The ISO 27001 Alternative for UK SMEs: IASME Cyber Assurance
Published 4 August 2026
Why SMEs look for an ISO 27001 alternative
ISO 27001 is a genuinely good standard. The problem is proportionality. A 25-person consultancy asked for "ISO 27001 or equivalent" in a tender is being asked to fund a full information security management system, a gap analysis, a Stage 1 and Stage 2 audit and then annual surveillance. For most SMEs the certification cost is only part of it: the real cost is 6–12 months of internal time.
The three questions worth asking before you commit:
- Does the buyer's clause actually say ISO 27001, or "ISO 27001 or equivalent"?
- Do you sell internationally, or into the UK supply chain only?
- Is this one contract, or a repeatable requirement across your pipeline?
Side-by-side
| Cyber Essentials | Cyber Assurance L1 | Cyber Assurance L2 | ISO 27001 | |
|---|---|---|---|---|
| Scope | 5 technical controls | 14 governance themes | 14 themes, audited | Full ISMS |
| Assessment | Verified self-assessment | Verified assessment | Independent audit | Stage 1 + Stage 2 audit |
| Indicative cost | £320 + VAT | £320 + VAT | Quoted per organisation | £8,000–£25,000+ |
| Time to certify | Days to 2 weeks | 4–8 weeks | 8–12 weeks | 6–12 months |
| Validity | 12 months | 12 months | 3 years + annual check | 3 years + surveillance |
| Recognition | UK, procurement-standard | UK, growing fast | UK, strong | International |
What Cyber Assurance actually covers
The 14 themes sit across four areas: Identify, Protect, Deter & Detect, and Respond & Recover. In practice that means an information security policy, an asset inventory, a risk register, access control, staff training records, incident response, tested backups and supplier assurance. If you have read Annex A of ISO 27001, this will look familiar – it is the same territory, expressed proportionately for smaller organisations. Full detail: the 14 themes explained.
How much ISO 27001 groundwork it covers
Cyber Assurance is not ISO 27001 and does not convert into it. What it does is force you to build most of the documentation ISO 27001 will later ask for: the policy set, the risk methodology, the continuity plan, the supplier register. Organisations that certify to Cyber Assurance first usually find the later ISO 27001 project shorter, because the evidence already exists and is already being maintained.
When you should still choose ISO 27001
- You sell to international enterprise buyers who name ISO 27001 specifically.
- Your contract value justifies the cost and the buyer will not accept an equivalent.
- You are already carrying most of an ISMS and want formal recognition.
- You need to satisfy a group or parent-company mandate written around ISO.
The pragmatic route for most UK SMEs
- Certify to Cyber Essentials – it is the prerequisite and the technical floor.
- Add Cyber Assurance Level 1 to evidence governance.
- Step to Level 2 when a buyer specifically wants an audited certificate.
- Move to ISO 27001 only when international enterprise demand justifies it.
If you are working to a tender deadline, see Cyber Assurance for tenders, or send us the assurance clause and we will tell you honestly whether an equivalent will be accepted.
