Version 5 Effective Date: February 2026

Revisions:

Date:

Author:

Description:

March 2020

Emma Philpott

First Version Published

September 2022

Emma Philpott

Change to clarify that the scope of the code covers other job functions as well as assessors.

Addition of clause 4 “Unacceptable Behaviours”

June 2023

Emma Philpott

Add clarification about companies that have a common director or other officer.

November 2023

Emma Philpott

Add clarification under paragraph 1 to describe both Assessor and CB responsibilities and the individual assessor agreement that will come into effect on 1st December. This includes requirement for CB to inform IASME if an assessor leaves and to have a contract with any current assessors.

Add clarification in section 2, under point 5, Confidentiality to strengthen confidentiality terms.

Replace text in 3.5 to give more detail on confidentiality expectations.

Clarify text under para 6.2 example as it is more about data protection and marketing laws than confidentiality

Added whistleblowing requirement to 3.1

Template Assessor Letter of Appointment included at end of Code for information

Wendy Reeves

Additional Clause added as clause 6 for Cyber Essentials Assessors acting as Mentors to Training Cyber Essentials Assessors

Wendy Reeves

Significant changes made, to include the expected conduct and behaviours from Assessor towards IASME staff. As a result, changes have been made to the following sections:

  1. – Introduction

  2. – Ethical Principles

  3. – Behaviour and Outcomes, specifically:

    3.1 – Integrity

    3.4 – Professional Competence and Due Care

    1. – Unacceptable Behaviours

    2. – Situations where an Assessor or Certification Body Should Not Conduct the Assessment

    3. – Examples of How to Apply this Code of Conduct

    4. – Integrity

Wendy Reeves

Updated to V5

1 Introduction

IASME is committed to delivering a high quality, consistent and fair experience for customers who want to gain certification to Cyber Essentials and IASMEʼs other certifications.

To achieve this, all IASME Assessors are required to operate with the highest level of ethical conduct. This includes maintaining professional and respectful communication with IASME and adhering to all policies, procedures, and requirements set out by IASME as the scheme Delivery Partner. Assessors are expected to conduct themselves professionally and respectfully during all IASME-hosted webinars, meetings, and events. This expectation also applies to any associated projects or pilots they may participate in, ensuring that their behaviour reflects positively on the scheme and its stakeholders.

This Code of Conduct document sets out the principles, behaviour and outcomes that Cyber Essentials Assessors must follow to avoid conflict of interest, ensure good customer experience, and uphold the integrity of the scheme. It also outlines the expectations for Assessors to engage with IASME in a manner that supports the effective delivery and administration of the scheme.

The Code applies directly to individual Assessors. It also applies to the CB for whom the Assessor is working. The CB must at all times ensure that its Assessors comply with this Code.

The CB must enter into a written confidentiality agreement with each of its Assessors which imposes a duty of confidentiality at least equivalent to the duty set out in paragraph 3.5 below and enforce such agreement. Assessors must also respect and protect the confidentiality of any information shared by IASME in the course of scheme delivery.

The CB shall ensure that its Certification Services are performed only by an Assessor and that there is a current written contract of employment (or other legally binding contract) between the CB and the Assessor. In addition, the CB must promptly inform IASME in writing in the event of termination or expiry of its contract with any Assessor.

Although the term ‘Assessor’ is used throughout this Code, the same principles apply to any other job function, contractors, or third parties that may be involved in supporting delivery of the Cyber Essentials scheme. Examples may include sales personnel or contracted marketing services.

2 Ethical Principles

All Assessors must use the following ethical principles to guide their decisions in relation to assessments, customers, IASME staff, and operating the scheme:

  1. Integrity – Act in accordance with the law and consistently exercise the highest moral principles during all interactions with customers and IASME staff.

  2. Honesty – Present facts clearly and truthfully.

  3. Objectivity – Perform all duties and make all decisions in relation to the scheme based on facts, not personal feelings or commercial concerns.

  4. Professional competence and due care – Render only those services which you are fully competent and qualified to perform.

