Prerequisites
Why Cyber Essentials is the Cyber Assurance Prerequisite
Published 22 May 2026
The rule, exactly
- CE must be valid at purchase with 30+ days remaining
- CE must be valid at pass with 30+ days remaining
- If CE expires during the assessment, your Cyber Assurance pass is at risk
Why IASME requires it
Cyber Assurance is built on top of Cyber Essentials. The five CE technical controls – firewalls, secure configuration, access control, malware protection, and patch management – are foundational. CA assumes they're in place and assesses the governance, process and risk maturity above them.
Sequencing options
- CE first, CA later – classic route, lowest upfront cost, slower overall.
- Bundle CE + CA together – fastest end-to-end, single project, single onboarding. Recommended for tender deadlines.
- CE + CA Level 2 bundle – for organisations that need audited assurance from the outset.
Watch out for
- Buying CA when your CE is in its last 30 days – you will be asked to renew CE first
- CE certificate held in your IT provider's name rather than yours – it must be in your organisation's name
- Scope mismatch – CE and CA scopes should match unless you have a documented reason
What if I already have ISO 27001?
ISO 27001 does not substitute for Cyber Essentials in the CA prerequisite rule. Even if you hold ISO 27001, you still need CE to access Cyber Assurance.
See Cyber Assurance prerequisites for the full checklist.
