Cyber Assurance Recertification: The Annual & 3-Year Cycle
Published 30 April 2026
Level 1 recertification
- Validity: 12 months
- Requirement: annual resubmission of the verified self-assessment via the IASME portal
- Plus: maintained Cyber Essentials certification (no expiry gaps)
- Process: largely a re-review and update of last year's evidence – significantly faster than first certification
Level 2 recertification
- Validity: 3 years
- Annual requirement: re-achieve Cyber Essentials and Cyber Assurance Level 1 every year ('soft check')
- Year 3: full Level 2 audit again
The annual soft check is a lightweight verification – not a full audit – which is what keeps the 3-year cost significantly lower than an ISO 27001 surveillance cycle.
Three-year cost comparison
For a 50-person organisation, a typical 3-year Level 2 plan looks like:
- Year 1: Full L2 audit + prerequisite CE + L1 self-assessment
- Year 2: CE renewal + L1 soft-check resubmission
- Year 3: CE renewal + L1 soft-check resubmission
Compare this to ISO 27001 (initial audit + 2 surveillance audits) and the cost difference is dramatic. See Cyber Assurance cost for full breakdown.
Don't let CE lapse
Both Level 1 and Level 2 require a continuously valid Cyber Essentials certificate. If your CE lapses, your CA status is at risk. We monitor expiry dates for all our clients and flag renewal at least 60 days out.
Switching Certification Body at renewal
You can change Certification Body at any renewal. Bring your existing IASME certificate number and submission history – we'll review your previous evidence and run a renewal-readiness check before you commit. Same idea as switching at CE renewal.
