Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Cyber Essentials vs ISO 27001 explained

Cyber Essentials vs ISO 27001: 10 Clear Differences (2026)

Cyber Essentials vs ISO 27001 is a comparison between a five-control technical baseline and a whole management system, and the two answer different questions. Cyber Essentials, the UK government-backed scheme run by the NCSC and delivered by IASME, asks whether five specific technical controls — firewalls, secure configuration, security update management, user access control and malware protection — are in place across a defined scope, verified by a self-assessment reviewed by an assessor (or, for Plus, by a technical audit).

ISO/IEC 27001:2022 asks whether the organisation runs a risk-based information security management system: scope, leadership, risk assessment and treatment, a Statement of Applicability against 93 Annex A controls, internal audit, management review and continual improvement, certified by an accredited body on a three-year cycle. This guide compares the two on ten points, sets out who needs which — and who needs both — and shows how a Cyber Essentials certificate maps onto an ISO 27001 programme so the second is built on the first rather than beside it.

Cyber Essentials vs ISO 27001: baseline vs management system
Cyber Essentials: 5 technical controls, verified self-assessment (or Plus audit), 12-month certificate, £320–600 IASME fee. ISO 27001: risk-based ISMS, 93 Annex A controls via the SoA, accredited certification, 3-year cycle.

Cyber Essentials vs ISO 27001 at a glance

Cyber Essentials (and Plus) ISO/IEC 27001:2022
What it is A UK scheme defining five technical controls against internet-based attack An international standard for an information security management system
Who runs it NCSC; delivered by IASME as the single delivery partner ISO/IEC; certification by accredited certification bodies worldwide
Controls Five: firewalls, secure configuration, security update management, user access control, malware protection — Requirements for IT Infrastructure v3.3 (April 2026) Whatever the risk assessment justifies, selected from 93 Annex A controls in four themes and recorded in the Statement of Applicability
Method Prescriptive: the requirements say what to do (patch critical fixes within 14 days; MFA on cloud services; 12-character passwords or 8 with a deny list) Risk-based: the organisation decides what to do and must justify it
Assessment Verified self-assessment marked by an IASME-licensed assessor; Plus adds an independent technical audit with device sampling and vulnerability scanning Stage 1 and stage 2 audit by an accredited certification body, then annual surveillance and recertification in year three
Validity 12 months; renewal is a fresh assessment Three years, subject to surveillance
Typical cost £320–600 plus VAT IASME fee by size band; Plus quoted, commonly £1,200–4,250 plus VAT Certification fees from a few thousand pounds for a small scope to tens of thousands; implementation is the larger cost
Evidence produced A certificate and, if eligible, £25,000 of cyber liability insurance A certificate, the SoA, and an auditable management system
Geography UK-centred; required in UK public procurement under PPN 014 for higher-risk contracts Global; the default security certification in supplier due diligence
Coverage Technical hygiene against commodity internet attack People, process, physical and technological controls, governance and improvement

Cyber Essentials vs ISO 27001 on parameters: what the scheme fixes

ISO 27001 does not tell you how quickly to patch, how long a password must be or whether an administrator may browse the web from a privileged account; it tells you to assess the risk and select controls, and Annex A controls such as 8.8 (management of technical vulnerabilities) and 8.5 (secure authentication) leave the parameters to the organisation.

Cyber Essentials fixes them: critical and high-risk updates (CVSS v3 base score 7 or above) within 14 days; MFA always on cloud services; separate accounts for administration; unsupported software removed or segregated from the internet by a defined sub-set; device lockout after no more than 10 failed attempts. An ISO 27001-certified organisation can fail Cyber Essentials on any of those, and a surprising number do — usually on patching or an unsupported operating system inside scope. Our guide to the Cyber Essentials questionnaire covers the auto-fail conditions.

What ISO 27001 covers that Cyber Essentials does not

  • Risk. Cyber Essentials has no risk assessment; the same five controls apply to every organisation. ISO 27001 clauses 6.1.2 and 6.1.3 make the risk assessment and treatment plan the engine of the system.
  • People and process controls. Screening, awareness, supplier security, incident management, business continuity, logging and monitoring, secure development — 37 organisational and 8 people controls in Annex A with no Cyber Essentials counterpart.
  • Governance. Leadership commitment, roles, objectives, competence, internal audit, management review, corrective action — clauses 5 to 10.
  • Physical security. 14 Annex A physical controls; Cyber Essentials treats a stolen laptop as a device-configuration question, not a premises one.
  • Insider and non-internet threats. Cyber Essentials is explicit that it addresses attacks from the internet; ISO 27001 addresses whatever the risk assessment finds.

