What is IASME Cyber Assurance? Plain-English Explainer
Published 30 April 2026
Cyber Assurance in plain English
Where Cyber Essentials proves you have five basic technical controls in place, Cyber Assurance proves you also have the policies, processes, people and recovery plans needed to be genuinely resilient. It is the UK's flagship information assurance standard for SMEs and is recognised across supply chains as evidence of mature governance.
Two levels of certification
- Level 1 – Verified Assessment: an online questionnaire reviewed by an independent IASME assessor. Valid 12 months.
- Level 2 – Audited: an independent assessor reviews documentation, interviews staff and observes activities (remote or on-site). Valid 3 years with an annual CE + L1 soft check.
The 14 themes across four areas
The standard is organised into four areas: Identify & Classify (assets, legal, risk, organisation, planning), Protect (physical, people, policy, access, intrusion, change), Deter & Detect (monitoring) and Respond & Recover (backup, resilience). Full breakdown: the 14 themes explained.
Cyber Essentials is the prerequisite
You cannot purchase or pass Cyber Assurance without a valid Cyber Essentials certificate that has at least 30 days remaining. If you don't already hold CE, you can buy it as a bundle. See the prerequisite rules.
What does it cost?
Level 1 is tiered by IASME at £320–£600 + VAT depending on size. Level 2 is quote-based depending on network size and complexity. Full breakdown: Cyber Assurance cost.
Who needs it?
Organisations bidding for contracts where governance maturity matters (NHS, financial services, larger enterprise supply chains), regulated firms wanting to evidence good information-handling, and SMEs that want a credible, affordable alternative to ISO 27001.
