Cyber Essentials vs ISO 27001
One is a UK government baseline built on five technical controls. The other is an internationally certified management system for all of your information. Here is how they differ, who asks for which, and how to hold both without doing the work twice.

The short answer: Cyber Essentials is a UK government-backed scheme that checks five technical controls, either by self-assessment or with hands-on testing at the Plus level. ISO 27001 is an international standard for a full information security management system (ISMS), certified by an external auditor. If a UK public-sector contract names Cyber Essentials, you need Cyber Essentials. If enterprise buyers, international customers or tenders ask for evidence of how you manage security risk, you need ISO 27001. Many UK firms hold both.
The question comes up more than it used to. Procurement teams have got stricter, cyber insurers ask harder questions at renewal, and buyers now expect a certificate rather than a promise. Choosing the wrong one wastes a budget cycle. Choosing neither costs you the deal.
{{snapshot}}
Cyber Essentials vs ISO 27001 at a glance
- Cyber Essentials is UK-only, run by the NCSC and delivered through IASME. Two levels: self-assessed Cyber Essentials and independently tested Cyber Essentials Plus.
- ISO 27001 is the international ISMS standard (ISO/IEC 27001:2022), certified by an accredited certification body on a three-year cycle with annual surveillance audits.
- Scope is the real difference: five technical controls versus a risk-based system covering people, process, physical and technical security.
- Who asks decides it: UK central government and MoD supply chains ask for Cyber Essentials; enterprise, financial services and international buyers ask for ISO 27001.
- Holding both is normal for MSPs, consultancies and anyone selling into both the public sector and enterprise.
{{/snapshot}}
What Cyber Essentials actually covers
Cyber Essentials is a certification scheme, not a management standard. It was launched by the UK government in 2014 and is now run by the National Cyber Security Centre, with IASME as the sole delivery partner. The point of it is narrow and deliberate: make sure an organisation has the basic technical hygiene that stops the bulk of opportunistic attacks. The NCSC's own line is that the controls defend against the most common internet-based threats.
There are five technical controls, and the assessment is about whether they are in place across your in-scope devices, networks and cloud services:
- Firewalls on the boundary and on devices, with inbound rules justified.
- Secure configuration, including removing default accounts and unnecessary software.
- Security update management, with high-risk patches applied within 14 days of release.
- User access control, including least privilege, separate admin accounts and multi-factor authentication for cloud services.
- Malware protection on every in-scope device.
The two levels differ in how you prove it. Cyber Essentials is a self-assessment questionnaire, signed off by a board member and reviewed by an assessor. Cyber Essentials Plus is the same control set, but an assessor tests it: vulnerability scans, checks on a sample of devices, and tests of how your systems handle malicious email attachments and downloads. Plus has to be completed within three months of the basic certificate. Both are valid for 12 months and then you recertify.
It is fast and it is cheap relative to any ISO standard. A prepared small business can complete the basic self-assessment in days. That is the appeal, and it is also the limit. Cyber Essentials does not ask you to identify your information assets, assess risk, write policies, train people, manage suppliers or plan for incidents. It checks the locks on the doors. It does not ask what is in the building or who has a key. Read the NCSC's scheme overview for the official scope.
What ISO 27001 covers that Cyber Essentials does not
ISO 27001 sets requirements for an information security management system. You define the scope of the ISMS, identify the information you hold and the assets it lives on, assess the risks to it, decide how to treat those risks, and then run the whole thing as an ongoing system with leadership involvement, internal audits and management review. Clauses 4 to 10 of the standard describe that system. Annex A of the 2022 edition lists 93 controls across four themes: organisational, people, physical and technological. You justify which apply in a Statement of Applicability rather than implementing all of them blindly.
Certification is external. A UKAS-accredited certification body runs a stage 1 audit of your documentation and a stage 2 audit of the ISMS in operation. The certificate runs on a three-year cycle with surveillance audits each year in between. Nobody signs a questionnaire and posts it off. The certification hub walks through the audit stages in detail.
The consequence is that ISO 27001 answers a different question. Cyber Essentials tells a buyer that your devices are patched and your admins use MFA. ISO 27001 tells a buyer that you know what data you hold, you have thought about what could go wrong, and someone senior is accountable for keeping it that way. Enterprise security questionnaires, financial services due diligence and most international tenders are asking the second question. That is why they name ISO 27001, and why a Cyber Essentials certificate on its own rarely closes that conversation.
Cyber Essentials vs ISO 27001 side by side
| Aspect | Cyber Essentials / Cyber Essentials Plus | ISO 27001 |
|---|---|---|
| What it is | UK government-backed certification of five technical controls | International standard for an information security management system |
| Run by | NCSC, delivered by IASME and its certification bodies | ISO/IEC; certification by accredited bodies (UKAS in the UK) |
| Scope | Devices, networks and cloud services in scope; technical controls only | People, process, physical and technical security for the whole ISMS scope |
| How you are assessed | Self-assessment questionnaire (CE) or on-site and remote technical testing (CE Plus) | Stage 1 and stage 2 external audits, then annual surveillance audits |
| Risk assessment required | No | Yes, and it drives which controls you implement |
| Validity | 12 months | Three-year certificate with annual surveillance |
| Typical effort | Days to a few weeks for a prepared small organisation | Typically two to three months to audit-ready with a platform; longer on spreadsheets |
| Recognised | UK; a named requirement in many UK public-sector and MoD contracts | Internationally; standard ask in enterprise, financial services and cross-border tenders |
| Cyber insurance | Basic cyber liability cover included for eligible smaller UK organisations | Not bundled, but insurers often ask about it at renewal |
The row that matters most is risk assessment required. Everything else follows from it. Because Cyber Essentials fixes the control set in advance, it can be quick and cheap. Because ISO 27001 makes you derive the controls from your own risks, it takes longer and means more, and it is why the Annex A controls look like a menu rather than a checklist.