Cyber Essentials vs ISO 27001: who needs which

Situation Get Why
UK organisation bidding for central government contracts involving personal data or IT services Cyber Essentials (often Plus) PPN 014 requires it for in-scope contracts; a small organisation can hold it within weeks
Supplier to enterprise or international customers whose questionnaires ask for a security certification ISO 27001 Cyber Essentials is rarely recognised outside the UK and does not answer the governance questions
Small UK business with no current certification and limited budget Cyber Essentials first The five controls stop most commodity attacks, the fee is fixed and small, and the certificate is quick
Organisation building an ISO 27001 ISMS in the UK Both Cyber Essentials verifies the technical baseline the ISMS’s risk treatment relies on, annually and cheaply
Regulated or high-assurance environment (NIS regulations, financial services, health) ISO 27001, with Cyber Essentials Plus as a floor Regulators expect risk-based governance; Plus proves the basics are actually implemented on the devices
Organisation asked for ‘certification’ by a customer without saying which Ask The two are not interchangeable and buying the wrong one wastes a year

Cyber Essentials vs ISO 27001 as a sequence: building the ISMS on the certificate

Because the five controls map onto specific Annex A controls, a Cyber Essentials certificate is evidence in an ISO 27001 programme rather than a parallel effort.

Cyber Essentials control ISO 27001:2022 Annex A controls it evidences What the ISMS adds
Firewalls 8.20 Networks security; 8.21 Security of network services; 8.22 Segregation of networks Network architecture decisions from risk; monitoring of the rules
Secure configuration 8.9 Configuration management; 8.19 Installation of software on operational systems; 8.7 Protection against malware (partly) Baselines under change control; hardening standards per platform
Security update management 8.8 Management of technical vulnerabilities Vulnerability scanning cadence, risk-rated exceptions, supplier patch obligations
User access control 5.15 Access control; 5.16 Identity management; 5.17 Authentication information; 5.18 Access rights; 8.2 Privileged access rights; 8.5 Secure authentication Joiner-mover-leaver process, access reviews, the policy behind the MFA setting
Malware protection 8.7 Protection against malware Logging, incident response when it triggers, awareness

The reverse is also useful: an organisation with ISO 27001 should run the Cyber Essentials question set as an annual check that its technical controls meet the scheme’s parameters, because an ISMS can be certified with a 30-day patch policy that Cyber Essentials would fail. Our guides to Cyber Essentials certification and ISO 27001 certification cover each route; ISO 27001 vs SOC 2 covers the other comparison UK suppliers are asked to make.

Frequently asked questions

What is the difference in Cyber Essentials vs ISO 27001?
Cyber Essentials is a UK scheme verifying five prescribed technical controls against internet-based attack, renewed annually for a fixed fee. ISO 27001 is an international standard for a risk-based information security management system with governance, people, physical and technical controls, certified by accredited bodies on a three-year cycle.

Does ISO 27001 include Cyber Essentials?
Not automatically. ISO 27001 leaves parameters such as patch timescales and password rules to the organisation’s risk assessment; Cyber Essentials fixes them. An ISO 27001-certified organisation can fail Cyber Essentials on an unsupported operating system or a 30-day patch cycle.

Which is cheaper?
Cyber Essentials by a wide margin: £320–600 plus VAT for the IASME fee, with Plus quoted separately. ISO 27001 certification runs to thousands in audit fees and the implementation effort is larger still.

Which should a small UK company do first?
Cyber Essentials, unless a customer specifically requires ISO 27001. It is quick, cheap, unblocks UK public-sector tenders under PPN 014, and its five controls are the technical foundation an ISMS later relies on.

Is Cyber Essentials recognised outside the UK?
Rarely. International customers ask for ISO 27001 or SOC 2. Cyber Essentials is the right answer to a UK procurement requirement and a sensible baseline anywhere, but it is not a substitute for ISO 27001 in global supplier due diligence.

Where this leaves you

Treat Cyber Essentials vs ISO 27001 as a sequence rather than a choice: certify the five technical controls first if you are in the UK, because they are cheap, fast and required for public-sector work; build the ISO 27001 management system when customers, regulators or your own risk picture demand governance, people and physical controls; and keep the annual Cyber Essentials check running underneath the ISMS, because the standard that lets you choose your patch window is not the one that will catch you missing it.

References

More on Cyber Essentials

The scope definition, the five control policies, the asset inventory and the evidence records that carry an organisation through the Cyber Essentials assessment — and give an ISO 27001 programme its technical baseline — are in the Cyber Essentials UK Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.