Cyber Essentials vs ISO 27001: which do you need?

7 min read · Updated

Cyber Essentials proves you have five basic technical protections in place. ISO 27001 proves you run a whole system for managing information security risk across the business. Cyber Essentials is quicker and cheaper, and is often the minimum for UK public-sector work. ISO 27001 takes months, costs more, and is what larger customers and many tenders ask for when they want real assurance.

If you're not sure which you need, ask the customer or read the tender wording. If it says "ISO 27001", Cyber Essentials won't do instead. If it says "Cyber Essentials", ISO 27001 alone may not tick the box either.

At a glance

Cyber Essentials ISO 27001
What it is A UK government-backed scheme, run by the NCSC with IASME An international standard for an information security management system (ISMS)
What it covers Five technical controls on your IT Your whole approach to information risk: people, process, suppliers, technology
How you get it Online self-assessment, checked by a certification body (Plus adds a hands-on technical audit) Two-stage audit by an accredited certification body (UKAS in the UK)
How long it takes Days to a few weeks Usually several months
How long it lasts 12 months 3 years, with yearly surveillance audits
Typical cost (2026) Roughly £320–£600 + VAT for the basic assessment, by organisation size Roughly £3,500–£10,000+ for the first audit for a small business, plus your time
Who asks for it UK government contracts, public-sector supply chains, insurers Larger customers, enterprise procurement, international buyers, many tenders

What Cyber Essentials checks

Cyber Essentials covers five technical areas:

  1. Firewalls protecting your internet connection and devices.
  2. Secure configuration: removing default passwords and unnecessary software.
  3. User access control: the right accounts with the right rights, and multi-factor authentication for cloud services.
  4. Malware protection on devices.
  5. Security update management: applying critical and high-risk patches quickly.

You answer an online questionnaire, a director signs it off, and an assessor reviews it. Cyber Essentials Plus adds a technical audit where an assessor tests a sample of your devices. Both have to be renewed every year.

It's a good baseline: it blocks a large share of common attacks. But it doesn't ask about your suppliers, your incident response, your risk decisions or whether your staff are trained.

What ISO 27001 checks

ISO 27001 asks you to build and run an ISMS. In practice that means:

  • A defined scope: which parts of the business, sites and systems are covered.
  • A risk assessment and treatment plan: what could go wrong with your information, and what you've decided to do about it.
  • A Statement of Applicability: for each of the 93 controls in Annex A of the 2022 edition, whether it applies and why.
  • Policies, procedures and evidence that the controls are actually working.
  • Ongoing running: internal audits, management reviews and improvement, year after year.

The certification body checks your documents at stage 1, then checks the system is working at stage 2. After that, surveillance audits in years two and three keep the certificate valid.

Which should you do first?

Do Cyber Essentials first if:

  • a public-sector customer or contract requires it;
  • you want a quick, affordable baseline before tackling anything bigger;
  • you have no security certification at all and need something this quarter.

Go straight for ISO 27001 if:

  • a customer or tender asks for ISO 27001 by name;
  • you sell to larger organisations who send long security questionnaires;
  • you need to show you manage risk across the business, not just your IT.

Do both if you sell to both the public sector and larger private customers. The work overlaps a lot: Cyber Essentials' five areas map onto ISO 27001 controls on network security, configuration, access, malware and vulnerabilities. Doing Cyber Essentials well gives you a head start on ISO 27001, and an ISO 27001 system makes Cyber Essentials renewals easier.

Common mistakes

  • Assuming one replaces the other. They answer different questions. Check exactly what your customer asked for.
  • Treating either as a one-off. Cyber Essentials expires after a year; ISO 27001 has to keep running between audits.
  • Leaving cloud services out. Both expect your cloud accounts (email, file sharing, business apps) to be included where they hold your data.

How ClearIMS helps

ClearIMS covers ISO 27001 and includes Cyber Essentials and business continuity. You describe your business in plain English and it drafts your ISO 27001 scope, risk register, Statement of Applicability and policies; a named person in your business approves every record, and the AI never approves anything. Then it keeps the work running on tasks with owners and due dates.

We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.

Not sure where you stand on ISO 27001? Take the 2-minute readiness check, or book a 20-minute call.

SOURCES

  1. About Cyber Essentials (NCSC)
  2. Cyber Essentials pricing (IASME)
  3. ISO/IEC 27001:2022 (ISO)
  4. Find a UKAS-accredited certification body (UKAS)
FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Ten organisations get the software at half price. We get to learn from them.

Start with the 30-day free trial. If ClearIMS earns its place, a founding seat locks £150 a month for 24 months, or £1,500 a year upfront. No VAT charged.

Apply for a founding placeBook a 20-minute callWe make the software. Your certification is yours, awarded by your certification body.