
Cyber Essentials vs ISO 27001: what is the difference?
What is the difference between Cyber Essentials and ISO 27001?
Cyber Essentials is a UK government-backed scheme covering five technical controls, achievable in weeks. ISO/IEC 27001 is an international standard for an information security management system - governance, risk and process across the organisation - assessed by an external auditor and typically taking six to twelve months. One is a technical baseline. The other is a management system.
Cyber Essentials in brief
Cyber Essentials is administered by IASME on behalf of the NCSC. It covers five control areas:
Firewalls and internet gateways
Secure configuration
User access control
Malware protection
Security update management
The base level is a self-assessment questionnaire, reviewed by a certification body. Cyber Essentials Plus adds an independent technical audit, including vulnerability scanning of a sample of devices.
Timescale: two to six weeks for most SMEs
Renewal: annual
Typical driver: it is mandatory for many UK public sector contracts, and increasingly requested in private supply chains
ISO 27001 in brief
ISO/IEC 27001:2022 specifies the requirements for an information security management system. It is not a checklist of technical controls. It asks you to identify your information assets, assess the risks to them, select and justify controls, document the result in a Statement of Applicability, and demonstrate that the system is reviewed and improved over time.
Certification is granted by an accredited certification body after a two-stage audit, with surveillance audits in the following years.
Timescale: six to twelve months to first certification for most SMEs
Certification cycle: three years, with annual surveillance audits
Typical driver: enterprise clients, regulated sectors, international contracts and investor due diligence
Compared directly
Cyber Essentials | ISO 27001 | |
|---|---|---|
Nature | Technical control baseline | Management system standard |
Origin | UK, government-backed | International |
Assessment | Self-assessment, or audit for Plus | External audit, two stages |
Scope | Devices and internet-facing systems | Whatever scope you define |
Effort | Weeks | Months |
Ongoing | Annual recertification | Surveillance audits, continual improvement |
Recognised by | UK public sector, UK supply chains | Enterprise and international buyers |
Which do you need?
Start with Cyber Essentials if you are bidding for UK public sector work, a client has asked for it by name, or you want a defensible baseline quickly. It is the fastest credible signal available to a UK SME.
Pursue ISO 27001 if enterprise clients audit you, you handle sensitive data at scale, you are raising investment, or you sell internationally. It answers questions Cyber Essentials cannot.
Do both if you sell to both markets. They are not alternatives. The five Cyber Essentials controls will feature among the controls in your ISO 27001 Statement of Applicability, so the work compounds rather than duplicates.
The sequencing that works
Cyber Essentials first. It forces you to fix patching, access control and configuration, which are prerequisites for ISO 27001 anyway.
Gap analysis against ISO 27001 Annexe A.
Build the management system - policies, risk assessment, Statement of Applicability, internal audit, management review.
Stage 1 and Stage 2 audits.
Doing it in this order means the technical remediation is finished before the auditor arrives, which is where most first-time ISO projects lose time.
What people underestimate
ISO 27001 is largely an evidence exercise. The auditor is not asking whether you have a policy. They are asking to see the records that prove you follow it - risk reviews held, access rights reviewed, incidents logged and closed, suppliers assessed. Organisations that treat it as a documentation project fail Stage 2.
How NVOY helps
We deliver Cyber Essentials and ISO 27001 readiness for clients, and we hold ISO/IEC 27001:2022 certification ourselves for the provision of IT managed services, professional services and supply of IT equipment - certificate 21497ISMS001, issued by Alcumus ISOQAR under UKAS accreditation. You can verify it independently.
See IT Security, or read how to get Cyber Essentials certified.
BLOGS


