Last updated: 5 October 2026
Quick answer: Cyber Essentials vs ISO 27001 comes down to depth. Cyber Essentials is a UK government-backed certification of five technical controls, renewed every 12 months. ISO 27001 is an international standard for a full, risk-based information security management system, certified over a three-year cycle. Many UK organisations start with Cyber Essentials and grow into ISO 27001.
If you lead security for a UK organisation, you will eventually be asked which certification you hold. A public sector buyer may ask for Cyber Essentials. An international customer may ask for ISO 27001. Your board will ask which one is worth the money.
The two are not competitors. They answer different questions. Cyber Essentials proves that a small set of basic technical controls is in place. ISO 27001 proves that you run a management system that identifies, treats and reviews information security risk across the whole organisation.
This guide compares the two side by side, shows how the controls map to each other, and gives you a simple way to decide whether you need one, the other or both.
Cyber Essentials vs ISO 27001: what is the difference?
Cyber Essentials checks five technical controls at a point in time. ISO 27001 certifies a management system that covers people, processes and technology and must be improved continually.
The simplest way to think about it:
- Cyber Essentials asks: “Have you switched on the basic protections that stop most common internet-based attacks?”
- ISO 27001 asks: “Do you understand your information security risks, have you chosen proportionate controls, and can you show that the system works and improves?”
Because of that difference, Cyber Essentials is prescriptive and relatively quick, while ISO 27001 is flexible but demands more governance, documentation and management involvement.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed scheme, run by the NCSC with IASME as delivery partner, that certifies five technical controls against common cyber attacks.
According to the NCSC Cyber Essentials overview, the five controls are:
- Firewalls: boundary protection for internet-connected devices.
- Secure configuration: removing default settings, accounts and unnecessary software.
- Security update management: keeping software and devices patched.
- User access control: limiting accounts and privileges to what people need.
- Malware protection: preventing and detecting malicious software.
Cyber Essentials and Cyber Essentials Plus
There are two levels. Cyber Essentials is a verified self-assessment: you answer a question set and a certification body reviews it. Cyber Essentials Plus covers the same controls but adds hands-on technical testing of your systems by an assessor.
The IASME FAQ confirms that both certificates expire after 12 months, so the scheme requires annual renewal. It also notes that if you achieved Cyber Essentials less than three months before moving to Cyber Essentials Plus, you do not need to repeat the self-assessment stage.
What changed in April 2026?
Version 3.3 of the Cyber Essentials requirements has applied since late April 2026. As IASME set out, multi-factor authentication is now mandatory for all cloud services where it is available, cloud services cannot be excluded from scope, and critical security updates must be installed within 14 days. Assessment accounts opened before the change had six months to certify under the previous requirements, so by late October 2026 every new certificate follows v3.3. Our earlier post on Cyber Essentials Plus and the 14-day patching requirement covers the update management side.
What is ISO 27001?
ISO/IEC 27001 is the international standard for an information security management system (ISMS). It requires you to assess risk, select controls, document decisions and improve the system over time.
The current edition, ISO/IEC 27001:2022, was published in October 2022, with an amendment in 2024 on climate action. ISO reports more than 70,000 valid certificates across 150 countries in its 2022 survey, which is why international customers recognise it so widely.
The standard has two parts:
- Clauses 4 to 10: the management system requirements, including context, leadership, risk assessment and treatment, internal audit, management review and continual improvement. These are mandatory.
- Annex A: a reference set of 93 controls grouped into organisational, people, physical and technological themes. You decide which apply and justify the decision in a Statement of Applicability.
Certification follows a three-year cycle: an initial two-stage audit, surveillance audits in the intervening years and a recertification audit. Certificates against the older 2013 edition expired or were withdrawn at the end of the 36-month transition period, which ended in October 2025.
For a deeper look at how ISO 27001 fits with other frameworks, see our ISO 27001 framework page.
How do Cyber Essentials and ISO 27001 compare side by side?
The table below summarises the main differences a CISO needs to explain to a board or a buyer.
| Criterion | Cyber Essentials / Plus | ISO 27001 |
|---|---|---|
| Type | UK government-backed certification scheme | International management system standard |
| Scope | Five technical controls on in-scope IT | Whole ISMS for a defined scope: people, process, technology, suppliers |
| Approach | Prescriptive requirements | Risk-based; you select and justify controls |
| Assessment | Verified self-assessment; Plus adds technical testing | Two-stage external audit by a certification body |
| Validity | Certificate expires after 12 months | Three-year cycle with surveillance audits |
| Documentation | Answers to the question set | Policies, risk assessment, Statement of Applicability, records |
| Management involvement | Sign-off by a board-level or equivalent person | Leadership commitment, management review, assigned roles |
| Recognition | Mainly UK, especially public sector supply chains | Global |
| Typical effort | Weeks for a well-run small IT estate | Months, depending on size and maturity |
In practice: Cyber Essentials tells a buyer your laptops and servers are hardened today. ISO 27001 tells a buyer you will still be managing risk properly next year, including risks that have nothing to do with firewalls, such as supplier failures or insider threats.
Which certification do customers and regulators ask for?
UK public sector buyers commonly ask for Cyber Essentials, while international and regulated customers tend to ask for ISO 27001. US customers often ask for SOC 2 instead.
Under Procurement Policy Note 09/14, the UK government has required Cyber Essentials for newly advertised central government contracts involving the handling of personal information and the provision of certain ICT products and services since 1 October 2014. Many private sector supply chains now copy that expectation.
| Market | What buyers typically ask for | Notes |
|---|---|---|
| UK | Cyber Essentials or Plus, often ISO 27001 for larger contracts | Central government contracts in scope of PPN 09/14 require Cyber Essentials |
| EU | ISO 27001 | Often used as a foundation for NIS2 and DORA security measures; Cyber Essentials has little recognition |
| US | SOC 2, sometimes ISO 27001 | SOC 2 is an attestation report rather than a certification |
If you sell into several markets, ISO 27001 usually has the widest reach, but it will not replace Cyber Essentials where a UK contract names it explicitly.
How do the Cyber Essentials controls map to ISO 27001?
Every Cyber Essentials control has a counterpart in ISO 27001 Annex A, so work done for one is reusable for the other.
| Cyber Essentials control | Related ISO 27001:2022 Annex A controls |
|---|---|
| Firewalls | 8.20 Networks security; 8.22 Segregation of networks |
| Secure configuration | 8.9 Configuration management |
| Security update management | 8.8 Management of technical vulnerabilities |
| User access control | 5.15 Access control; 5.18 Access rights; 8.2 Privileged access rights; 8.5 Secure authentication |
| Malware protection | 8.7 Protection against malware |
That mapping covers only a small slice of Annex A. Cyber Essentials says nothing about risk assessment, supplier security, incident management, business continuity, awareness training, legal requirements or internal audit, all of which ISO 27001 expects you to consider.
A cross-framework control mapping tool lets you record evidence once and reuse it for Cyber Essentials, ISO 27001, NIS2 or customer questionnaires, instead of maintaining separate spreadsheets.
Should you get Cyber Essentials, ISO 27001 or both?
Choose Cyber Essentials if you need a fast, affordable UK baseline; choose ISO 27001 if you need global assurance or a full risk programme; choose both if you sell to UK public sector and international customers.
Use this decision guide:
- Does a UK contract you want require Cyber Essentials? If yes, get it, regardless of anything else.
- Do customers outside the UK, or regulated customers, ask for ISO 27001? If yes, plan ISO 27001 certification.
- Do you process sensitive data or run critical services? If yes, the risk-based approach of ISO 27001 is worth building even before a customer demands it.
- Are you small, with a simple IT estate and no external demand yet? Start with Cyber Essentials, then Cyber Essentials Plus, and use them as the technical foundation for a later ISMS.
If you want to run both programmes from one place, with shared controls, evidence and assessments, you can start your 14-day free trial of Enactia’s AI-powered GRC platform.
How do you run both certifications without duplicating work?
Treat Cyber Essentials as the technical baseline inside your ISMS, not as a separate project.
- One control set: record each technical control once and link it to both Cyber Essentials requirements and Annex A.
- One evidence library: patch reports, firewall rules and access reviews serve both assessments.
- One policy set: write your access control, patching and malware policies to satisfy both, and keep them under version control with policy management.
- One calendar: align the Cyber Essentials renewal with an ISO 27001 internal audit or surveillance audit, so the same team prepares once.
- One gap assessment: run readiness compliance assessments for both frameworks together and track findings in one list.
Common mistake: assuming ISO 27001 certification automatically meets Cyber Essentials. ISO 27001 lets you set your own risk-based control levels, while Cyber Essentials has fixed technical requirements such as time limits for applying critical updates. You still need to pass the Cyber Essentials assessment separately.
Common mistake: treating Cyber Essentials as “done” for the year. The certificate is a snapshot. Configuration drift, new cloud services and unpatched devices can put you out of line weeks after certification.
Key takeaways
- Cyber Essentials certifies five technical controls and expires after 12 months; ISO 27001 certifies a full risk-based ISMS on a three-year cycle.
- UK public sector contracts often require Cyber Essentials; international and regulated customers usually expect ISO 27001.
- Since April 2026, Cyber Essentials v3.3 has made MFA mandatory for cloud services where available.
- All five Cyber Essentials controls map to ISO 27001 Annex A, so the work is reusable.
- Many organisations benefit from both, run from one shared control and evidence set.
Frequently asked questions
Is Cyber Essentials easier than ISO 27001?
Yes, in most cases. Cyber Essentials covers five prescriptive technical controls and is assessed through a verified self-assessment, with technical testing added at the Plus level. ISO 27001 requires a documented management system, a risk assessment, a Statement of Applicability, internal audits and management reviews, followed by a two-stage external audit.
Does ISO 27001 replace Cyber Essentials?
No. ISO 27001 covers far more ground, but it does not automatically satisfy the fixed technical requirements of Cyber Essentials. If a UK contract requires Cyber Essentials, you need that certificate as well. Because the controls overlap, organisations with ISO 27001 usually find Cyber Essentials straightforward to add.
How long is each certificate valid?
Cyber Essentials and Cyber Essentials Plus certificates expire after 12 months, so you renew every year. ISO 27001 certification runs on a three-year cycle, with surveillance audits by the certification body in the years between the initial certification and the recertification audit.
Is Cyber Essentials recognised outside the UK?
Recognition outside the UK is limited. Cyber Essentials is a UK government-backed scheme designed mainly for UK organisations and supply chains. International customers are more likely to ask for ISO 27001 or, in the United States, a SOC 2 report. If you sell abroad, plan for one of those alongside Cyber Essentials.
Which should a small business do first?
Most small UK businesses should start with Cyber Essentials. It is quicker, focuses on the controls that block the most common attacks and is often required for public sector work. Once that baseline is stable, moving to Cyber Essentials Plus and then ISO 27001 builds on the same technical work.
Choosing the right path
Cyber Essentials and ISO 27001 work best together. Cyber Essentials gives you a proven technical baseline and access to UK supply chains; ISO 27001 turns that baseline into a managed, risk-based programme that international customers trust. Map the controls once, share the evidence, and let each certification do the job it was designed for.
If you would like help planning both programmes, contact us or book a demo or start your 14-day free trial.
