Cyber Essentials vs ISO 27001: what is the difference?

What is the difference between Cyber Essentials and ISO 27001?

Cyber Essentials is a UK government-backed scheme covering five technical controls, achievable in weeks. ISO/IEC 27001 is an international standard for an information security management system - governance, risk and process across the organisation - assessed by an external auditor and typically taking six to twelve months. One is a technical baseline. The other is a management system.

Cyber Essentials in brief

Cyber Essentials is administered by IASME on behalf of the NCSC. It covers five control areas:

  1. Firewalls and internet gateways

  2. Secure configuration

  3. User access control

  4. Malware protection

  5. Security update management

The base level is a self-assessment questionnaire, reviewed by a certification body. Cyber Essentials Plus adds an independent technical audit, including vulnerability scanning of a sample of devices.

  • Timescale: two to six weeks for most SMEs

  • Renewal: annual

  • Typical driver: it is mandatory for many UK public sector contracts, and increasingly requested in private supply chains

ISO 27001 in brief

ISO/IEC 27001:2022 specifies the requirements for an information security management system. It is not a checklist of technical controls. It asks you to identify your information assets, assess the risks to them, select and justify controls, document the result in a Statement of Applicability, and demonstrate that the system is reviewed and improved over time.

Certification is granted by an accredited certification body after a two-stage audit, with surveillance audits in the following years.

  • Timescale: six to twelve months to first certification for most SMEs

  • Certification cycle: three years, with annual surveillance audits

  • Typical driver: enterprise clients, regulated sectors, international contracts and investor due diligence

Compared directly


Cyber Essentials

ISO 27001

Nature

Technical control baseline

Management system standard

Origin

UK, government-backed

International

Assessment

Self-assessment, or audit for Plus

External audit, two stages

Scope

Devices and internet-facing systems

Whatever scope you define

Effort

Weeks

Months

Ongoing

Annual recertification

Surveillance audits, continual improvement

Recognised by

UK public sector, UK supply chains

Enterprise and international buyers

Which do you need?

Start with Cyber Essentials if you are bidding for UK public sector work, a client has asked for it by name, or you want a defensible baseline quickly. It is the fastest credible signal available to a UK SME.

Pursue ISO 27001 if enterprise clients audit you, you handle sensitive data at scale, you are raising investment, or you sell internationally. It answers questions Cyber Essentials cannot.

Do both if you sell to both markets. They are not alternatives. The five Cyber Essentials controls will feature among the controls in your ISO 27001 Statement of Applicability, so the work compounds rather than duplicates.

The sequencing that works

  1. Cyber Essentials first. It forces you to fix patching, access control and configuration, which are prerequisites for ISO 27001 anyway.

  2. Gap analysis against ISO 27001 Annexe A.

  3. Build the management system - policies, risk assessment, Statement of Applicability, internal audit, management review.

  4. Stage 1 and Stage 2 audits.

Doing it in this order means the technical remediation is finished before the auditor arrives, which is where most first-time ISO projects lose time.

What people underestimate

ISO 27001 is largely an evidence exercise. The auditor is not asking whether you have a policy. They are asking to see the records that prove you follow it - risk reviews held, access rights reviewed, incidents logged and closed, suppliers assessed. Organisations that treat it as a documentation project fail Stage 2.

How NVOY helps

We deliver Cyber Essentials and ISO 27001 readiness for clients, and we hold ISO/IEC 27001:2022 certification ourselves for the provision of IT managed services, professional services and supply of IT equipment - certificate 21497ISMS001, issued by Alcumus ISOQAR under UKAS accreditation. You can verify it independently.

See IT Security, or read how to get Cyber Essentials certified.

Arrange a consultation