Cyber Essentials vs ISO 27001 is a comparison between a five-control technical baseline and a whole management system, and the two answer different questions. Cyber Essentials, the UK government-backed scheme run by the NCSC and delivered by IASME, asks whether five specific technical controls — firewalls, secure configuration, security update management, user access control and malware protection — are in place across a defined scope, verified by a self-assessment reviewed by an assessor (or, for Plus, by a technical audit).
ISO/IEC 27001:2022 asks whether the organisation runs a risk-based information security management system: scope, leadership, risk assessment and treatment, a Statement of Applicability against 93 Annex A controls, internal audit, management review and continual improvement, certified by an accredited body on a three-year cycle. This guide compares the two on ten points, sets out who needs which — and who needs both — and shows how a Cyber Essentials certificate maps onto an ISO 27001 programme so the second is built on the first rather than beside it.

Cyber Essentials vs ISO 27001 at a glance
| Cyber Essentials (and Plus) | ISO/IEC 27001:2022 | |
|---|---|---|
| What it is | A UK scheme defining five technical controls against internet-based attack | An international standard for an information security management system |
| Who runs it | NCSC; delivered by IASME as the single delivery partner | ISO/IEC; certification by accredited certification bodies worldwide |
| Controls | Five: firewalls, secure configuration, security update management, user access control, malware protection — Requirements for IT Infrastructure v3.3 (April 2026) | Whatever the risk assessment justifies, selected from 93 Annex A controls in four themes and recorded in the Statement of Applicability |
| Method | Prescriptive: the requirements say what to do (patch critical fixes within 14 days; MFA on cloud services; 12-character passwords or 8 with a deny list) | Risk-based: the organisation decides what to do and must justify it |
| Assessment | Verified self-assessment marked by an IASME-licensed assessor; Plus adds an independent technical audit with device sampling and vulnerability scanning | Stage 1 and stage 2 audit by an accredited certification body, then annual surveillance and recertification in year three |
| Validity | 12 months; renewal is a fresh assessment | Three years, subject to surveillance |
| Typical cost | £320–600 plus VAT IASME fee by size band; Plus quoted, commonly £1,200–4,250 plus VAT | Certification fees from a few thousand pounds for a small scope to tens of thousands; implementation is the larger cost |
| Evidence produced | A certificate and, if eligible, £25,000 of cyber liability insurance | A certificate, the SoA, and an auditable management system |
| Geography | UK-centred; required in UK public procurement under PPN 014 for higher-risk contracts | Global; the default security certification in supplier due diligence |
| Coverage | Technical hygiene against commodity internet attack | People, process, physical and technological controls, governance and improvement |
Cyber Essentials vs ISO 27001 on parameters: what the scheme fixes
ISO 27001 does not tell you how quickly to patch, how long a password must be or whether an administrator may browse the web from a privileged account; it tells you to assess the risk and select controls, and Annex A controls such as 8.8 (management of technical vulnerabilities) and 8.5 (secure authentication) leave the parameters to the organisation.
Cyber Essentials fixes them: critical and high-risk updates (CVSS v3 base score 7 or above) within 14 days; MFA always on cloud services; separate accounts for administration; unsupported software removed or segregated from the internet by a defined sub-set; device lockout after no more than 10 failed attempts. An ISO 27001-certified organisation can fail Cyber Essentials on any of those, and a surprising number do — usually on patching or an unsupported operating system inside scope. Our guide to the Cyber Essentials questionnaire covers the auto-fail conditions.
What ISO 27001 covers that Cyber Essentials does not
- Risk. Cyber Essentials has no risk assessment; the same five controls apply to every organisation. ISO 27001 clauses 6.1.2 and 6.1.3 make the risk assessment and treatment plan the engine of the system.
- People and process controls. Screening, awareness, supplier security, incident management, business continuity, logging and monitoring, secure development — 37 organisational and 8 people controls in Annex A with no Cyber Essentials counterpart.
- Governance. Leadership commitment, roles, objectives, competence, internal audit, management review, corrective action — clauses 5 to 10.
- Physical security. 14 Annex A physical controls; Cyber Essentials treats a stolen laptop as a device-configuration question, not a premises one.
- Insider and non-internet threats. Cyber Essentials is explicit that it addresses attacks from the internet; ISO 27001 addresses whatever the risk assessment finds.
