Skip to main content
    NixInfinity-AI
    Audit Preparation

    How to Prepare for a Cyber Assurance Level 2 Audit

    Published 8 May 2026

    Pre-audit prerequisites

    • Valid Cyber Essentials certificate (30+ days remaining)
    • Valid Cyber Assurance Level 1 (Verified)
    • Named senior responsible owner
    • Organisation-wide scope agreed with the auditor

    Evidence assessors expect

    1. Asset register – devices, cloud services, data flows, owners.
    2. Risk register – live, dated, with treatments and review cadence.
    3. Information security policy – approved, dated, version-controlled.
    4. Acceptable use policy – signed by all staff.
    5. Incident response plan – tested in the last 12 months.
    6. Business continuity plan – with RTO/RPO targets.
    7. Backup evidence – successful restore tests.
    8. Training records – for all staff, including induction.
    9. Supplier register – with risk ratings.
    10. Change management log – for the last 12 months.

    Common audit failure points

    • Policies that exist but aren't read, signed or dated
    • No evidence the incident response plan has been tested
    • Risk register that hasn't been updated in 6+ months
    • Backup configured but never restore-tested
    • Joiners/movers/leavers process not followed for ex-staff accounts

    The week before

    Walk every theme yourself. For each one, ask: "If the auditor asked me to prove this right now, what would I show them?" If the answer takes more than 60 seconds to find, fix the index, not the evidence.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions