Cyber Assurance Prerequisites: Cyber Essentials and the 30-Day Rule
Published 30 April 2026
The two prerequisite rules
- To purchase Cyber Assurance: you must hold a valid Cyber Essentials certificate with at least 30 days remaining before expiry.
- To pass Cyber Assurance: the same rule applies – your CE must still have 30+ days remaining when CA is awarded.
Bundle option (no current CE)
If you don't currently hold Cyber Essentials, IASME lets you buy CE and CA together. After payment:
- You have 6 months to complete the Cyber Essentials assessment.
- Once CE is awarded, your account is upgraded to Cyber Assurance.
- You then have a further 6 months to complete the Cyber Assurance assessment.
The CE fee added is at the matching tier for your organisation size (£320 to £600 + VAT).
Scope alignment rule
The scope of organisation that you certify to Cyber Assurance must not be larger than the scope covered by your Cyber Essentials certification. So if your CE covers your UK office only, your CA cannot cover a wider European group. Plan scope at CE stage with CA in mind.
Six-month assessment window
IASME issues login details to the online assessment portal as soon as you pay. You have 6 months to complete each assessment. After 6 months the account becomes invalid and a refund cannot be issued. We work to your timeline so you submit well inside the window.
Organisations outside the UK
If you're based outside the UK, contact IASME (or us) before purchasing. IASME may accept an equivalent prerequisite certification in place of Cyber Essentials. We'll confirm what is acceptable for your jurisdiction before any money changes hands.
Recertification rules
Cyber Assurance recertification rules also reference CE:
- Level 1: annual resubmission of the verified self-assessment + maintained CE.
- Level 2: 3-year audit cycle but you must re-achieve CE and CA Level 1 every year as a soft check.