Cyber Essentials vs ISO 27001: who needs which
| Situation | Get | Why |
|---|---|---|
| UK organisation bidding for central government contracts involving personal data or IT services | Cyber Essentials (often Plus) | PPN 014 requires it for in-scope contracts; a small organisation can hold it within weeks |
| Supplier to enterprise or international customers whose questionnaires ask for a security certification | ISO 27001 | Cyber Essentials is rarely recognised outside the UK and does not answer the governance questions |
| Small UK business with no current certification and limited budget | Cyber Essentials first | The five controls stop most commodity attacks, the fee is fixed and small, and the certificate is quick |
| Organisation building an ISO 27001 ISMS in the UK | Both | Cyber Essentials verifies the technical baseline the ISMS’s risk treatment relies on, annually and cheaply |
| Regulated or high-assurance environment (NIS regulations, financial services, health) | ISO 27001, with Cyber Essentials Plus as a floor | Regulators expect risk-based governance; Plus proves the basics are actually implemented on the devices |
| Organisation asked for ‘certification’ by a customer without saying which | Ask | The two are not interchangeable and buying the wrong one wastes a year |
Cyber Essentials vs ISO 27001 as a sequence: building the ISMS on the certificate
Because the five controls map onto specific Annex A controls, a Cyber Essentials certificate is evidence in an ISO 27001 programme rather than a parallel effort.
| Cyber Essentials control | ISO 27001:2022 Annex A controls it evidences | What the ISMS adds |
|---|---|---|
| Firewalls | 8.20 Networks security; 8.21 Security of network services; 8.22 Segregation of networks | Network architecture decisions from risk; monitoring of the rules |
| Secure configuration | 8.9 Configuration management; 8.19 Installation of software on operational systems; 8.7 Protection against malware (partly) | Baselines under change control; hardening standards per platform |
| Security update management | 8.8 Management of technical vulnerabilities | Vulnerability scanning cadence, risk-rated exceptions, supplier patch obligations |
| User access control | 5.15 Access control; 5.16 Identity management; 5.17 Authentication information; 5.18 Access rights; 8.2 Privileged access rights; 8.5 Secure authentication | Joiner-mover-leaver process, access reviews, the policy behind the MFA setting |
| Malware protection | 8.7 Protection against malware | Logging, incident response when it triggers, awareness |
The reverse is also useful: an organisation with ISO 27001 should run the Cyber Essentials question set as an annual check that its technical controls meet the scheme’s parameters, because an ISMS can be certified with a 30-day patch policy that Cyber Essentials would fail. Our guides to Cyber Essentials certification and ISO 27001 certification cover each route; ISO 27001 vs SOC 2 covers the other comparison UK suppliers are asked to make.
Frequently asked questions
What is the difference in Cyber Essentials vs ISO 27001?
Cyber Essentials is a UK scheme verifying five prescribed technical controls against internet-based attack, renewed annually for a fixed fee. ISO 27001 is an international standard for a risk-based information security management system with governance, people, physical and technical controls, certified by accredited bodies on a three-year cycle.
Does ISO 27001 include Cyber Essentials?
Not automatically. ISO 27001 leaves parameters such as patch timescales and password rules to the organisation’s risk assessment; Cyber Essentials fixes them. An ISO 27001-certified organisation can fail Cyber Essentials on an unsupported operating system or a 30-day patch cycle.
Which is cheaper?
Cyber Essentials by a wide margin: £320–600 plus VAT for the IASME fee, with Plus quoted separately. ISO 27001 certification runs to thousands in audit fees and the implementation effort is larger still.
Which should a small UK company do first?
Cyber Essentials, unless a customer specifically requires ISO 27001. It is quick, cheap, unblocks UK public-sector tenders under PPN 014, and its five controls are the technical foundation an ISMS later relies on.
Is Cyber Essentials recognised outside the UK?
Rarely. International customers ask for ISO 27001 or SOC 2. Cyber Essentials is the right answer to a UK procurement requirement and a sensible baseline anywhere, but it is not a substitute for ISO 27001 in global supplier due diligence.
Where this leaves you
Treat Cyber Essentials vs ISO 27001 as a sequence rather than a choice: certify the five technical controls first if you are in the UK, because they are cheap, fast and required for public-sector work; build the ISO 27001 management system when customers, regulators or your own risk picture demand governance, people and physical controls; and keep the annual Cyber Essentials check running underneath the ISMS, because the standard that lets you choose your patch window is not the one that will catch you missing it.
References
- NCSC — Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026) — The five controls, the scope rules and the parameters (14 days, MFA, password lengths).
- NCSC — Cyber Essentials overview — The scheme, the two levels and the IASME delivery model.
- ISO/IEC 27001:2022 — Information security management systems — Requirements — The ISMS requirements and Annex A.
- GOV.UK — PPN 014: Cyber Essentials scheme — When UK public bodies must require Cyber Essentials from suppliers.
More on Cyber Essentials
- Cyber Essentials vs ISO 27001 — you are here
- Cyber Essentials certification: the complete guide
- Cyber Essentials Plus: what the audit adds
- Cyber Essentials cost in 2026
- Cyber Essentials requirements: the five controls
- Cyber Essentials scope: whole organisation or sub-set
The scope definition, the five control policies, the asset inventory and the evidence records that carry an organisation through the Cyber Essentials assessment — and give an ISO 27001 programme its technical baseline — are in the Cyber Essentials UK Toolkit, or start with the free templates.