ISO 27001 vs Cyber Essentials
One is a fixed set of technical controls you can certify this month; the other is a security management system audited over the better part of a year. They answer different questions from different buyers. Here is the comparison and the sensible order.
The short answer
Cyber Essentials is a fixed set of five technical controls, self-assessed, certified in days for a few hundred pounds, and aimed at stopping common attacks. ISO 27001 is a management system for information security, independently audited over months, costing from the low tens of thousands, and aimed at proving you govern security as a business discipline. They are not rivals: most organisations that hold ISO 27001 hold Cyber Essentials too, and nearly everyone should start with Cyber Essentials.
Side by side
| Cyber Essentials | ISO 27001 | |
|---|---|---|
| What it is | Five technical controls, pass/fail | An information security management system (ISMS) with 93 controls to consider |
| Who checks | Self-assessment reviewed by a certification body (Plus adds a hands-on audit) | External audit by an accredited certification body, then annual surveillance audits |
| Time to certify | Days to a few weeks | Six to twelve months typically |
| Typical cost, small business | A few hundred pounds; low thousands for Plus | £10,000–£40,000 in year one including consultancy, plus ongoing audit fees |
| Scope | Devices, networks and accounts | People, processes, suppliers, physical security and technology |
| Validity | 12 months | 3 years, with annual audits |
| Who asks for it | UK public sector, insurers, most supply chains | Large corporates, regulated sectors, international clients |
| Recognised | UK | Worldwide |
When Cyber Essentials is the right answer
You're a UK small or medium business, you've been asked for it by a customer, a tender, a framework or an insurer, and you want the common attacks stopped without a governance programme. It's also the sensible first step even if ISO 27001 is the destination: the five controls are a subset of what an ISO auditor will expect, and a pass gets the free insurance and the badge while the longer project runs.
When ISO 27001 is the right answer
You sell to large organisations that ask for it in their supplier questionnaires, you operate internationally, you're in a regulated sector, or a contract is conditional on it. ISO 27001 is what a buyer wants when they need to know you'll keep being secure — that there's a process, an owner, risk assessments and an audit trail — not just that your laptops were patched on the day you certified.
What sits in between
If Cyber Essentials feels thin and ISO 27001 feels like too much, there is a middle step: IASME Cyber Assurance, which adds governance, policies, risk assessment and GDPR to the Cyber Essentials controls at a fraction of ISO's cost and is recognised by an increasing number of UK buyers. And Cyber Essentials Plus — the same controls, verified hands-on by an assessor — is often what a buyer actually wants when they say "something more than basic Cyber Essentials". The Plus comparison is here.
The practical order
Cyber Essentials now, Plus if a buyer or insurer asks for it, IASME Cyber Assurance if you want governance without the ISO price tag, ISO 27001 when a contract or market genuinely requires it. Each builds on the last; none is wasted. What Cyber Essentials involves and costs is in how to get certified.
Before anything else, run our free readiness check against the current rules — it flags the MFA and 14-day traps specifically, so you know in two minutes whether this year's renewal is a formality or a project.
Start with the one you can finish this month.
Fixed price, current-rules review before submission, fixes included, resubmission covered. If ISO 27001 is where you’re heading, Cyber Essentials first is the right foundation.
hello@passcyber.co.uk · Take the readiness check
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd