help (at) seqmtraining.co.uk [ help (at) seqmtraining.co.uk ]

ISO 27001 vs Cyber Essentials: What’s the Difference?

The difference between ISO 27001 and Cyber Essentials is one of breadth against depth of a different kind. ISO/IEC 27001 is an international standard for building an information security management system covering people, processes and technology, certified through an accredited audit. Cyber Essentials is a UK government-backed scheme covering five prescribed technical controls, certified through a verified self-assessment. They are not competing certifications, and many organisations hold both.

Cybersecurity has become a board-level concern for organisations of every size, and buyers increasingly want proof rather than assurances. That is why ISO 27001 vs Cyber Essentials comes up so often when organisations decide how to demonstrate good security practice. This guide sets out what each certification covers, how the two compare on scope, cost and recognition, and how to decide which one your organisation needs. For background, see our introductions to ISO 27001 and to the information security management system it describes, along with a summary of the ISO 27001 requirements. If you are moving towards certification, our ISO 27001 training courses cover the standard at Foundation, Internal Auditor and Lead Auditor level.

What Is ISO 27001?

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS), published jointly by ISO and the International Electrotechnical Commission. The current edition is ISO/IEC 27001:2022.

Objectives. The standard protects the confidentiality, integrity and availability of information through a risk-based management system. Rather than prescribing a fixed list of measures, it requires an organisation to assess its own risks, decide how to treat them, and select controls that fit. Annex A provides 93 reference controls across four themes: organisational, people, physical and technological. Which of those apply, and why, is recorded in the Statement of Applicability.

Coverage. ISO 27001 reaches well beyond IT. It covers governance, leadership accountability, staff competence and awareness, supplier relationships, physical security, incident management and business continuity, alongside technical controls.

Typical organisations. Any organisation holding information that matters to someone else, with heaviest adoption in technology, financial services, healthcare, professional services and international supply chains.

Benefits. Global recognition in procurement and due diligence, a structured framework for managing security as the business changes, and independent assurance that carries weight with regulators, insurers and enterprise customers.

Certification. Certification is awarded by accredited certification bodies following a two-stage audit. It runs on a three-year cycle with annual surveillance audits, and the management system is expected to improve over that period rather than stand still.

What Is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme launched in 2014. The technical requirements are set by the National Cyber Security Centre (NCSC), and the scheme is administered on its behalf by the IASME Consortium through a network of licensed certification bodies.

Objective. To protect organisations against the most common internet-based attacks: the high-volume, low-sophistication attacks that use widely available tools against unpatched or poorly configured systems. It is deliberately a baseline rather than a comprehensive security programme.

The five technical controls. Every version of the scheme is built on the same five areas:

  • Firewalls – securing the boundary between your network and the internet
  • Secure configuration – removing default accounts, unnecessary software and weak settings
  • Security update management – keeping software and firmware patched
  • User access control – restricting privileges and authenticating users properly
  • Malware protection – defending devices against malicious software

Two levels. Cyber Essentials is assessed through a verified self-assessment questionnaire, reviewed by an assessor at a licensed certification body. Cyber Essentials Plus covers the same five controls but adds independent technical verification, including vulnerability scans of the scoped infrastructure and hands-on checks on a sample of devices.

Annual updates. The scheme is revised every year to keep pace with the threat landscape. The current requirements are version 3.3, paired with the Danzell question set, which replaced the previous Willow set in April 2026. The v3.3 changes centre on scope and clarity rather than new controls: cloud services now have a formal definition and a definitive statement that they cannot be excluded from scope, the user access control section highlights passwordless authentication methods such as passkeys, the application development section (previously called “web applications”) now references the UK Government’s Software Security Code of Practice, and the guidance on backing up data has been moved earlier in the requirements to emphasise its importance.

Two requirements catch organisations out more than any others. Authentication to cloud services must always use MFA, without the “where available” latitude that applies elsewhere. And updates must be applied within 14 days of release where the vendor describes the vulnerability as critical or high risk, where it carries a CVSS v3 base score of 7 or above, or where the vendor gives no severity detail at all. That last condition is easily missed, because it turns an absence of information into an obligation.

Certification. IASME publishes tiered fees based on organisation size, from £320 + VAT for a micro organisation of up to nine employees, rising to £600 + VAT for organisations of 250 or more. Cyber Essentials Plus is priced separately by the certification body according to scope and complexity, and typically runs into the low thousands. Certification lasts 12 months and must be renewed annually. Because the scheme is updated each year, recertification is not simply a matter of resubmitting last year’s answers.

ISO 27001 vs Cyber Essentials at a Glance

The table below summarises how ISO 27001 vs Cyber Essentials compare across the factors that usually drive the decision.

Feature ISO 27001 Cyber Essentials
Scope Information security management system Basic technical cybersecurity controls
Geography International Primarily UK
Approach Risk-based management system Prescriptive technical controls
Certification Accredited two-stage certification audit Verified self-assessment, or independent technical verification for Cyber Essentials Plus
Covers policies and governance Yes Limited
Covers technical controls Yes Yes
Recognised internationally Yes Primarily UK
Certification cycle Three years with annual surveillance audits Annual recertification
Indicative certification cost Varies by scope and certification body £320–£600 + VAT for Cyber Essentials; higher for Plus
Suitable for Organisations of all sizes needing a mature, internationally recognised system Organisations wanting a baseline level of cyber protection

Key Differences Between ISO 27001 and Cyber Essentials

Five areas account for most of what separates the two schemes in practice.

Purpose

ISO 27001 exists to build a management system: an ongoing set of processes for identifying information risk, deciding what to do about it, and improving over time. Cyber Essentials exists to close the specific technical gaps that common attacks exploit. One is a way of running the organisation; the other is a defined security floor.

Scope

ISO 27001 applies organisation-wide, to a scope the organisation defines and justifies. It covers information in every form, including paper records, staff knowledge and data held by suppliers. Cyber Essentials scopes to the technical IT environment: devices, networks, cloud services and the software running on them. Governance, training, supplier management and physical security fall largely outside it.

Risk Management

This is the most fundamental of the differences between ISO 27001 and Cyber Essentials. Under ISO 27001, the organisation identifies its own risks and selects controls proportionate to them, which means two certified organisations can have very different control sets and both be entirely compliant. Cyber Essentials makes no such judgement. The requirements are standardised and prescriptive, applying the same way regardless of what the organisation does. That is a strength for consistency and a limitation for organisations whose risks sit outside the five controls.

Certification Process

ISO 27001 certification involves a Stage 1 audit reviewing documentation and readiness, a Stage 2 audit testing the system in operation, and annual surveillance audits across a three-year cycle before recertification. Preparation commonly takes six to twelve months.

Cyber Essentials is a verified self-assessment questionnaire reviewed by an assessor, and certification can be issued within days for organisations that already meet the controls. Cyber Essentials Plus adds independent technical testing. Both levels require annual recertification.

The difference in effort is substantial, and so is the difference in what the certificate demonstrates.

International Recognition

ISO 27001 is recognised globally and is routinely requested in international tenders, enterprise vendor assessments and regulated sector due diligence. Cyber Essentials is recognised primarily within the UK, where it carries real weight in public sector procurement.

Procurement Policy Note 014 requires suppliers bidding for certain central government contracts to hold Cyber Essentials, with Cyber Essentials Plus expected where the cyber risk is higher. The requirement flows down through supply chains, so subcontractors to government primes are frequently asked for it too. For an organisation selling only into the UK public sector, Cyber Essentials may matter more day to day than ISO 27001. For an organisation selling internationally, the reverse is almost always true.

Similarities Between ISO 27001 and Cyber Essentials

ISO 27001 vs Cyber Essentials is often framed as a contest, but the two share a good deal of common ground. Both aim to:

  • Improve cybersecurity through controls that are tested rather than assumed
  • Reduce cyber risk, particularly exposure to attacks that succeed through basic weaknesses
  • Increase customer confidence by providing independent evidence rather than self-declaration
  • Demonstrate commitment to security to buyers, insurers and regulators
  • Support regulatory compliance, notably UK GDPR obligations around appropriate technical and organisational measures, though neither certification satisfies data protection law on its own
  • Encourage continual improvement, through surveillance audits in one case and annual scheme updates in the other

There is also meaningful technical overlap. The five Cyber Essentials controls map onto controls that appear in ISO 27001 Annex A, so an organisation that has implemented ISO 27001 thoroughly will usually find Cyber Essentials straightforward. The reverse does not hold: Cyber Essentials covers a small fraction of what ISO 27001 requires.

Which Organisations Should Choose ISO 27001?

ISO 27001 suits organisations that:

  • Handle sensitive personal, financial or commercially confidential information
  • Need an internationally recognised certification
  • Operate globally or sell across borders
  • Work in regulated industries where security assurance is scrutinised
  • Want a mature information security management system rather than a point-in-time check

In practice, that tends to mean financial services, healthcare providers and their suppliers, SaaS and cloud companies, professional services firms handling client data, and government suppliers operating beyond the baseline.

The deciding question is usually who is asking. If enterprise procurement teams, overseas clients or regulators are requesting evidence, ISO 27001 is generally what they have in mind.

Which Organisations Should Choose Cyber Essentials?

Cyber Essentials suits organisations that:

  • Want a straightforward cybersecurity baseline without building a management system
  • Bid for UK government contracts, or supply organisations that do
  • Need to reassure customers quickly and at modest cost
  • Have limited security maturity and want a clear starting point
  • Want to reduce exposure to the most common cyber attacks

For smaller organisations in particular, Cyber Essentials is often the sensible first step. It is achievable in weeks rather than months, the cost is predictable, and the five controls address the attacks most likely to cause real damage.

It is worth being clear about what it does not do. Cyber Essentials says nothing about whether staff are trained, whether suppliers are assessed, whether incidents are managed, or whether anyone has thought about the risks specific to your business. Those gaps are exactly what ISO 27001 addresses, which is why the choice between ISO 27001 or Cyber Essentials is often better framed as a question of sequence than of preference. A great many organisations certify to Cyber Essentials first and build towards ISO 27001 as the business grows.

Training for ISO 27001 and Cybersecurity Professionals

The two certifications differ in one respect that is easy to overlook: the professional pathway behind them. ISO 27001 has an established, internationally recognised auditor training route. Cyber Essentials does not have an equivalent. Assessors are trained and licensed by IASME to deliver the scheme, but there is no transferable international auditing qualification comparable to CQI and IRCA certified ISO 27001 training.

SEQM Training delivers CQI and IRCA certified ISO 27001 courses online at three levels.

ISO 27001 Foundation

The ISO 27001 Foundation Course covers the structure and intent of the standard, including how risk assessment, risk treatment and control selection fit together. It suits anyone contributing to an ISMS without a background in management systems.

ISO 27001 Internal Auditor

The ISO 27001 Internal Auditor Course develops the skills to plan and conduct internal audits, gather evidence and report findings. Internal audit is a requirement of the standard, and finding problems internally is considerably cheaper than having a certification body find them.

ISO 27001 Lead Auditor

The ISO 27001 Lead Auditor Course covers leading full certification audits, including planning, team management, sampling and reporting. It is the recognised route for those pursuing an auditing career or taking senior responsibility for an ISMS.

Frequently Asked Questions

Neither is better; they do different jobs. ISO 27001 is broader and more demanding, and carries more weight internationally. Cyber Essentials is faster, cheaper and specifically valuable for UK public sector work.

Yes, and many organisations do. They complement each other, and an existing ISO 27001 system usually makes Cyber Essentials straightforward to achieve.

Largely, but not automatically. The five Cyber Essentials controls map onto controls in ISO 27001 Annex A, but ISO 27001 lets organisations decide which controls are necessary. You still need to certify separately to hold a Cyber Essentials certificate.

Not in general law. It is mandatory for suppliers bidding for certain UK central government contracts under Procurement Policy Note 014, and requirements often flow down to subcontractors.

ISO 27001. It is recognised worldwide, whereas Cyber Essentials is a UK scheme recognised primarily within the UK.

Cyber Essentials lasts 12 months and must be renewed annually against that year’s requirements. ISO 27001 certification runs on a three-year cycle with annual surveillance audits.