LICENSED IASME CERTIFICATION BODY

IASME and Cyber Essentials: who does what

Cyber Essentials is the government-backed scheme. The NCSC owns it, IASME runs it on the NCSC’s behalf, and your certificate comes from a certification body licensed by IASME. EJN Labs is one of them, licensed for Cyber Essentials and Cyber Essentials Plus, so we assess and issue in house rather than preparing you and handing you on.

  • Free retest of every fix
  • Fixed price agreed up front
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori

WHO DOES WHAT

Who does what in Cyber Essentials

Four organisations appear somewhere on the paperwork. Only one of them issues your certificate.

NCSC

The National Cyber Security Centre owns Cyber Essentials and decides what the five technical controls have to achieve. It does not assess organisations and it does not issue certificates.

IASME

IASME is the NCSC’s Delivery Partner for the scheme. It owns the question set, licenses the certification bodies that mark submissions, and holds the register of who is certified.

Certification bodies

Licensed by IASME to mark your submission and issue your certificate. EJN Labs is one, licensed for both Cyber Essentials and Cyber Essentials Plus.

Your organisation

You choose the scope and answer the question set for it. Cyber Essentials Plus then adds an on-systems check of those same five controls.

The five technical controls
FirewallsSecure configurationUser access controlMalware protectionSecurity update management

The same five controls apply at both levels. They are set out in the NCSC’s Cyber Essentials overview.

THE SCHEMES

What IASME runs, and which parts we issue

IASME’s name sits on more than Cyber Essentials, which is where most of the confusion starts.

Cyber Essentials

A self-assessment against the five technical controls, marked by a licensed certification body. It is a standard you meet, not an exam you sit. EJN Labs is licensed to assess and issue it.

Cyber Essentials Plus

The same five controls, verified by an assessor on your systems rather than taken on your word. It is assessor-led verification, not a penetration test, and neither level requires one. EJN Labs is licensed to assess and issue it.

IASME Cyber Assurance

A separate, higher-tier IASME standard for organisations that need more than Cyber Essentials covers. It has its own certification bodies and its own assessment, and it is not a scheme we issue.

The two we are licensed for are listed against EJN Labs on IASME’s own register of certification bodies.

LICENSED, NOT ACCREDITED

What being licensed by IASME actually means

The word matters, because it tells you who stands behind the certificate.

Licensed, not accredited

IASME and the NCSC both say licensed. Accredited is the UKAS word and means something else. A certification body is licensed by IASME to mark submissions and issue certificates under the scheme, and that licence is what stands behind the certificate you receive. If a supplier tells you it is IASME-accredited, it is using the wrong word for the right thing, or the wrong word for something else entirely.

We assess and issue in house

EJN Labs is a certification body licensed by IASME for Cyber Essentials and Cyber Essentials Plus. The same team scopes the work, marks the submission and issues the certificate, rather than preparing you and handing the assessment to another firm. That is the difference between a certification body and a reseller, and it is worth asking any supplier which one they are.

Cyber Essentials work is done by an assessor, not a penetration tester. See how we run certification

COST AND SCOPE

What it costs, how long it takes, and what it does not include

What you pay

Both levels are quoted as a fixed price against the scope you choose, agreed before any work starts. The IASME scheme fee sits inside that published price and is never billed on top. See the full price list.

How long it takes

Cyber Essentials is usually a matter of working days once your answers are ready. Cyber Essentials Plus takes longer, because it adds an on-systems check of the same five controls rather than relying on your answers alone.

What it does not require

Neither level requires a penetration test. Cyber Essentials Plus is assessor-led verification of the same five controls, and treating it as a penetration test overstates what it is and what it proves.

Where a test does fit

If you want evidence of what an attacker could actually reach, rather than confirmation that a control is in place, that is a penetration test and a separate engagement.

Scope drives both the price and the timeline, so it is the first thing we agree with you.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a Cyber Essentials quote in 24 hours

A fixed-price quote back in one working day, from a named CREST-certified consultant. No sales pipeline, no chasing.

  • CREST-accredited, and licensed by IASME for Cyber Essentials and Cyber Essentials Plus. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £5,000 for a single-role, single-app scope, agreed up front. In our experience most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one working day with a fixed-price quote from a named CREST-certified consultant.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one working day. Your data stays with us. No newsletter signup.

FAQ

Frequently asked questions

What is the difference between IASME and Cyber Essentials?

Cyber Essentials is the scheme; IASME is the organisation that runs it. The NCSC owns Cyber Essentials and defines the five technical controls, IASME is the NCSC’s Delivery Partner and operates the scheme day to day, and certificates are issued by the certification bodies IASME licenses. They are not competing standards and you do not choose between them.

Is EJN Labs an IASME certification body?

Yes. EJN Labs is a certification body licensed by IASME for both Cyber Essentials and Cyber Essentials Plus, listed on IASME’s own register. That means we assess and issue your certificate in house rather than preparing you and passing the assessment to another firm.

Is it IASME-accredited or IASME-licensed?

Licensed. IASME and the NCSC both use licensed for certification bodies under the scheme. Accredited is the UKAS word and means something different, so a supplier describing itself as IASME-accredited is using the wrong term.

Do we need a penetration test for Cyber Essentials or Cyber Essentials Plus?

No. Neither level requires a penetration test. Cyber Essentials is a self-assessment against the five controls, and Cyber Essentials Plus is an assessor-led verification of those same controls on your systems. A penetration test is a separate exercise that answers a different question, namely what an attacker could actually reach.

Can you certify us for IASME Cyber Assurance?

No. IASME Cyber Assurance is a separate, higher-tier IASME standard with its own certification bodies, and it is not a scheme we issue. We are licensed for Cyber Essentials and Cyber Essentials Plus.

Is the IASME scheme fee charged on top of your price?

No. Because we are the certification body and issue the certificate ourselves, the IASME scheme fee sits inside the published certification price rather than being added to it. The full price list is on our pricing page.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a Cyber Essentials quote in 24 hours

Tell us what needs testing and a CREST-accredited UK team replies within one working day with a fixed price.