  5. Confidentiality – Maintaining confidentiality is a critical element of the Scheme. CBs and Assessors must at all times ensure that strict confidentiality is maintained for the benefit of Customer Organisations and stakeholders. This includes safeguarding any sensitive or proprietary information shared by IASME in the course of scheme delivery.

3 Behaviour and Outcomes

The following behaviour and outcomes are expected under each ethical principle

3.1 Integrity

  • Assessors must work with care, skill and diligence in a safe and professional manner.

  • Assessors must ensure they remain up to date with any changes to IASMEʼs guidance and policies and must implement them promptly.

  • All actions carried out by an Assessor must comply with UK law and guidance issued by IASME. In particular, appropriate consent must be agreed with customers prior to an engagement.

  • Through their words or actions, Assessors must not damage the reputation of IASME, NCSC, or the Cyber Essentials Scheme and not attract adverse publicity to the scheme. This includes ensuring that all communications with IASME are conducted respectfully and professionally, and that any concerns or disputes are raised through appropriate channels.

  • The Assessor must never accept gifts or additional payment to look favourably on an assessment situation or divert from the assessment guidance.

  • If the Assessor makes a mistake or error of judgement which affects the outcome of an assessment, they must immediately report this to IASME. Additionally, Assessors must cooperate fully with IASME in resolving any issues arising from such errors.

  • If the Assessor is subject to a complaint or investigation, the Assessor must cooperate fully and respectfully with IASME in resolving any issues.

  • If the Assessor makes a mistake or error of judgement in relation to advice or the assessment of a client, they must inform that client.

  • The Assessor must inform IASME if they are aware that an assessment is being completed with inaccurate information.

3.2 Honesty

  • Assessors must ensure that all claims about their skills and expertise are accurate, clear and up-to-date

  • When discussing the benefits of certification assessors must accurately present the facts in a way the client can understand.

3.3 Objectivity

  • Assessments must be performed with independence and honesty to ensure a fair and true outcome.

  • When marking assessments or carrying out in-person audits, Assessors must make decisions about compliance based solely on factual information, not hearsay, rumour or sentiment.

  • Assessors must be independent and free from outside influence when making decisions about a client’s compliance to the standards

  • Where organisations provide cyber security services in addition to certification to the same client, particular effort must be taken to ensure that commercial drivers do not influence the objectivity the assessment process. IASME may ask for evidence of the steps taken to ensure this objectivity at any time.

  • The Assessor must declare any commercial relationship with a product or service before recommending it to a client. In these cases they must recommend at least one other product and allow the client to make the decision.

3.4 Professional Competence and Due Care

  • Assessors must maintain their knowledge of the Cyber Essentials scheme and good information security practice. Assessors must use all tools made available to them by IASME to achieve this, including webinars, forums, and regular Certification Body meeting training sessions.

  • Assessors must at all times commit sufficient time, effort and attention to their work to ensure that they always deliver a high-quality service. This includes responding promptly and professionally to any communications or requests from IASME.

  • Where a situation occurs where an Assessor does not have sufficient knowledge or competency, they must seek guidance and direction from IASME.

  • Assessors must feedback to IASME on any new insight or knowledge they gain from their involvement with the scheme to enable IASME to improve the body of knowledge for all Assessors.

  • The Assessor must make clear to the client which security improvements or investments are required to pass Cyber Essentials and which additional ones they are recommending for more general security. Assessors must also ensure that any recommendations or advice provided to clients align with IASMEʼs guidance and standards.

  • Assessors must conduct themselves professionally and respectfully during all IASME-hosted webinars, meetings, and events. This includes both verbal contributionsand written comments made via Q&A. Assessors should refrain from disruptive behaviour, use appropriate language, and treatIASME staff and other attendees with courtesy and respect. Any concerns or disagreements should be raised constructively and through the appropriate channels.

3.5 Confidentiality and Data Protection

The Assessor must keep the information received or obtained directly or indirectly from IASME, NCSC, any CB or the Customer Organisation, strictly confidential (whether that information is marked or otherwise identified to the Assessor as being confidential or not) and use that information only for the purposes of performing the assessment; meeting the contractual obligations to IASME as an Assessor, and as otherwise permitted in the Assessor Terms of Appointment.

