The Cyber Assurance Certification Process: Step by Step
Published 30 April 2026
Step 0: Cyber Essentials prerequisite
You must hold a valid Cyber Essentials certificate with 30+ days remaining. If you don't, bundle CE with CA (see prerequisites).
Step 1: Scoping and quote
We confirm your CE status, organisation size band, scope alignment and which depth of the standard applies. You get a fixed-fee quote covering the IASME fee plus our preparation support.
Step 2: Portal access
On payment, IASME issues login details to the online assessment portal. The 6-month assessment window starts now.
Step 3: Evidence preparation
We provide policy templates, a risk register starter, BC plan structure and a question-by-question evidence map aligned to the 14 themes. You collate evidence; we review and gap-fill.
Step 4: Submit Level 1
You complete the questionnaire in the portal. An independent IASME assessor verifies the submission. Most submissions are reviewed within 5–10 working days.
Step 5: Award or remediation
If everything is in order, the Level 1 certificate is issued. If non-conformities are flagged, you have a remediation period to address them. We support you through corrections at no extra charge.
Step 6 (optional): Level 2 audit
Once Level 1 is in place, you can apply for the Level 2 audit. The auditor reviews documentation, interviews staff and observes activities (remote or on-site). A detailed findings report is issued and the certificate is valid for 3 years – with annual CE + L1 soft check.
Annual maintenance
For Level 1 certification: annual resubmission of the verified self-assessment + maintained CE. For Level 2: re-achieve CE and CA Level 1 every year. See CA recertification cycle.
