The London-headquartered cybersecurity consultancy expands its UK assurance capabilities as an IASME-licensed Certification Body for the UK Government-backed Cyber Essentials scheme.
LONDON, 20 August 2026 — RedSecLabs, an independent cybersecurity consultancy serving regulated and security-conscious organisations, today announced that it has become a Cyber Essentials Certification Body, licensed by IASME to assess organisations against the Cyber Essentials scheme.
Cyber Essentials is a UK Government-backed certification scheme supported by the National Cyber Security Centre (NCSC) and delivered through IASME. It establishes a practical technical security baseline designed to protect organisations against the most common internet-based cyber-attacks.
As a Certification Body, RedSecLabs can now assess organisations against the Cyber Essentials requirements and issue Cyber Essentials certification to organisations that successfully meet the scheme criteria.
The new capability expands RedSecLabs’ UK assurance practice alongside its existing penetration testing, security assessment and compliance services.
From identifying security weaknesses to independently assessing the baseline
Cyber Essentials focuses on five fundamental technical control areas: firewalls, secure configuration, security update management, user access control and malware protection.
These controls address many of the weaknesses routinely exploited in common cyber-attacks, including unnecessary internet exposure, insecure configurations, excessive privileges, unsupported or unpatched software and inadequate protection against malicious code.
For RedSecLabs, becoming a Certification Body is a natural extension of its existing work helping organisations identify, understand and address technical security risks.
“A large part of effective cybersecurity comes down to consistently getting the fundamentals right,” said Rafay Baloch, Founder and CEO of RedSecLabs.
“Becoming a Cyber Essentials Certification Body allows us to extend our assurance capabilities further and help organisations demonstrate that those fundamental controls are in place against a recognised UK Government-backed standard.”
“It also complements our broader work across penetration testing, PCI DSS, SWIFT and security assurance, giving clients another practical route to independently demonstrate their security posture.”
Strengthening RedSecLabs’ UK assurance capabilities
The Cyber Essentials Certification Body appointment forms part of RedSecLabs’ continued investment in recognized cybersecurity and assurance capabilities.
RedSecLabs is already a CREST member and PCI DSS Qualified Security Assessor company, with capabilities spanning penetration testing, red teaming, security advisory, SWIFT Customer Security Program assessments and compliance assurance.
The company has also recently achieved UKAS-accredited ISO/IEC 27001:2022 and ISO 9001:2015 certifications, strengthening its own information security management and quality management frameworks.
Together, these capabilities enable RedSecLabs to support organizations across multiple layers of cybersecurity assurance — from establishing fundamental technical controls and obtaining Cyber Essentials certification through to penetration testing and specialised regulatory and industry assurance.
Supporting UK organisations with Cyber Essentials
Cyber Essentials has become an important security benchmark for organisations of all sizes and is particularly relevant to businesses working with government, regulated organisations and security-conscious supply chains.
As a Certification Body, RedSecLabs can now provide organisations with access to the Cyber Essentials assessment and certification process, with assessments conducted by qualified Cyber Essentials Assessors.
This capability complements RedSecLabs’ existing work helping organisations strengthen areas including vulnerability management, endpoint and cloud security, identity and access management, secure configuration and remediation.
RedSecLabs will continue to expand its Cyber Essentials capabilities as part of the company's wider UK cybersecurity assurance practice.
About RedSecLabs
RedSecLabs is a London-headquartered cybersecurity consultancy providing penetration testing, red teaming, incident response, security advisory and compliance assurance services to organisations across financial services, payments, healthcare, SaaS and the public sector.
RedSecLabs is a Cyber Essentials Certification Body, CREST member and PCI DSS Qualified Security Assessor company and is certified to ISO/IEC 27001:2022, ISO 9001:2015 and Cyber Essentials.
The company operates internationally, with a presence in the United Kingdom, United States and United Arab Emirates.
RedSecLabs was founded by Rafay Baloch, a cybersecurity researcher and practitioner known for his work in browser and application security.
Media enquiries
RedSecLabs
[email protected]
+44 20 3996 1505