This clause does not prevent the Assessor from disclosing such information to the extent strictly necessary in order to comply with Law or with an order of a Court or Tribunal in England and Wales. In the event that the Assessor considers himself or herself obliged to make such a disclosure the Assessor must first notify IASME and the relevant CB, giving them not less than 10 days’ written notice before making any such disclosure. The Assessor must co-operate with IASME and the CB and comply with their reasonable instructions concerning the proposed disclosure. In the event of any conflict between IASME’s instructions and those of the CB, IASME’s instructions shall prevail.

The Assessor and CB must also comply with Data Protection Law and not place IASME in breach of Data Protection Law.

4 Unacceptable Behaviours

Participation in this scheme requires that the CBs and their employees and contractors meet the Standards of conduct at all times. This includes maintaining professional and respectful conduct in all interactions with IASME and ensuring compliance with IASMEʼs policies and procedures.

This Code imposes a high standard of honesty and integrity. CBs are contractually responsible for ensuring that their Assessors and other employees and contractors are fully aware of this and for ensuring compliance by their Assessors, employees and contractors.

Behaviours that threaten the reputation of the Scheme (or IASME) will be in breach of the Agreement. This includes any actions or communications that undermine IASMEʼs role, authority, or reputation as the scheme Delivery Partner.

CBs are responsible for ensuring that these principles are taken into account by all employees or contractors. This may, for example, include those individuals or third-party organisations that are responsible for the CBs’ marketing and sales activities.

IASME considers that the following behaviours (amongst others) are likely to amount to a breach:

  • Excessive or persistent scraping of personal data relating to staff within customer organisations from online sources in order to solicit business. (IASME does not post the contact details of staff within a customer organisation). Excessive or persistent behaviour will be defined as IASME receiving either two or more complaints, or one serious complaint from recipients of such communications.

  • Exploiting the database of certified organisations for purposes of marketing and sales. This online database is for the purpose of validating that an organisation is certified to Cyber Essentials or Cyber Essentials Plus. It must not be proactively used to identify an organisationʼs recertification date for sales and marketing purposes.

  • Failing to communicate transparently with organisations. You must be clear and honest about your company identity, pricing and any other key matters when dealing with customers. Clarity and honesty must be established from the outset and maintained throughout all interactions. Additionally, you must always provide a clear opt-out option and ensure that those who opt out do not receive any further communications.

  • Masquerading as another organisation. (Note, for example, that IAMSE Consortium Limited is a corporate body and no CB or Assessor is entitled to indicate or suggest that they are part of, or agents for, IASME). Assessors must also ensure that they do not misrepresent their relationship with IASME in any communication or documentation.

  • Cold calling a competitor’s customer to solicit business is strongly discouraged. Persistent cold calling, in particular, risks bringing the Scheme into disrepute and may constitute a breach. Cold calling includes telephoning, emailing or otherwise approaching individuals with unsolicited marketing material. To solicit business, CBs may use postal services (ie hardcopy materials). Assessors must also refrain from using IASMEʼs name or reputation in any way that could be perceived as endorsing or supporting such practices.

IASME will take action against any CB or Assessor found to be in breach of their contractual obligations. This includes breaches of conduct in their interactions with IASME, such as failure to comply with IASMEʼs policies, procedures, or reasonable requests.

Ultimately, any investigation of a suspected breach can result in the termination of a CB’s appointment. A single breach (if serious enough) may be enough to justify termination. IASME reserves the right to investigate any suspected breaches of this Code, including those related to conduct towards IASME, and to take appropriate action as necessary.

5 Situations where an Assessor or Certification Body Should Not Conduct the Assessment

In some situations, the conflict of interest is such that Assessors should not undertake an assessment for a client. These situations include the following:

  • The Assessor is an employee, director or shareholder of the company they are assessing.

  • The Assessor has a financial interest (investment) in the company they are assessing.

  • A family member of the Assessor is a director or shareholder of the company they are assessing.

  • The Certification Body is owned by or owns the company they are assessing.

  • The Certification Body and the company being assessed share a common director, manager, owner or person(s) with financial interest.

