Skip to main content
    NixInfinity-AI
    Comparison

    The ISO 27001 Alternative for UK SMEs: IASME Cyber Assurance

    Published 4 August 2026

    Why SMEs look for an ISO 27001 alternative

    ISO 27001 is a genuinely good standard. The problem is proportionality. A 25-person consultancy asked for "ISO 27001 or equivalent" in a tender is being asked to fund a full information security management system, a gap analysis, a Stage 1 and Stage 2 audit and then annual surveillance. For most SMEs the certification cost is only part of it: the real cost is 6–12 months of internal time.

    The three questions worth asking before you commit:

    • Does the buyer's clause actually say ISO 27001, or "ISO 27001 or equivalent"?
    • Do you sell internationally, or into the UK supply chain only?
    • Is this one contract, or a repeatable requirement across your pipeline?

    Side-by-side

    Cyber EssentialsCyber Assurance L1Cyber Assurance L2ISO 27001
    Scope5 technical controls14 governance themes14 themes, auditedFull ISMS
    AssessmentVerified self-assessmentVerified assessmentIndependent auditStage 1 + Stage 2 audit
    Indicative cost£320 + VAT£320 + VATQuoted per organisation£8,000–£25,000+
    Time to certifyDays to 2 weeks4–8 weeks8–12 weeks6–12 months
    Validity12 months12 months3 years + annual check3 years + surveillance
    RecognitionUK, procurement-standardUK, growing fastUK, strongInternational

    What Cyber Assurance actually covers

    The 14 themes sit across four areas: Identify, Protect, Deter & Detect, and Respond & Recover. In practice that means an information security policy, an asset inventory, a risk register, access control, staff training records, incident response, tested backups and supplier assurance. If you have read Annex A of ISO 27001, this will look familiar – it is the same territory, expressed proportionately for smaller organisations. Full detail: the 14 themes explained.

    How much ISO 27001 groundwork it covers

    Cyber Assurance is not ISO 27001 and does not convert into it. What it does is force you to build most of the documentation ISO 27001 will later ask for: the policy set, the risk methodology, the continuity plan, the supplier register. Organisations that certify to Cyber Assurance first usually find the later ISO 27001 project shorter, because the evidence already exists and is already being maintained.

    When you should still choose ISO 27001

    • You sell to international enterprise buyers who name ISO 27001 specifically.
    • Your contract value justifies the cost and the buyer will not accept an equivalent.
    • You are already carrying most of an ISMS and want formal recognition.
    • You need to satisfy a group or parent-company mandate written around ISO.

    The pragmatic route for most UK SMEs

    1. Certify to Cyber Essentials – it is the prerequisite and the technical floor.
    2. Add Cyber Assurance Level 1 to evidence governance.
    3. Step to Level 2 when a buyer specifically wants an audited certificate.
    4. Move to ISO 27001 only when international enterprise demand justifies it.

    If you are working to a tender deadline, see Cyber Assurance for tenders, or send us the assurance clause and we will tell you honestly whether an equivalent will be accepted.

    Not sure an equivalent will be accepted?

    Send us the tender or contract clause and a UK IASME-licensed assessor will tell you whether Cyber Assurance satisfies it, before you spend anything.

    Frequently Asked Questions

    Related Cyber Essentials Guides