IASME Cyber Assurance
Certification
The IASME standard that takes you beyond Cyber Essentials – 14 themes across Identify, Protect, Deter & Detect and Respond & Recover. The affordable, UK-built route to mature cyber resilience.
- Cyber Essentials is the prerequisite – we can bundle both
- All 14 IASME themes across four areas covered
- Level 1 verified assessment £320 + VAT (0–9 staff)
- Level 2 audit valid for 3 years (with annual soft check)
- GDPR-aligned governance framework
- Independent IASME-licensed assessor


Get Your Free Quote
We'll respond within 24 hours with a tailored certification plan
Or email us directly at cyber@nixinfinityai.com
Who asks for Cyber Assurance?
Cyber Assurance is what UK buyers ask for when Cyber Essentials is not enough but ISO 27001 is disproportionate. These are the requests we see most often.
NHS and healthcare suppliers
Where the Data Security and Protection Toolkit applies, Cyber Assurance is well aligned and widely accepted as evidence of governance controls.
Central and local government
Enterprise-grade public sector contracts where Cyber Essentials is the baseline and buyers want documented risk management on top.
Financial services supply chain
Banks, insurers and IFAs asking suppliers to evidence policy, risk and business continuity controls beyond the five technical controls.
Enterprise procurement teams
Tenders where ISO 27001 is 'preferred' but Cyber Assurance is 'accepted' – the realistic route inside a tender deadline.
Security questionnaires and due diligence
A third-party-issued certificate answers most of a supplier security questionnaire in one document, instead of a 200-row spreadsheet.
Insurers and parent companies
Underwriters and group risk teams asking for a risk register, incident response plan and tested backups before they extend cover.
Cyber Assurance at a glance
| Cyber Essentials | Cyber Assurance L1 | ISO 27001 | |
|---|---|---|---|
| Covers | 5 technical controls | 14 governance themes | Full ISMS |
| Typical cost | £320 + VAT | £320 + VAT | £8,000–£25,000+ |
| Typical timeline | Days to 2 weeks | 4–8 weeks | 6–12 months |
| Validity | 12 months | 12 months (L2: 3 years) | 3 years + surveillance |
Full breakdown: Cyber Assurance vs ISO 27001 and Cyber Assurance for tenders.
Cyber Assurance Pricing
Tiered IASME fees based on organisation size. Level 2 audits are quoted after scoping.
Level 1
Verified Self-Assessment
Reviewed by an independent IASME assessor. Tiered IASME fees by organisation size.
Official IASME fees
- Micro – 0–9 employees£320 + VAT
- Small – 10–49 employees£440 + VAT
- Medium – 50–249 employees£500 + VAT
- Large – 250+ employees£600 + VAT
Don't have Cyber Essentials yet? We can bundle it – the matching CE band is added at the same tier.
- Verified self-assessment questionnaire
- All 14 IASME themes covered
- Independent assessor review
- Six-month assessment window
- 12-month valid certification
- Includes annual recertification reminders
Level 2
Audit Certification
Independent audit of your processes, procedures and controls. Pricing depends on size and complexity of your network.
Quote-based
Scoped per organisation
You must hold Level 1 before Level 2
- Full audit of processes, procedures and controls
- Documentation and policy deep-dive
- Staff interviews and observation
- Remote or on-site audit options
- Detailed findings report
- Remediation guidance included
- Valid for three years (with annual L1 + CE soft check)
Cyber Essentials is a mandatory prerequisite for Cyber Assurance. We can bundle both.
Certification Comparison
Cyber Essentials is the technical baseline and a mandatory prerequisite for Cyber Assurance Level 1 and Level 2.
| Feature | Cyber Essentials | CA Level 1 | CA Level 2 |
|---|---|---|---|
| CE certification required (prerequisite) | n/a | Required | Required |
| Five technical controls | |||
| All 14 IASME themes | |||
| Verified self-assessment | |||
| Policy & procedure review | |||
| Risk management & risk register | |||
| Business continuity & incident management | |||
| Independent audit (documents + interviews) | |||
| Remote or on-site verification | |||
| Detailed findings report | |||
| GDPR alignment | |||
| Certification validity | 12 months | 12 months | 3 years (annual L1 + CE soft check) |
CE certification required (prerequisite)
Five technical controls
All 14 IASME themes
Verified self-assessment
Policy & procedure review
Risk management & risk register
Business continuity & incident management
Independent audit (documents + interviews)
Remote or on-site verification
Detailed findings report
GDPR alignment
Certification validity
What Cyber Assurance Covers
Cyber Assurance is a risk-based standard built around 14 themes, grouped into four areas. Together they form IASME's roadmap to cyber resilience.
