Skip to main content
    NixInfinity-AI
    IASME Accredited
    14 Themes · 4 Areas
    Requires Cyber Essentials

    IASME Cyber Assurance
    Certification

    The IASME standard that takes you beyond Cyber Essentials – 14 themes across Identify, Protect, Deter & Detect and Respond & Recover. The affordable, UK-built route to mature cyber resilience.

    • Cyber Essentials is the prerequisite – we can bundle both
    • All 14 IASME themes across four areas covered
    • Level 1 verified assessment £320 + VAT (0–9 staff)
    • Level 2 audit valid for 3 years (with annual soft check)
    • GDPR-aligned governance framework
    • Independent IASME-licensed assessor
    5-Starrated service
    IASME Cyber Assurance certification mark – governance and risk management standardIASME Cyber Assurance Level 2 certified badgeIASME accredited certification body badge for Cyber Assurance

    Get Your Free Quote

    We'll respond within 24 hours with a tailored certification plan

    📅 Or Book a Free Consultation

    Or email us directly at cyber@nixinfinityai.com

    5-Starrated service
    GDPR-aligned framework
    IASME Accredited Assessor
    Trusted by NHS, Government & Enterprise

    Who asks for Cyber Assurance?

    Cyber Assurance is what UK buyers ask for when Cyber Essentials is not enough but ISO 27001 is disproportionate. These are the requests we see most often.

    NHS and healthcare suppliers

    Where the Data Security and Protection Toolkit applies, Cyber Assurance is well aligned and widely accepted as evidence of governance controls.

    Central and local government

    Enterprise-grade public sector contracts where Cyber Essentials is the baseline and buyers want documented risk management on top.

    Financial services supply chain

    Banks, insurers and IFAs asking suppliers to evidence policy, risk and business continuity controls beyond the five technical controls.

    Enterprise procurement teams

    Tenders where ISO 27001 is 'preferred' but Cyber Assurance is 'accepted' – the realistic route inside a tender deadline.

    Security questionnaires and due diligence

    A third-party-issued certificate answers most of a supplier security questionnaire in one document, instead of a 200-row spreadsheet.

    Insurers and parent companies

    Underwriters and group risk teams asking for a risk register, incident response plan and tested backups before they extend cover.

    Cyber Assurance at a glance

    Cyber EssentialsCyber Assurance L1ISO 27001
    Covers5 technical controls14 governance themesFull ISMS
    Typical cost£320 + VAT£320 + VAT£8,000–£25,000+
    Typical timelineDays to 2 weeks4–8 weeks6–12 months
    Validity12 months12 months (L2: 3 years)3 years + surveillance

    Full breakdown: Cyber Assurance vs ISO 27001 and Cyber Assurance for tenders.

    Cyber Assurance Pricing

    Tiered IASME fees based on organisation size. Level 2 audits are quoted after scoping.

    Level 1

    Verified Self-Assessment

    Reviewed by an independent IASME assessor. Tiered IASME fees by organisation size.

    Official IASME fees

    • Micro – 0–9 employees£320 + VAT
    • Small – 10–49 employees£440 + VAT
    • Medium – 50–249 employees£500 + VAT
    • Large – 250+ employees£600 + VAT

    Don't have Cyber Essentials yet? We can bundle it – the matching CE band is added at the same tier.

    • Verified self-assessment questionnaire
    • All 14 IASME themes covered
    • Independent assessor review
    • Six-month assessment window
    • 12-month valid certification
    • Includes annual recertification reminders
    Most Comprehensive

    Level 2

    Audit Certification

    Independent audit of your processes, procedures and controls. Pricing depends on size and complexity of your network.

    Quote-based

    Scoped per organisation

    You must hold Level 1 before Level 2

    • Full audit of processes, procedures and controls
    • Documentation and policy deep-dive
    • Staff interviews and observation
    • Remote or on-site audit options
    • Detailed findings report
    • Remediation guidance included
    • Valid for three years (with annual L1 + CE soft check)

    Cyber Essentials is a mandatory prerequisite for Cyber Assurance. We can bundle both.

    Certification Comparison

    Cyber Essentials is the technical baseline and a mandatory prerequisite for Cyber Assurance Level 1 and Level 2.

    CE certification required (prerequisite)

    CE
    n/a
    CA L1
    Required
    CA L2
    Required

    Five technical controls

    CE
    CA L1
    CA L2

    All 14 IASME themes

    CE
    CA L1
    CA L2

    Verified self-assessment

    CE
    CA L1
    CA L2

    Policy & procedure review

    CE
    CA L1
    CA L2

    Risk management & risk register

    CE
    CA L1
    CA L2

    Business continuity & incident management

    CE
    CA L1
    CA L2

    Independent audit (documents + interviews)

    CE
    CA L1
    CA L2

    Remote or on-site verification

    CE
    CA L1
    CA L2

    Detailed findings report

    CE
    CA L1
    CA L2

    GDPR alignment

    CE
    CA L1
    CA L2

    Certification validity

    CE
    12 months
    CA L1
    12 months
    CA L2
    3 years (annual L1 + CE soft check)
    Included
    Not included

    What Cyber Assurance Covers

    Cyber Assurance is a risk-based standard built around 14 themes, grouped into four areas. Together they form IASME's roadmap to cyber resilience.