  • The Certification Body and the company being assessed share a common organisational or individual relationship which may affect the independence of the assessment.

Additionally, Assessors and Certification Bodies must notify IASME of any potential or perceived conflicts of interest that may arise during the course of their work. IASME reserves the right to review and determine whether the conflict of interest is significant enough to disqualify the Assessor or Certification Body from conducting the assessment.

6 Mentor Responsibilities

This section applies to Assessors who are performing the role of Mentor to a Trainee Assessor.

The role of Mentor is an important role within the Scheme and may only be undertaken by individuals who meet the Mentor Requirements as published from time to time.

The Mentor is responsible for guiding the learning and development of the Trainee. It is therefore essential that the Mentor is familiar with the Training Requirements and practical steps that need to be completed by a Trainee before he or she may become an Assessor. The Mentor must help the Trainee prepare for the Trainee Assessor’s Skills Exam. This requires a structured approach to sharing know-how and expertise; discussing areas for improvement and development and ensuring that the Trainee’s work on Scheme assessments is properly supervised and monitored.

A written Training Record should be maintained, providing reliable evidence of the assessments and other milestones reached by the Trainee. The Training Record must be sufficiently detailed to enable IASME to determine whether or not the training has been properly completed.

The Mentor must devote sufficient time and attention to the role to give the Trainee every chance to succeed in their training.

When the Mentor is satisfied that the Trainee has reached the necessary level of experience and maturity and has completed the training, the Mentor is responsible for nominating the Trainee to take the Assessor Skills Exam.

The Mentor is fully responsible for the Trainee’s actions in Cyber Essentials assessments and compliance with the Assessor Code of Conduct and will face any disciplinary actions for the Trainee’s breach of the Code, poor-quality or incorrect work.

The Mentor must sign off all assessments completed by the Trainee and remains accountable to the customer Organisation for the Assessment.

The Mentor can obtain guidance from IASME (via the IASME Learning platform) on how to carry out the Mentor role and fully meet their responsibilities.

7 Examples of How to Apply this Code of Conduct

The following are examples of common situations that may be encountered by Assessors together with examples of how to apply the relevant rules set out above. In all cases, Assessors mustensure that their actions and decisions align with IASMEʼs guidance and policies, and they must seek clarification from IASME if they are uncertain about how to proceed.

7.1 An Assessor is working with a client to provide guidance and support to improve security. The Assessor then carries out a Cyber Essentials assessment for the same client.

The primary aim of Cyber Essentials is to encourage and educate organisations on implementingthe five technical controls. Providing guidance and support to clients on how to implement these controls is encouraged by both IASME and NCSC.

In this situation, the following should be considered:

Integrity

Only provide guidance to clients to the extent that you are knowledgeable about the subject. For instance, if the client needs to configure a complicated Cisco firewall and you understand the principles of firewalls but don’t have in-depth knowledge of Cisco, you should explain this clearly to the client and direct them to a suitably trained Cisco expert.

You must ensure that any statements made about the scheme are consistent with IASMEʼs official guidance and do not misrepresent the scope or benefits of certification.

Honesty

If a client asks whether Cyber Essentials will protect them from all cyber attacks, you must explain the scheme’s limitations. Emphasise that it is designed only to reduce the impact of commodity cyber attacks via the internet.

Objectivity

When carrying out the Cyber Essentials assessment, the client asks if they can remove from scope some old Windows 7 desktops that are rarely used but are connected to the main office network. The requirements of Cyber Essentials are that all internet-connected machines inside the boundary of scope (ie the office network) must be included in the assessment.

In this situation, in order to retain objectivity, you may offer your guidance and support to the client to decommission the Windows 7 desktops. Once this has been completed, you can continue the assessment and pass the client.

If the client does not want to decommission the Windows 7 desktops, you should advise the client that the machines cannot be removed from scope as they are part of the main office network so they must be included in the assessment. The client will then fail the assessment due to unsupported software.

7.2 A Certification Body wants to grow its business and attract new clients for Cyber Essentials certification.

Certification Bodies are free to pursue their own commercial strategy to attract clients. However, their conduct must comply with the requirements of this code of conduct.

