IASME and Cyber Essentials: who does what
Cyber Essentials is the government-backed scheme. The NCSC owns it, IASME runs it on the NCSC’s behalf, and your certificate comes from a certification body licensed by IASME. EJN Labs is one of them, licensed for Cyber Essentials and Cyber Essentials Plus, so we assess and issue in house rather than preparing you and handing you on.
- Free retest of every fix
- Fixed price agreed up front
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
WHO DOES WHAT
Who does what in Cyber Essentials
Four organisations appear somewhere on the paperwork. Only one of them issues your certificate.
The National Cyber Security Centre owns Cyber Essentials and decides what the five technical controls have to achieve. It does not assess organisations and it does not issue certificates.
IASME is the NCSC’s Delivery Partner for the scheme. It owns the question set, licenses the certification bodies that mark submissions, and holds the register of who is certified.
Licensed by IASME to mark your submission and issue your certificate. EJN Labs is one, licensed for both Cyber Essentials and Cyber Essentials Plus.
You choose the scope and answer the question set for it. Cyber Essentials Plus then adds an on-systems check of those same five controls.
The same five controls apply at both levels. They are set out in the NCSC’s Cyber Essentials overview.
THE SCHEMES
What IASME runs, and which parts we issue
IASME’s name sits on more than Cyber Essentials, which is where most of the confusion starts.
A self-assessment against the five technical controls, marked by a licensed certification body. It is a standard you meet, not an exam you sit. EJN Labs is licensed to assess and issue it.
The same five controls, verified by an assessor on your systems rather than taken on your word. It is assessor-led verification, not a penetration test, and neither level requires one. EJN Labs is licensed to assess and issue it.
A separate, higher-tier IASME standard for organisations that need more than Cyber Essentials covers. It has its own certification bodies and its own assessment, and it is not a scheme we issue.
The two we are licensed for are listed against EJN Labs on IASME’s own register of certification bodies.
LICENSED, NOT ACCREDITED
What being licensed by IASME actually means
The word matters, because it tells you who stands behind the certificate.
IASME and the NCSC both say licensed. Accredited is the UKAS word and means something else. A certification body is licensed by IASME to mark submissions and issue certificates under the scheme, and that licence is what stands behind the certificate you receive. If a supplier tells you it is IASME-accredited, it is using the wrong word for the right thing, or the wrong word for something else entirely.
EJN Labs is a certification body licensed by IASME for Cyber Essentials and Cyber Essentials Plus. The same team scopes the work, marks the submission and issues the certificate, rather than preparing you and handing the assessment to another firm. That is the difference between a certification body and a reseller, and it is worth asking any supplier which one they are.
Cyber Essentials work is done by an assessor, not a penetration tester. See how we run certification
COST AND SCOPE
What it costs, how long it takes, and what it does not include
Both levels are quoted as a fixed price against the scope you choose, agreed before any work starts. The IASME scheme fee sits inside that published price and is never billed on top. See the full price list.
Cyber Essentials is usually a matter of working days once your answers are ready. Cyber Essentials Plus takes longer, because it adds an on-systems check of the same five controls rather than relying on your answers alone.
Neither level requires a penetration test. Cyber Essentials Plus is assessor-led verification of the same five controls, and treating it as a penetration test overstates what it is and what it proves.
If you want evidence of what an attacker could actually reach, rather than confirmation that a control is in place, that is a penetration test and a separate engagement.
Scope drives both the price and the timeline, so it is the first thing we agree with you.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a Cyber Essentials quote in 24 hours
A fixed-price quote back in one working day, from a named CREST-certified consultant. No sales pipeline, no chasing.
- CREST-accredited, and licensed by IASME for Cyber Essentials and Cyber Essentials Plus. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £5,000 for a single-role, single-app scope, agreed up front. In our experience most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one working day with a fixed-price quote from a named CREST-certified consultant.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one working day with your fixed-price quote from a named CREST-certified consultant.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one working day. Your data stays with us. No newsletter signup.
BY SECTOR
Sectors we test
Law firms
Client files and case systems.
Law firms sector pageHealthcare
Patient data and clinical systems.
Healthcare sector pageFintech
Payment flows and FCA-regulated estates.
Fintech sector pageSaaS
Multi-tenant platforms and customer APIs.
SaaS sector pagePublic sector
Testing evidence procurement teams accept.
Public sector pageInsurance
Policyholder data and underwriting platforms.
Insurance sector pageWe deliver on-site or remotely UK-wide; for the capital, see penetration testing London, or browse all sectors.
FAQ
Frequently asked questions
What is the difference between IASME and Cyber Essentials?
Cyber Essentials is the scheme; IASME is the organisation that runs it. The NCSC owns Cyber Essentials and defines the five technical controls, IASME is the NCSC’s Delivery Partner and operates the scheme day to day, and certificates are issued by the certification bodies IASME licenses. They are not competing standards and you do not choose between them.
Is EJN Labs an IASME certification body?
Yes. EJN Labs is a certification body licensed by IASME for both Cyber Essentials and Cyber Essentials Plus, listed on IASME’s own register. That means we assess and issue your certificate in house rather than preparing you and passing the assessment to another firm.
Is it IASME-accredited or IASME-licensed?
Licensed. IASME and the NCSC both use licensed for certification bodies under the scheme. Accredited is the UKAS word and means something different, so a supplier describing itself as IASME-accredited is using the wrong term.
Do we need a penetration test for Cyber Essentials or Cyber Essentials Plus?
No. Neither level requires a penetration test. Cyber Essentials is a self-assessment against the five controls, and Cyber Essentials Plus is an assessor-led verification of those same controls on your systems. A penetration test is a separate exercise that answers a different question, namely what an attacker could actually reach.
Can you certify us for IASME Cyber Assurance?
No. IASME Cyber Assurance is a separate, higher-tier IASME standard with its own certification bodies, and it is not a scheme we issue. We are licensed for Cyber Essentials and Cyber Essentials Plus.
Is the IASME scheme fee charged on top of your price?
No. Because we are the certification body and issue the certificate ourselves, the IASME scheme fee sits inside the published certification price rather than being added to it. The full price list is on our pricing page.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a Cyber Essentials quote in 24 hours
Tell us what needs testing and a CREST-accredited UK team replies within one working day with a fixed price.



