Cyber Assurance Level 1 vs Level 2: Which One Do You Need?
Published 7 July 2026
What both levels cover
Both Level 1 and Level 2 assess the same underlying standard: the IASME Cyber Assurance controls across 14 themes and 4 areas (governance and people, identify, protect, and detect and respond). The difference is the depth of verification. See the full breakdown in the 14 themes deep dive.
Level 1: self-assessed and verified
- You complete the Cyber Assurance question set covering all 14 themes.
- An IASME-licensed assessor reviews your answers and evidence remotely.
- Certificate issued when the assessor is satisfied.
- Annual recertification.
- UK price £320 + VAT for the smallest bands, scaling with size.
Level 2: independently audited
- Same question set, but every material claim is verified by an on-site or remote audit.
- Sample of policies, records, systems and staff interviewed.
- Full report of findings, remediation window for anything non-conformant.
- Certificate valid for three years, with annual re-verification of CE and Level 1.
- UK price is quote-based, typically several thousand pounds depending on scope.
Cost and timeline compared
| Aspect | Level 1 | Level 2 |
|---|---|---|
| Certification price | £320 + VAT | Quote-based (typically £3k–£10k+) |
| Timeline | 2–4 weeks | 6–12 weeks |
| Verification | Remote review of evidence | Audit of evidence and interviews |
| Certificate validity | 1 year | 3 years (with annual checks) |
| Recertification | Annual full submission | Annual light-touch, full re-audit at year 3 |
When Level 1 is enough
- You are winning private-sector work and buyers ask for "Cyber Assurance" without specifying a level.
- You need to demonstrate governance maturity beyond CE, without the cost of an audit.
- You are building towards Level 2 or ISO 27001 in the following year and want an interim credential.
When Level 2 is worth the cost
- Public-sector tenders (Government Commercial Agency lots, NHS DSPT-adjacent work) specifically ask for it.
- Large enterprise buyers accept it in place of ISO 27001 for smaller suppliers.
- Your board or regulator wants independent third-party assurance, not self-attestation.
- You want a credential that credibly signals maturity to insurance underwriters.
Prerequisite: Cyber Essentials
Neither level can be issued without a valid Cyber Essentials certificate. IASME treats CE as the technical baseline that Cyber Assurance builds governance on top of. Full detail in why CE is the CA prerequisite.
The clean upgrade path
- Year 0: achieve Cyber Essentials.
- Year 0–1: achieve Cyber Assurance Level 1. Fix any control gaps the assessor flags.
- Year 1–2: mature policies and evidence for six to twelve months.
- Year 2: upgrade to Level 2 with a much higher first-time pass rate.
Jumping straight from CE to Level 2 is possible but usually expensive: audit findings drive a second round of remediation and a re-audit. Level 1 is the shock absorber.
What buyers actually accept
Level 1 satisfies almost every private-sector "do you have Cyber Assurance" question. Level 2 is what named public-sector procurement asks for. If your tender text says "Cyber Assurance certified" without specifying level, Level 1 is compliant.
For the wider picture see Cyber Assurance cost UK 2026, Cyber Assurance vs ISO 27001and Level 2 audit prep.
