Audit Preparation
How to Prepare for a Cyber Assurance Level 2 Audit
Published 8 May 2026
Pre-audit prerequisites
- Valid Cyber Essentials certificate (30+ days remaining)
- Valid Cyber Assurance Level 1 (Verified)
- Named senior responsible owner
- Organisation-wide scope agreed with the auditor
Evidence assessors expect
- Asset register – devices, cloud services, data flows, owners.
- Risk register – live, dated, with treatments and review cadence.
- Information security policy – approved, dated, version-controlled.
- Acceptable use policy – signed by all staff.
- Incident response plan – tested in the last 12 months.
- Business continuity plan – with RTO/RPO targets.
- Backup evidence – successful restore tests.
- Training records – for all staff, including induction.
- Supplier register – with risk ratings.
- Change management log – for the last 12 months.
Common audit failure points
- Policies that exist but aren't read, signed or dated
- No evidence the incident response plan has been tested
- Risk register that hasn't been updated in 6+ months
- Backup configured but never restore-tested
- Joiners/movers/leavers process not followed for ex-staff accounts
The week before
Walk every theme yourself. For each one, ask: "If the auditor asked me to prove this right now, what would I show them?" If the answer takes more than 60 seconds to find, fix the index, not the evidence.
