least three (3) years’ experience in either an Information Technology or Cyber Security role during the five (5) years preceding their application or complete the TCEA route as described below. This experience must not include periods of study. 

In addition, all CE Assessors must complete and pass the IASME Assessor Skills Assessment Exam (“Exam”) unless they meet option A or B or C below. The Exam allows candidates who hold relevant skills and experience but do not hold one of the above certifications or memberships an opportunity demonstrate their skills. The Exam contents and marking scheme will be agreed between National Cyber Security Council (“NCSC”) and IASME, and will be periodically updated.

Option A

Hold one of the following certifications, which must be in-date and valid at the time of application:

  • ISC2 Certified Information Systems Security Professional (CISSP);

  • ISACA Certified Information Security Manager (CISM); and/or

  • ISO27001 Lead Auditor.

Option B

Hold membership of the Certified Professional (“CCP”) scheme at the following level: SIRA, IA Auditor or IA Architect roles at Practitioner-equivalent level or above which must be in-date and valid at the time of application. 

Option C

Hold UK Cyber Security Council Practitioner, Principal or Chartered professional registration with any specialism, which must be in-date and valid at the time of application.

All new assessors will be required to meet the above requirements before attending the Cyber Essentials Assessor Training Course.

  1. Cyber Essentials Plus

Every Certification Body (“CB”) that offers CE+ must, at all times, have at least one CE+ assessor who holds at least one of the certifications in list A. This person is referred to as the Lead CE+ Assessor.

List A

  • CREST Registered Penetration Tester.

  • CREST Certified Infrastructure Tester.

  • Cyber Scheme Team Member (“CSTM”).

  • Cyber Scheme Team Leader (“CSTL”).

  • EC-Council Certified Security Analyst (“ECSA”): Penetration Testing Practical.

  • EC-Council Certified Penetration Testing Professional (“CPENT”).

  • Offensive Security Certified Professional (“OSCP”).

  • Practitioner, Principle or Chartered Security Tester under UK Cyber Security Council.

For all other CE+ assessors (not including the Lead CE+ Assessor), they must either hold one of the qualifications from List A or pass the Vulnerability Assessment Plus (“VA+”) Exam. This is an exam developed by IASME and NCSC, and delivered by The Cyber Scheme.

  1. Trainee Cyber Essentials Assessor (“TCEA”)

4.1 The position of TCEA is specifically for those who: 

  • Have less than three (3) years’ experience in IT/Security (not including periods of study). 

  • Have completed the Cyber Basics assessment. 

  • Have completed a Prior-Learning Review with an apprenticeship organisation and determined their eligibility for an ICT Level 3 Apprenticeship. 

  • Wish to mark CE assessments under the mentorship of a fully qualified Cyber Essentials Assessor.  

All TCEAs must be based in the United Kingdom or the Crown Dependencies and must be employed by (or contracted to) a licensed Cyber Essentials CB. 

After passing the Cyber Basics Assessment, the applicant TCEA must attend the Cyber Essentials Assessor Course and pass the exam. After completing these steps, the applicant TCEA will be qualified to act as a TCEA, providing they: 

  • Are working for a licensed CB;

  • Have a nominated Mentor Assessor (see 3.2); and 

  • Are undertaking a Level 3 ICT Apprenticeship (if eligible) as outlined above. 

4.2 Mentor requirements 

To become a mentor to a TCEA, you must be able to demonstrate the following, at the point of onboarding: 

  • That you are a fully compliant CE Assessor, employed or contracted to a licensed CB; 

  • That you have completed no less than 12 Cyber Essentials assessments in total; and 

  • That you have had no more than one (1) failed moderation in the previous 12 months. 

4.3 Timelines associated with being a TCEA 

If eligible for an ICT L3 apprenticeship, and you commence this, then you must remain a TCEA for the duration of your apprenticeship.    If you are eligible for an ICT L3 apprenticeship but you opt not to commence this, then you must remain a TCEA until a time that you reach three (3) years of experience in IT/Security (not including periods of study).    If you are not eligible for an ICT L3 apprenticeship, then you must remain a TCEA for a minimum of one (1) year. 

4.4 Applying to become a full CE assessor from a TCEA 

For a TCEA to apply to become a full CE Assessor, they must: 

  • Have marked a minimum of 20 CE assessments; 

  • Completed the Trainee CE module in IASME’s Learning Platform; and 

  • Remained a TCEA for the appropriate time (see 3.3).

Once these measures have been met, your Mentor may recommend your application to be a full CE Assessor. At this stage, you must complete IASME’s Practical Skills Exam. In addition, IASME reserves the right to review training records maintained by IASME, the TCEA and Mentor to further contextualise the TCEA’s learning journey. This, alongside the above points, will be considered so that IASME may make the decision to onboard the TCEA as a full CE Assessor.

  1. Other Assessor Criteria

  • All CE Assessors must assess at least three (3) CE assessments every 12 months in order to retain their status as an Assessor.

  • All CE Assessors must be based in the United Kingdom or the Crown Dependencies.

  • All CE Assessors must attend on-going training and development to remain as an Assessor. Some training, such as the CE Scheme update training will be mandatory. With certain training and development assessors will be awarded CPD points. All assessors must earn at least ten (10) CPD points every calendar year and 40 CPD points over three (3) years to remain as an Assessor.