Cyber Assurance
Level Two.
Move beyond self-assessment. IASME Cyber Assurance Level Two provides independent, expert auditing of your security controls, offering the ultimate proof of compliance to your supply chain and enterprise clients.
From Self-Declared to Independently Verified.
Level One acts as a foundational baseline. To achieve Level Two, a certified IASME Assessor must independently verify that the controls and policies you declared are actively functioning in reality.
Self-Assessed
You declare your compliance through a comprehensive questionnaire covering 13 security themes.
- Self-reported compliance
- Management sign-off
- Policy creation
- Questionnaire submission
Audited & Verified
An official assessor examines physical evidence, reviews logs, and conducts interviews to prove compliance.
- Independent assessor review
- Evidence sampling & logs
- Staff operational interviews
- Physical or remote site checks
Inside the Assessor's Clipboard.
Level Two is an evidence-based audit. Here is a breakdown of exactly what the assessor will require from your organization to grant certification.
Document Reviews
The assessor will review your formally documented Information Security Management policies. This includes checking incident response plans, data privacy (GDPR) frameworks, risk registers, and business continuity procedures.
System & Log Sampling
Auditors require technical proof that policies are enforced. They will sample firewall configurations, request endpoint anti-malware logs, verify backup schedules, and check active directory configurations for secure access controls.
Staff Interviews
Policies are useless if staff do not follow them. The assessor will conduct brief, remote interviews with key personnel (such as HR, IT, and general staff) to verify they understand data handling procedures and incident reporting.
Site Inspections
Whether conducted in-person or via secure remote video, the assessor will verify physical security controls. This includes checking office access controls, visitor logging, clean desk policies, and server room security.
IASME & Certification - Practical guidance for a more secure business
Small Business Compliance: GDPR & Cyber Essentials
How SMEs can navigate UK Cyber Essentials, Cyber Essentials Plus, and IASME Cyber Assurance standards smoothly with certified assessor guidance.
Read full briefing →A Beginner’s Guide to Security Awareness & Verification
Building strong human defences and technical controls required to satisfy government and defence supply chain certification audits.
Read full briefing →GDPR Compliance for SMEs: A Practical 90-Day Roadmap
A step-by-step 90-day framework to build audit-ready GDPR compliance, data mapping, and evidence controls without operational overhead.
Read full briefing →Why Modern Businesses Need Continuous Cyber Protection
One-off assessments are no longer enough. Here is why continuous cyber protection has become the baseline for organisations serious about security.
Read full briefing →Ready to schedule your Level Two Audit?
Talk to our official IASME assessors about upgrading from Level One, preparing your evidence, and booking your formal assessment.
Book Your Audit → info@worldcomputing.co.uk