Which one do you need?
Work backwards from who is asking, then from what you sell.
You sell to UK central government, the NHS supply chain or the MoD. Cyber Essentials is a stated requirement in many of those contracts, and often Cyber Essentials Plus for anything sensitive. An ISO 27001 certificate does not automatically satisfy a clause that names Cyber Essentials, so get the badge the contract asks for. If the same contracts also involve personal data at scale or critical services, expect ISO 27001 to appear further along.
You sell to enterprises, regulated firms or international customers. Their procurement and security teams will send you a questionnaire, and ISO 27001 is the answer that ends it fastest. Cyber Essentials will get you polite credit and a request for more. This is the pattern for SaaS vendors, fintechs and consultancies. Our page on ISO 27001 for consulting firms covers the client-driven version of that pressure.
You are small, and nobody has asked yet. Start with Cyber Essentials. It is the cheapest way to close the obvious gaps, it comes with basic cyber insurance for eligible organisations, and it makes the ISO 27001 conversation easier when it arrives. When it does arrive, ISO 27001 for small businesses explains how to scope it so it stays proportionate.
You are an MSP or IT provider. Hold both. Your public-sector clients want Cyber Essentials Plus because their contracts demand it, and your larger clients want ISO 27001 because you sit inside their supply chain risk. See ISO 27001 for managed service providers for how the standard lands when you run other people's infrastructure.
Still unsure, or juggling more than two frameworks? The compliance framework selector maps who you sell to against what they usually require.
Cyber Essentials Plus vs ISO 27001: is Plus enough?
This is the version of the question we hear most from firms that already hold Cyber Essentials Plus and have just been asked for ISO 27001. The honest answer: Plus is a deeper test of the same five controls, and nothing more than that. The assessor proves your patching, configuration, access control and malware protection actually work, which is valuable, but the scope has not moved. There is still no risk register, no policy set, no supplier review, no incident process, no management review.
So if a buyer asks for ISO 27001, Cyber Essentials Plus will not substitute, and arguing that it should tends to slow the deal rather than save it. What Plus does give you is a head start. The technical evidence you gathered for it maps directly onto several of ISO 27001's technological controls, and the discipline of annual re-testing is exactly the operating rhythm ISO 27001 expects. You are further along than you think, just not finished.
Holding both without doing the work twice
The five Cyber Essentials controls sit comfortably inside ISO 27001's Annex A. Firewalls, secure configuration, patching, access control and malware protection all correspond to technological controls in the 2022 edition. That means an ISO 27001 ISMS with sensible scoping will already produce the evidence Cyber Essentials asks for. The reverse is not true, but the overlap is the point: build the ISMS once and let both certificates draw from it. Our guide to transferable compliance goes deeper on reusing controls across standards.
Advantex, a UK IT and communications integrator, is the usual shape of this. They held ISO 9001 and Cyber Essentials Plus, then added ISO 27001 and ISO 14001. Running the frameworks on one platform cut their audit preparation time by 30 to 40 percent, according to managing director Dave O'Connell. The Advantex case study has the detail. The platform did not do the work for them. What changed is that they stopped keeping four separate versions of the same evidence.
Practically, that means one control library with each control mapped to every framework it satisfies, policy templates already linked to those controls, and evidence collected once and attached wherever it applies. That is how Hicomply is built, and it is why we tell customers that what they build for ISO 27001 powers SOC 2 and whatever comes next. The platform tour shows the mapping in action, and the plans page is public if you want to price it against a consultant day rate.
{{snapshot}}
Hicomply's take
We have watched too many firms treat Cyber Essentials and ISO 27001 as a choice when the buyer had already made it for them. Read your contracts and your questionnaires first; the answer is usually written down. If you are small and nobody is asking, do Cyber Essentials this quarter and stop worrying. If a serious buyer wants ISO 27001, do not try to negotiate them down to Cyber Essentials Plus, because you will lose the month and probably the deal. And whichever you start with, keep the evidence somewhere it can be reused. Picking the wrong standard is rare. Picking one and then rebuilding everything from scratch for the second is the mistake we actually see.
{{/snapshot}}
Get from Cyber Essentials to ISO 27001 without a second spreadsheet
If Cyber Essentials was your first certificate and ISO 27001 is the next request in your inbox, the work you have already done counts. Hicomply maps your existing controls and evidence into an ISMS, gives you the policies and risk register the auditor will ask for, and keeps both certifications maintained year-round instead of rebuilt at renewal. Customers starting from nothing typically reach audit-ready in two to three months.
Book a demo to see how your Cyber Essentials evidence maps across, or run the ISO 27001 cost calculator first to see what the step up actually costs.
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.






