IASME Cyber Assurance Explained: 14 Themes, 4 Areas
Published 4 May 2026
What Cyber Assurance actually is
Cyber Assurance is IASME's risk-based information assurance standard. It is recognised by the UK government and designed to give SMEs a credible, affordable alternative to ISO 27001. Where Cyber Essentials proves you have the five basic technical controls in place, Cyber Assurance proves you have the governance, policy and operational maturity to manage information risk across the whole organisation.
The 4 areas
- Identify and classify – knowing your assets, your risks and your obligations.
- Protect – the technical and procedural controls that keep data safe.
- Deter and detect – monitoring, awareness and the controls that spot incidents early.
- Respond and recover – incident response, business continuity and lessons learned.
The 14 themes
The four areas break down into 14 themes you must evidence:
- Planning information security
- Organisation
- Assets
- Legal and regulatory
- Risk assessment and management
- Policy realisation
- People
- Physical and environmental
- Operations and management
- Technical security
- Backup and restore
- Incident response
- Business continuity and disaster recovery
- Secure business operations: monitoring, review and change management
See our deep dive on the 14 themes of Cyber Assurance.
Level 1 (Verified) vs Level 2 (Audited)
Level 1 is a verified self-assessment, marked by an IASME-licensed assessor. Valid for 12 months. Level 2 adds an on-site or remote audit by a qualified auditor and is valid for 3 years, with an annual CE + CA Level 1 re-check. Compare both: Level 1 vs Level 2.
Why Cyber Essentials is a prerequisite
You cannot purchase Cyber Assurance without a valid Cyber Essentials certificate with 30+ days remaining. The same rule applies to pass. If you don't yet hold CE, the cleanest route is to bundle them. See Cyber Assurance prerequisites.