In this situation, the following should be considered:

Integrity

The Certification Body should only use marketing methods that would be considered acceptable and reasonable by an independent person. For example, directly targeting customers of other Certification Bodies with marketing that includes or implies malicious or false claims about their competency is unacceptable and risks damaging the reputation of the scheme. However, an advert in a trade magazine for a particular business sector stating the benefits of using a particular Certification Body and providing a special offer on pricing would be acceptable.

Data Protection and Marketing

It is essential to comply with Data Protection Law including laws regulating use of electronic marketing, such as the Privacy and Electronic Communications Regulations (PECR). Any new marketing campaign should therefore be carefully designed to comply with such laws

7.3 An Assessor is carrying out a CE+ assessment for a client andfinds a critical vulnerability in a desktop. The clientʼs technical manager questions the Assessorʼs judgement and demands the vulnerability not be noted in the CE+ report.

In this situation, the following should be considered:

Professional competence and due care

The Assessor should ensure they have acted with due care in this situation by re-running any tests that are in dispute and checking any guidance provided by IASME to ensure they have come to the correct decision.

Objectivity

The Assessorʼs decision must not be influenced by the client. The Assessor must ensure they have sufficient factual information about the issue and can ask the client for further information, if needed, to clarify any relevant points.

The Assessor can also choose to refer the factual information to IASME and ask IASME for a view on compliance. The Assessor can then share IASMEʼs view with the client. In our experience, this has proved to be a very effective way to deal with this situation and retain objectivity.

It is vital that any relevant vulnerabilities identified are noted in the assessment report together with any decisions taken and advice given by IASME. This provides a clear record of actions to help support the Assessor’s claims of objectivity in the event of a later query.

8 Template Assessor Letter of Appointment

Dear [Name of Assessor]

APPLICATION TO BECOME A CYBER ESSENTIALS SCHEME ASSESSOR (“Assessor”)

I am pleased to confirm that you have successfully completed the application process. Subject to the terms set out below, this letter confirms your appointment as an Assessor. Subject to our safe receipt of your acceptance of the terms of appointment, Your appointment commences on the date of this letter. Your status as an Assessor will continue until it is terminated in accordance with the Terms of Appointment. Capitalised words and expressions have the meaning given to them in the Scheme Documentation unless the meaning is set out here.  

Terms of Appointment In accepting the appointment as an Assessor, you accept and agree to be legally bound by the Terms of Appointment. These include – (i) the terms of this Appointment Letter; and (ii) the Cyber Essentials Scheme Assessor Code of Conduct (copy attached) (as may be amended by IASME from time to time) Please note that amongst other matters, the Terms of Appointment (i) contain binding obligations concerning the use of the Scheme Logo, (ii) impose controls on your use of the Assessor Badge; (iii) impose a strict duty of confidentiality on you and (iv) oblige you to perform all assessments (and related activity) professionally and strictly in accordance with the Cyber Essentials Scheme Documentation (“Scheme Documentation”). Breaches of these obligations may result in the immediate termination of your appointment.

NEXT STEPS You may not hold yourself out as an Assessor or make any public announcement of your pending appointment until we have acknowledged safe receipt of your written acceptance of the Terms of Appointment. We will notify you when we have received it. Please therefore sign, date and return the enclosed copy of this letter as soon as possible.

YOUR OBLIGATIONS 1 You must only hold yourself out (refer to yourself) as an Assessor if (and to the extent that) you are employed (or contracted to provide Assessor services) by a Certification Body (CB). On no account must you hold yourself out as an Assessor independently of a CB, and all assessments you carry out must be performed on behalf of a CB and in accordance with your written contract with that CB (provided that there is no conflict between that contract and the Scheme Documentation in which case the Scheme Documentation shall prevail).

