Info Gov

The UK Cyber Security Council has appointed IASME as a Licensed Body, bringing the government's Cyber Essentials delivery partner into the framework through which the Council assesses and registers cyber security professionals against its chartered standards.

The Council, the self-regulatory body for the UK cyber security profession established in 2021 by what was then the Department for Digital, Culture, Media and Sport, said the appointment supports its work to strengthen and professionalise the UK's cyber security sector.

The Council was awarded its Royal Charter in 2022, giving it the power to license organisations to assess individuals and recommend them for professional registration - at Associate, Practitioner, Principal and Chartered levels - against the Council's Standard for Professional Competence and Commitment.

IASME joins a small group of Licensed Bodies that includes the Chartered Institute of Information Security (CIISec) and The Cyber Scheme, which were appointed among the first in 2023 following pilot programmes covering specialisms including security testing, secure system architecture and design, cyber security governance and risk management, and cyber security audit and assurance.

The appointment consolidates IASME's position within the UK's cyber assurance architecture. The Malvern-based certification company is the National Cyber Security Centre's delivery partner for the Cyber Essentials scheme, which it operates through a network of more than 350 licensed certification bodies across the UK and Crown Dependencies, and it delivers the Defence Cyber Certification scheme for UK defence suppliers alongside further certification schemes for organisations, marine vessels and connected devices.

Professional registration with the Council already features in IASME's own assessor requirements: Cyber Essentials assessors must hold and maintain Council registration at Practitioner, Principal or Chartered level.

Professional registration carries increasing weight in public sector work. The Council announced in 2024 that the NCSC would require accredited service providers to hold a professional title in order to provide services to government entities, making the licensing of assessment bodies a practical gateway to the government cyber security market

Also in this section

Aug 05, 2026

Third AI platform goes rogue during cyber testing

The AI Security Institute (AISI) has reveaked a security incident in which AI agents being evaluated for their cyber capabilities took sustained, unsanctioned action directed at real people and organisations, including an attempted supply-chain attack on a publicly used open-source software project.
Jul 30, 2026

New NCSC guidance sets out three-stage framework for cyber attack recovery

The National Cyber Security Centre (NCSC) has published new guidance setting out a three-stage framework to help organisations respond to and recover from highly disruptive cyber attacks, warning that recovery from the most serious incidents can take weeks or months and that victims must plan for consequences extending well beyond their technology estate.

InfoGov Masthead Newsletter 800