    Area 1

    Identify & Classify

    Understand what you have, who's responsible, what regulations apply and what risks need treatment.

    • Identifying and protecting assets
    • Legal and regulatory landscape
    • Assessing and treating risks
    • Organisation
    • Planning information security
    Area 2

    Protect

    Put the right physical, procedural, technical and people controls in place to defend the business.

    • Physical and environmental protection
    • People
    • Policy realisation
    • Managing access
    • Technical intrusion
    • Change management
    Area 3

    Deter & Detect

    Monitor systems and operations so threats are spotted early and acted on quickly.

    • Secure business operations: monitoring and review
    Area 4

    Respond & Recover

    Be ready to respond to incidents, keep operating through them and restore normal service quickly.

    • Backup and restore
    • Resilience: business continuity, incident management and disaster recovery

    14 themes covering everything from asset management to disaster recovery. IASME tailors which themes apply based on your organisation size band (sole trader, micro, small or larger).

    What to Expect When Working With Us

    Governance certification made straightforward – by assessors who care.

    Calm, Practical Support

    Governance certification doesn't have to be overwhelming. We make it clear and manageable.

    Policy Gap Analysis

    We identify what's missing from your documentation before formal assessment, saving time and frustration.

    Remediation Included

    If non-conformities arise, we guide you through corrections at no extra charge until you pass.

    Your Timeline, Not Ours

    Need it for a tender? We'll prioritise. Planning ahead? We'll work at your pace.

    Fixed Fee, No Surprises

    Fixed fee, no hidden extras. The price we quote is the price you pay – no scope creep.

    Ongoing Compliance Advice

    We don't disappear after certification. Post-certification guidance included.

    The Certification Process

    Cyber Essentials first, then Level 1, then optional Level 2 audit. You have six months from purchase to complete each assessment.

    Prerequisite

    Step 0: Achieve Cyber Essentials

    A valid Cyber Essentials certificate with 30+ days remaining is required to purchase Cyber Assurance. We can bundle CE if you don't already hold it.

    1

    Level 1 – Verified Self-Assessment

    Step 1

    Initial Consultation

    Free scoping call to confirm your CE status, organisation size band and the appropriate depth of the standard.

    Step 2

    Self-Assessment

    Complete the IASME Cyber Assurance questionnaire covering all 14 themes that apply to your organisation size.

    Step 3

    Independent Verification

    An independent IASME assessor reviews your submission and provides feedback on any areas needing attention.

    Step 4

    Certification

    On successful completion you receive your IASME Cyber Assurance Level 1 certificate, valid for 12 months.

    2

    Level 2 – Independent Audit

    Step 1

    Scoping & Planning

    Detailed scoping session covering your organisation structure, network complexity and audit approach.

    Step 2

    Documentation Review

    Pre-audit review of your policies, procedures, risk register and security documentation.

    Step 3

    Audit Session

    Independent assessor examines documentation, interviews key staff and observes activities. Remote or on-site.

    Step 4

    Findings Report

    Detailed findings report with any non-conformities and remediation recommendations.

    Step 5

    Remediation Support

    Guidance and support to address any non-conformities identified during the audit.

    Step 6

    3-Year Certification

    Receive your Level 2 certificate, valid for three years – with annual CE + L1 soft-check renewal.

    Six-month assessment window

    Once you purchase, IASME issues login details for the online assessment portal. You have six months to complete each assessment. After that the account becomes invalid and a refund cannot be issued. We work to your timeline to keep things well inside the window.

    5/5

    What Our Clients Say

    Join organisations who've achieved certification with our expert support.

    "The 24-hour turnaround was exactly what we needed. We had a GCloud tender deadline and the team delivered our certification with time to spare. The pre-check saved us from a simple mistake that could have delayed everything."

    Sarah M.

    Tech Consultancy

    "Harpal from NixInfinity-AI was incredibly proactive and responded to our queries within a few hours. The Cyber Essentials assessment was explained well, and he made sure we understood the process. Thanks for all your help!"

    Craig F.

    Cybersecurity & Managed IT Services

    "A very simple process with clear pricing, and the team was very responsive, including by WhatsApp. Highly recommend."

    DearMP

    Casework software for UK Members of Parliament

    "Needed CE Plus urgently for a defence contract. They scheduled my assessment within days and the technical audit was thorough but not intimidating. Highly recommend."

    David K.

    Government Contractor

    Frequently Asked Questions

    Common questions about IASME Cyber Assurance certification.

    Ready to Get Certified?

    Fill out the form above and we'll get back to you within 24 hours with a tailored plan.

    Related Cyber Essentials Guides