Defence: Cybersecurity
The question
To ask the Secretary of State for Defence, what assessment he has made of the potential impact of the requirement to attain IASME certification on separate entities within the same business.
Answered by Luke Pollard
The Department applies a proportionate, risk‑based framework, with Defence Cyber Certification using Cyber Essentials as a baseline. The Department requires higher levels of assurance only where appropriate in order to minimise unnecessary administrative burden.
The Department keeps the impact of its cyber resilience requirements on suppliers under review, including how these apply to different entities within the same corporate group. In doing so, it seeks to recognise existing assurance activity where valid, and to address any gaps in a proportionate manner, without unnecessary duplication.
The approach we have taken ensures our Armed Forces are supported by a supply chain that is verifiably resilient against evolving cyber threats.
Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →