Cyber Assurance vs Cyber Essentials: What's the Difference?
Published 30 April 2026
The short answer
Cyber Essentials is the technical baseline. Cyber Assurance is the governance layer that sits on top of it. You do CE first, then CA. You cannot get CA without CE.
Side-by-side
- Scope: CE = 5 technical controls. CA = 14 themes across 4 areas (Identify, Protect, Deter & Detect, Respond & Recover).
- Format: CE = self-assessment reviewed by an assessor. CA L1 = verified assessment. CA L2 = independent audit.
- Validity: CE = 12 months. CA L1 = 12 months. CA L2 = 3 years (with annual CE + L1 soft check).
- Cost (IASME fees): CE £320 to £600 + VAT depending on size. CA L1 £320 to £600 + VAT on the same bands. CA L2 quoted per organisation.
- Audit: CE = no audit. CA L1 = no audit. CA L2 = full independent audit.
When CE is enough
Most public sector tenders and many private sector buyers ask for Cyber Essentials only. If your goal is a baseline of cyber hygiene, tender pre-qualification or cyber insurance, CE alone is normally enough. See our CE for tenders guide.
When you also need CA
You should consider Cyber Assurance when buyers, regulators or large enterprise procurement teams ask for evidence of governance maturity – information security policies, risk register, business continuity, supplier management. Cyber Assurance is also the natural step if ISO 27001 is on your roadmap but not yet affordable.
How to sequence them
- Achieve Cyber Essentials (or hold a valid CE with 30+ days remaining).
- Purchase Cyber Assurance (or bundle CE + CA together if you don't yet hold CE).
- Complete the CA Level 1 questionnaire within six months. The IASME assessor reviews and verifies.
- Optionally, apply for Level 2 once Level 1 is in place.
Full prerequisite rules: CA prerequisites explained.
