IASME Cyber Assurance (ICA) and ISO27001
IASME Cyber Assurance (ICA) is a security and governance certification that builds on Cyber Essentials by assessing not only technical controls, but also organisational, user, and management controls.
This was developed with government support as a more affordable and accessible alternative to the International "gold standard" for Cyber Security, ISO 27001. ICA provides a comprehensive security framework suitable for organisations of all sizes — including small businesses and micro-organisations. It is very useful for organisations that wish to indicate Resilience, as well as technical Cyber Security.
ICA is available at two levels:
-
Level 1 – self-assessment
-
Level 2 – independently audited
Regola offer support and certification for organisations wishing to get ICA L1 and ICA L2.
Organisations wishing to go all the way and get certified to ISO27001 have only a small hill to climb from ICA L2. Regola has the expertise and partners to support organisations wishing to achieve ISO27001 certification. However this would happen outside IASME, and the standards body awarding certification would be an International one, and not the UK Government.

What is it?
Level 1 is a verified self-assessment. It serves as the entry point to the IASME standard. Your organisation completes a set of questions about your policies and procedures, which is then reviewed by an independent IASME-certified assessor.
This level has recently been updated to be shorter, clearer, and more accessible, with questions tailored specifically to the size of your business.

What is it?
Level 2 is an in-depth, independent audit of your systems, processes, and people. Unlike Level 1, this involves a live audit (either on-site or remote) where an assessor interviews key staff, reviews documented evidence, and observes your operations to verify that your security controls are actually working as described.
It demonstrates a high level of cyber resilience and is often viewed as a cost-effective and more accessible alternative to ISO 27001.
Key Points of ICA

Broader Scope Than Cyber Essentials: Covers technical, user and management controls not just system security
Government-Supported Standard: Created to offer a cost-effective alternative to ISO 27001 for SMEs.
Two Certification Levels: Level 1 (online self-assessment) and Level 2 (audited)
Focus in Resilience & Governance: Includes risk management, policies, employee awareness, backup strategy, and incident handling.
Available through IASME to Certification Bodies: Regola offers ICA certification at both Level 2 and Level 2.
The Process
Level 1 — Self-Assessment
-
Purchase ICA Level 1 through IASME or a Certification Body (e.g. Regola).
-
Complete Online Questionnaire — Covers governance, risk assessment, policies, legal requirements (including GDPR), backups, and incident response.
-
Review & Approval — Submitted answers are reviewed and if successful, Level 1 certification is awarded.

Level 2 — Audited Certification
-
Requires you to hold a Level 1 Certification, as ICA Level 2 builds directly on Level 1.
-
Book an Audit With a Certification Body — Same question set as the first, but is independently verified.
-
Assessment & Evidence Review — Auditors confirm that policies and controls are implemented in practice.
-
Certification Granted — Awarded once the audit confirms compliance.

Moving Beyond IASME Cyber Assurance to ISO 27001
(Equivalent to Level 3)
While it's not a strict requirement to hold ICA certification, ISO 27001 is a natural stepping stone.
We can assist in preparing your company for an audit performed by an International Standards Certification Body and our partners can take you through to certification

