Cyber Assurance Level 1 vs Level 2: Verified vs Audited
Published 30 April 2026
Level 1 – Verified Assessment
You complete an online questionnaire covering all 14 IASME themes that apply to your organisation size band. An independent IASME assessor reviews your submission, checks the evidence you reference and either issues the certificate or asks for clarifications.
- Format: online questionnaire + assessor review
- Validity: 12 months
- IASME fee: £320–£600 + VAT depending on org size
- Time to complete: 2–4 weeks for prepared organisations
- CE prerequisite: yes
Level 2 – Audited
A more rigorous independent audit. The assessor examines your policies and procedures in detail, interviews key staff, observes activities and produces a detailed findings report. Audits can be remote or on-site.
- Format: documentation review + interviews + observation
- Validity: 3 years (with annual CE + L1 soft check)
- IASME fee: quote-based, depends on size and complexity of network
- Time to complete: 4–8 weeks including remediation
- Prerequisite: Level 1 must be in place
Which level should you choose?
Most SMEs start with Level 1. Move to Level 2 if:
- A specific buyer or contract requires it
- You want to demonstrate maximum assurance to enterprise clients
- You want a cost-effective, audited alternative to ISO 27001
- You're regulated and want third-party evidence of governance
Cost over three years
Because Level 2 is valid for three years (vs annual Level 1), the long-run cost of L2 can actually compare favourably with three consecutive L1 renewals once you account for the audit value. Full breakdown: Cyber Assurance cost.
