PassCyber
PassCyber / Guides

ISO 27001 vs Cyber Essentials

One is a fixed set of technical controls you can certify this month; the other is a security management system audited over the better part of a year. They answer different questions from different buyers. Here is the comparison and the sensible order.

Updated for the current question setReading time 5 minutes

The short answer

Cyber Essentials is a fixed set of five technical controls, self-assessed, certified in days for a few hundred pounds, and aimed at stopping common attacks. ISO 27001 is a management system for information security, independently audited over months, costing from the low tens of thousands, and aimed at proving you govern security as a business discipline. They are not rivals: most organisations that hold ISO 27001 hold Cyber Essentials too, and nearly everyone should start with Cyber Essentials.

Side by side

Cyber EssentialsISO 27001
What it isFive technical controls, pass/failAn information security management system (ISMS) with 93 controls to consider
Who checksSelf-assessment reviewed by a certification body (Plus adds a hands-on audit)External audit by an accredited certification body, then annual surveillance audits
Time to certifyDays to a few weeksSix to twelve months typically
Typical cost, small businessA few hundred pounds; low thousands for Plus£10,000–£40,000 in year one including consultancy, plus ongoing audit fees
ScopeDevices, networks and accountsPeople, processes, suppliers, physical security and technology
Validity12 months3 years, with annual audits
Who asks for itUK public sector, insurers, most supply chainsLarge corporates, regulated sectors, international clients
RecognisedUKWorldwide

When Cyber Essentials is the right answer

You're a UK small or medium business, you've been asked for it by a customer, a tender, a framework or an insurer, and you want the common attacks stopped without a governance programme. It's also the sensible first step even if ISO 27001 is the destination: the five controls are a subset of what an ISO auditor will expect, and a pass gets the free insurance and the badge while the longer project runs.

When ISO 27001 is the right answer

You sell to large organisations that ask for it in their supplier questionnaires, you operate internationally, you're in a regulated sector, or a contract is conditional on it. ISO 27001 is what a buyer wants when they need to know you'll keep being secure — that there's a process, an owner, risk assessments and an audit trail — not just that your laptops were patched on the day you certified.

What sits in between

If Cyber Essentials feels thin and ISO 27001 feels like too much, there is a middle step: IASME Cyber Assurance, which adds governance, policies, risk assessment and GDPR to the Cyber Essentials controls at a fraction of ISO's cost and is recognised by an increasing number of UK buyers. And Cyber Essentials Plus — the same controls, verified hands-on by an assessor — is often what a buyer actually wants when they say "something more than basic Cyber Essentials". The Plus comparison is here.

The practical order

Cyber Essentials now, Plus if a buyer or insurer asks for it, IASME Cyber Assurance if you want governance without the ISO price tag, ISO 27001 when a contract or market genuinely requires it. Each builds on the last; none is wasted. What Cyber Essentials involves and costs is in how to get certified.

The two-minute head start

Before anything else, run our free readiness check against the current rules — it flags the MFA and 14-day traps specifically, so you know in two minutes whether this year's renewal is a formality or a project.

PassCyber

Start with the one you can finish this month.

Fixed price, current-rules review before submission, fixes included, resubmission covered. If ISO 27001 is where you’re heading, Cyber Essentials first is the right foundation.

hello@passcyber.co.uk  ·  Take the readiness check

PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd