IASME Cyber Assurance Level 1 vs Level 2: which route fits your situation.
Both levels sit within the same IASME Cyber Assurance framework and cover the same control themes. The difference is how assurance is established — and what that means for the buyers, procurement teams or supply chains that will rely on your certificate.
The core difference in one sentence.
Level 1 asks: have you described your controls correctly? Level 2 asks: are your controls genuinely operating in practice?
| Level 1 — Verified | Level 2 — Audited | |
|---|---|---|
| Assessment method | Verified self-assessment questionnaire | Independent audit by qualified assessor |
| What is tested | Whether controls are described accurately | Whether controls are operating in practice |
| Control themes | CE technical controls + risk, policies, suppliers | Same — plus evidence that each area is live |
| Preparation effort | Moderate — controls must be in place and documented | Higher — evidence that controls operate consistently |
| Best for | Buyers needing broader governance than CE alone | Public sector, higher-trust procurement, supply chain scrutiny |
| Renewal | Annual | Annual |
When Level 1 is the right route.
Level 1 is appropriate when the commercial requirement is for governance assurance beyond the five Cyber Essentials technical controls — covering policies, risk management and supplier oversight — but where an independent audit is not specifically required. Many organisations use Level 1 as a stepping stone after achieving Cyber Essentials, to demonstrate a broader governance position before the commercial environment demands full audited assurance.
When Level 2 becomes necessary.
Level 2 is appropriate when buyers, procurement frameworks, public-sector contracts or supply-chain requirements ask for independently evidenced assurance — not just a self-described position. The certificate carries more commercial weight because an external assessor has tested whether the declared controls are actually operating. Organisations bidding for government contracts, entering regulated supply chains or dealing with enterprise procurement teams that conduct due diligence will typically need Level 2.
Can you go from Level 1 to Level 2, or skip straight to Level 2?
Both routes are valid. Organisations that already hold Level 1 have done most of the foundational work — the gap to Level 2 is usually about strengthening evidence and preparing for audit conditions rather than building new controls. Organisations that have not previously gone through the IASME framework can go directly to Level 2. The preparation effort is higher than for Level 1, but the commercial outcome is stronger.
Does Level 2 include everything in Level 1?
Yes. Level 2 covers the same control themes as Level 1 — the five Cyber Essentials technical controls plus the broader governance areas including risk, policies and supplier oversight. The additional requirement is independent audit testing that those controls are genuinely operating.
Is Level 1 still a credible certification?
Yes. Level 1 provides meaningful assurance that an organisation has the right governance framework in place and has verified it accurately. For many commercial situations it is the appropriate and proportionate route. The decision to pursue Level 2 should be driven by what buyers and contracts actually require.
How does IASME Cyber Assurance Level 2 compare to ISO 27001?
Both involve independent assessment and both cover governance beyond technical controls. ISO 27001 is a more comprehensive management system standard, involves a more involved certification process and is the appropriate route where enterprise buyers or regulators specify it. Level 2 is generally more accessible and faster to achieve while still providing a credible audited position for most SME commercial environments.
The right route depends on what your buyers actually require.
YDC helps organisations identify the most proportionate route and prepare for it properly — without overbuilding or choosing the wrong option.