Cyber Essentials vs ISO 27001: which do you need?
Cyber Essentials proves you have five basic technical protections in place. ISO 27001 proves you run a whole system for managing information security risk across the business. Cyber Essentials is quicker and cheaper, and is often the minimum for UK public-sector work. ISO 27001 takes months, costs more, and is what larger customers and many tenders ask for when they want real assurance.
If you're not sure which you need, ask the customer or read the tender wording. If it says "ISO 27001", Cyber Essentials won't do instead. If it says "Cyber Essentials", ISO 27001 alone may not tick the box either.
At a glance
| Cyber Essentials | ISO 27001 | |
|---|---|---|
| What it is | A UK government-backed scheme, run by the NCSC with IASME | An international standard for an information security management system (ISMS) |
| What it covers | Five technical controls on your IT | Your whole approach to information risk: people, process, suppliers, technology |
| How you get it | Online self-assessment, checked by a certification body (Plus adds a hands-on technical audit) | Two-stage audit by an accredited certification body (UKAS in the UK) |
| How long it takes | Days to a few weeks | Usually several months |
| How long it lasts | 12 months | 3 years, with yearly surveillance audits |
| Typical cost (2026) | Roughly £320–£600 + VAT for the basic assessment, by organisation size | Roughly £3,500–£10,000+ for the first audit for a small business, plus your time |
| Who asks for it | UK government contracts, public-sector supply chains, insurers | Larger customers, enterprise procurement, international buyers, many tenders |
What Cyber Essentials checks
Cyber Essentials covers five technical areas:
- Firewalls protecting your internet connection and devices.
- Secure configuration: removing default passwords and unnecessary software.
- User access control: the right accounts with the right rights, and multi-factor authentication for cloud services.
- Malware protection on devices.
- Security update management: applying critical and high-risk patches quickly.
You answer an online questionnaire, a director signs it off, and an assessor reviews it. Cyber Essentials Plus adds a technical audit where an assessor tests a sample of your devices. Both have to be renewed every year.
It's a good baseline: it blocks a large share of common attacks. But it doesn't ask about your suppliers, your incident response, your risk decisions or whether your staff are trained.
What ISO 27001 checks
ISO 27001 asks you to build and run an ISMS. In practice that means:
- A defined scope: which parts of the business, sites and systems are covered.
- A risk assessment and treatment plan: what could go wrong with your information, and what you've decided to do about it.
- A Statement of Applicability: for each of the 93 controls in Annex A of the 2022 edition, whether it applies and why.
- Policies, procedures and evidence that the controls are actually working.
- Ongoing running: internal audits, management reviews and improvement, year after year.
The certification body checks your documents at stage 1, then checks the system is working at stage 2. After that, surveillance audits in years two and three keep the certificate valid.
Which should you do first?
Do Cyber Essentials first if:
- a public-sector customer or contract requires it;
- you want a quick, affordable baseline before tackling anything bigger;
- you have no security certification at all and need something this quarter.
Go straight for ISO 27001 if:
- a customer or tender asks for ISO 27001 by name;
- you sell to larger organisations who send long security questionnaires;
- you need to show you manage risk across the business, not just your IT.
Do both if you sell to both the public sector and larger private customers. The work overlaps a lot: Cyber Essentials' five areas map onto ISO 27001 controls on network security, configuration, access, malware and vulnerabilities. Doing Cyber Essentials well gives you a head start on ISO 27001, and an ISO 27001 system makes Cyber Essentials renewals easier.
Common mistakes
- Assuming one replaces the other. They answer different questions. Check exactly what your customer asked for.
- Treating either as a one-off. Cyber Essentials expires after a year; ISO 27001 has to keep running between audits.
- Leaving cloud services out. Both expect your cloud accounts (email, file sharing, business apps) to be included where they hold your data.
How ClearIMS helps
ClearIMS covers ISO 27001 and includes Cyber Essentials and business continuity. You describe your business in plain English and it drafts your ISO 27001 scope, risk register, Statement of Applicability and policies; a named person in your business approves every record, and the AI never approves anything. Then it keeps the work running on tasks with owners and due dates.
We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.
Not sure where you stand on ISO 27001? Take the 2-minute readiness check, or book a 20-minute call.