2 In accepting the role of Assessor you agree to be bound by these Terms including, without prejudice to the generality of the other provisions, the Assessor Code of Conduct as modified from time to time. 3 You will not allow any conflict of interest to arise between your ordinary business activities or personal interests and your independent role as Assessor. 4 You will carry out the Assessments only on organisations referred to you by IASME or by a Certification Body with whom you have a written contract (including terms of confidentiality regarding the Customer, the assessment and the Scheme) for Assessor services and you will Assess each Applicant strictly against the Cyber Essentials Technical Standard and obtain the necessary Management Information and other data as required by the Cyber Essentials Scheme Documentation (or in the event that you perform an Assessment for IASME, such information concerning the assessment as IASME may require). 5 You will perform the Assessments (and your other obligations to IASME) strictly in accordance with the Terms and conduct yourself at all material times in a professional manner acting at all times with honesty and integrity. 6 You will keep the information you receive or obtain directly or indirectly from IASME, NCSC, any CB or the Customer Organisation, (whether that information is marked or otherwise identified to you as being confidential or not) strictly confidential and use that information only for the purposes of meeting your contractual obligations as an Assessor and as otherwise permitted in the Terms. This clause does not prevent you from disclosing such information to the extent strictly necessary in order to comply with Law or with an order of a Court or Tribunal in England and Wales. In the event that you consider you are obliged to make such a disclosure you must first notify IASME and the relevant CB, if any, giving them not less than 10 days’ written notice before making any such disclosure. You will co-operate with IASME and/or the CB and comply with their reasonable instructions concerning the proposed disclosure. 7 You will not do or cause or permit to be done anything likely to cause damage to the reputation, business or standing of IASME, the NCSC any Customer or the Scheme. 8 You will comply at all times with the applicable Law of England and Wales and with the professional and technical standards to which you are subject.

Termination 9 IASME may terminate your appointment at any time upon giving 1 month’s written notice to you. 10 IASME may terminate your appointment with immediate effect in the event that – (i) you breach the duty of confidence contained in paragraph 6; (ii) you breach the duty in paragraph 7 ; (iii) you bring IASME, NCSC or the Scheme into disrepute; (iv) you become insolvent or make any arrangement with your creditors; (vii) IASME perceives a material conflict of interest affecting your role as Assessor; (viii) you materially breach any one of more of the obligations placed on you by clauses 1, 3, 4, 5, or 12 or the obligations regarding IASME’s Intellectual Property Rights and/or the Scheme Intellectual Property Rights. (ix) you materially breach any one or more of the Assessor Requirements; (ix) IASME is directed by NCSC to terminate your appointment. In this event, IASME will inform you of the fact of the direction from NCSC but shall not be obliged to provide any further information to you. 11 In the event of termination for any reason you shall immediately cease holding yourself out as an Assessor; offering or providing Assessor services to any CB ; using the Assessor Badge and any other Scheme IPR and IASME IPR and shall provide all necessary information and support to the CB and IASME as the case may be in order to facilitate the termination of any assessment then in progress and the efficient and effective transfer of information and services to any third party nominated by IASME. In the event of termination, You hereby authorise IASME to remove the Assessor Badge from your website remotely and without further notice to you.

Warranties 12 You warrant and represent that you (i) have, and will maintain, the professional qualifications, skills and technical expertise required in order to perform the Assessments and as represented to IASME by you at the time of your appointment; (ii) are not under any investigation by any professional organisation or regulator and have not been subject to any disciplinary or enforcement measures in the past 5 years; (iii) are not and have not been disqualified from holding any directorship or other office.

No Minimum Volumes 13 You acknowledge and accept that IASME does not and has not guaranteed any or any minimum volume of work for you.

No Agency or Partnership 14 You appointment does not create any agency or partnership between you and IASME and you will not hold yourself out as an agent or partner of IASME.

Dispute Resolution 15 Any dispute concerning this appointment shall, if the dispute cannot be resolved through normal administrative discussions, in the first instance be referred to the Chief Executive Officers of IASME and of the relevant CB for resolution. 16 In the event that such executive resolution is unsuccessful after 14 days of being referred to those executives then the dispute shall be referred to an arbitrator appointed by the Chartered Institute of Arbitrators.

Applicable Law and Jurisdiction 17 The law of England and Wales shall apply to this agreement and both parties irrevocably submit to the jurisdiction of the English Courts.

Congratulations on your successful application! We look forward to welcoming you as anAssessor and working with you to ensure the continued success of the Scheme.

Yours sincerely,