Identify & Classify
Understand what you have, who's responsible, what regulations apply and what risks need treatment.
- Identifying and protecting assets
- Legal and regulatory landscape
- Assessing and treating risks
- Organisation
- Planning information security
Protect
Put the right physical, procedural, technical and people controls in place to defend the business.
- Physical and environmental protection
- People
- Policy realisation
- Managing access
- Technical intrusion
- Change management
Deter & Detect
Monitor systems and operations so threats are spotted early and acted on quickly.
- Secure business operations: monitoring and review
Respond & Recover
Be ready to respond to incidents, keep operating through them and restore normal service quickly.
- Backup and restore
- Resilience: business continuity, incident management and disaster recovery
14 themes covering everything from asset management to disaster recovery. IASME tailors which themes apply based on your organisation size band (sole trader, micro, small or larger).
What to Expect When Working With Us
Governance certification made straightforward – by assessors who care.
Calm, Practical Support
Governance certification doesn't have to be overwhelming. We make it clear and manageable.
Policy Gap Analysis
We identify what's missing from your documentation before formal assessment, saving time and frustration.
Remediation Included
If non-conformities arise, we guide you through corrections at no extra charge until you pass.
Your Timeline, Not Ours
Need it for a tender? We'll prioritise. Planning ahead? We'll work at your pace.
Fixed Fee, No Surprises
Fixed fee, no hidden extras. The price we quote is the price you pay – no scope creep.
Ongoing Compliance Advice
We don't disappear after certification. Post-certification guidance included.
The Certification Process
Cyber Essentials first, then Level 1, then optional Level 2 audit. You have six months from purchase to complete each assessment.
Step 0: Achieve Cyber Essentials
A valid Cyber Essentials certificate with 30+ days remaining is required to purchase Cyber Assurance. We can bundle CE if you don't already hold it.
Level 1 – Verified Self-Assessment
Initial Consultation
Free scoping call to confirm your CE status, organisation size band and the appropriate depth of the standard.
Self-Assessment
Complete the IASME Cyber Assurance questionnaire covering all 14 themes that apply to your organisation size.
Independent Verification
An independent IASME assessor reviews your submission and provides feedback on any areas needing attention.
Certification
On successful completion you receive your IASME Cyber Assurance Level 1 certificate, valid for 12 months.
Level 2 – Independent Audit
Scoping & Planning
Detailed scoping session covering your organisation structure, network complexity and audit approach.
Documentation Review
Pre-audit review of your policies, procedures, risk register and security documentation.
Audit Session
Independent assessor examines documentation, interviews key staff and observes activities. Remote or on-site.
Findings Report
Detailed findings report with any non-conformities and remediation recommendations.
Remediation Support
Guidance and support to address any non-conformities identified during the audit.
3-Year Certification
Receive your Level 2 certificate, valid for three years – with annual CE + L1 soft-check renewal.
Six-month assessment window
Once you purchase, IASME issues login details for the online assessment portal. You have six months to complete each assessment. After that the account becomes invalid and a refund cannot be issued. We work to your timeline to keep things well inside the window.
What Our Clients Say
Join organisations who've achieved certification with our expert support.
"The 24-hour turnaround was exactly what we needed. We had a GCloud tender deadline and the team delivered our certification with time to spare. The pre-check saved us from a simple mistake that could have delayed everything."
Sarah M.
Tech Consultancy
"Harpal from NixInfinity-AI was incredibly proactive and responded to our queries within a few hours. The Cyber Essentials assessment was explained well, and he made sure we understood the process. Thanks for all your help!"
Craig F.
Cybersecurity & Managed IT Services
"A very simple process with clear pricing, and the team was very responsive, including by WhatsApp. Highly recommend."
DearMP
Casework software for UK Members of Parliament
"Needed CE Plus urgently for a defence contract. They scheduled my assessment within days and the technical audit was thorough but not intimidating. Highly recommend."
David K.
Government Contractor
Frequently Asked Questions
Common questions about IASME Cyber Assurance certification.
Ready to Get Certified?
Fill out the form above and we'll get back to you within 24 hours with a tailored plan.
