The UK Cyber Security Council has appointed IASME as a Licensed Body, bringing the government's Cyber Essentials delivery partner into the framework through which the Council assesses and registers cyber security professionals against its chartered standards.
The Council, the self-regulatory body for the UK cyber security profession established in 2021 by what was then the Department for Digital, Culture, Media and Sport, said the appointment supports its work to strengthen and professionalise the UK's cyber security sector.
The Council was awarded its Royal Charter in 2022, giving it the power to license organisations to assess individuals and recommend them for professional registration - at Associate, Practitioner, Principal and Chartered levels - against the Council's Standard for Professional Competence and Commitment.
IASME joins a small group of Licensed Bodies that includes the Chartered Institute of Information Security (CIISec) and The Cyber Scheme, which were appointed among the first in 2023 following pilot programmes covering specialisms including security testing, secure system architecture and design, cyber security governance and risk management, and cyber security audit and assurance.
The appointment consolidates IASME's position within the UK's cyber assurance architecture. The Malvern-based certification company is the National Cyber Security Centre's delivery partner for the Cyber Essentials scheme, which it operates through a network of more than 350 licensed certification bodies across the UK and Crown Dependencies, and it delivers the Defence Cyber Certification scheme for UK defence suppliers alongside further certification schemes for organisations, marine vessels and connected devices.
Professional registration with the Council already features in IASME's own assessor requirements: Cyber Essentials assessors must hold and maintain Council registration at Practitioner, Principal or Chartered level.
Professional registration carries increasing weight in public sector work. The Council announced in 2024 that the NCSC would require accredited service providers to hold a professional title in order to provide services to government entities, making the licensing of assessment bodies a practical gateway to the government cyber security market

