- Cyber Essentials covers five technical control areas and takes two to six weeks to certify. ISO 27001 builds a complete management system and takes six to eighteen months.
- Cyber Essentials is often mandatory for UK central government contracts. ISO 27001 is expected in enterprise and regulated-sector procurement.
- The two certifications are not substitutes. They serve different purposes and suit different stages of business maturity.
- Most UK SMEs should get Cyber Essentials first, then plan ISO 27001 as they win larger contracts or move into regulated sectors.
- CE is a practical ISO 27001 preparation step: the five CE controls map directly to ISO 27001 Annex A technological controls.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed cybersecurity certification scheme created by the National Cyber Security Centre (NCSC) and launched in 2014. IASME (the Information Assurance for Small and Medium Enterprises consortium) administers it, accrediting the certification bodies that assess organisations and issue certificates.
The scheme has two levels. Cyber Essentials is the entry-level option. You complete a self-assessment questionnaire, and an IASME-accredited certification body reviews your answers and confirms that your controls meet the standard. The process is documentation-based and involves no external testing. Cyber Essentials Plus adds verified technical testing on top: an assessor carries out an external vulnerability scan of your internet-facing systems and hands-on internal testing of a sample of devices, confirming that the controls you described work as declared. CE Plus provides stronger assurance and is a requirement for some government contracts.
Both levels assess the same five technical control areas:
- Firewalls: boundary firewalls and internet gateways configured to block unauthorised inbound and outbound traffic
- Secure configuration: devices and software configured to reduce vulnerabilities beyond default settings
- User access control: user accounts limited to the privileges they need, with administrator accounts tightly controlled
- Malware protection: anti-malware software or application allowlisting in place and up to date
- Software and patch management: software kept current, security patches applied without delay, and unsupported software removed
The NCSC's position is that these five controls, properly implemented, prevent around 80% of the most common cyberattacks. That is the rationale for using CE as a baseline rather than a full standard: it targets the attacks organisations face most often.
Costs and timelines
Certification body fees for Cyber Essentials self-assessment run between £300 and £500, though the exact figure varies. Cyber Essentials Plus adds the cost of external vulnerability scanning and internal device testing, bringing the total to around £1,500 to £3,500 depending on the size and complexity of the organisation. Most businesses receive their certificate within two to six weeks of starting the questionnaire process.
Who needs it
Cyber Essentials is mandatory for any UK central government contract that involves handling personal data or providing IT products and services. The Ministry of Defence supply chain has its own requirements that mandate CE Plus across the tier. Many commercial procurement frameworks now reference CE as a minimum standard, even outside government. The certificate lasts twelve months; you must renew through a full reassessment each year.
What is ISO 27001?
ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). Unlike Cyber Essentials, it does not give you a fixed checklist to work through. It requires you to build a documented management system: defining the scope, conducting a formal risk assessment, selecting controls proportionate to your risk profile, running internal audits, holding management reviews, and committing to continual improvement. The approach is risk-based, which means two organisations in the same sector can have very different control sets and both achieve certification.
The most recent version, ISO 27001:2022, restructured the Annex A controls from 114 controls across 14 domains to 93 controls across four categories: organisational controls, people controls, physical controls, and technological controls. The 2022 revision introduced 11 new controls, including threat intelligence (A.5.7), cloud service security (A.5.23), ICT readiness for business continuity (A.5.30), and data masking (A.8.11). Organisations certified to the 2013 version had to transition to the 2022 standard by October 2025.
How certification works
You need a two-stage external audit by a UKAS-accredited certification body. Stage 1 reviews your documentation: the ISMS scope, risk assessment methodology, Statement of Applicability (which records which Annex A controls you have included and why you excluded the rest), and key policies. Stage 2 is an on-site assessment confirming that your controls work as documented. After initial certification, the certification body conducts annual surveillance audits and a full recertification audit every three years.
Costs and timelines
For a business with fifty to two hundred employees, first-time ISO 27001 certification costs between £15,000 and £40,000, combining consultant fees for implementation support and auditor fees for the external assessment. The timeline for most SMEs is six to eighteen months from starting the project to receiving the certificate. Working with an experienced consultant can shorten this by weeks or months by steering you past the most common delays in scope definition and risk assessment structure.
Who needs it
ISO 27001 comes up in enterprise procurement questionnaires, financial services due diligence, healthcare supplier assessments, and contracts with larger technology companies. Cloud and SaaS providers are now expected to hold ISO 27001 as a minimum. If your customers or partners ask for your ISO 27001 status in tender documents, you need to get certified. The standard has global recognition, which matters for UK businesses selling into European and international markets.
Side-by-side comparison
The table below covers the practical differences that matter most when deciding which to pursue and in what order.
Which one should you get first?
For most UK SMEs, the decision comes down to where your revenue comes from and where you want it to come from over the next two to three years.
If you hold or are bidding for UK central government contracts, Cyber Essentials is not optional. It is a contractual requirement in most cases, and IASME designed the scheme for businesses of all sizes. Get it in place first. You can complete it in weeks and show procurement that you meet the government's minimum standard.
If you are starting to sell into enterprise accounts, Cyber Essentials gives you a credible baseline to show procurement teams while you work toward ISO 27001. Enterprise buyers regard CE as proof of hygiene, not proof of maturity. It will get you past a basic supplier assessment, but it will not satisfy a tender that asks for ISO 27001 certification.
If you operate in financial services, healthcare, or run a SaaS product that processes customer data at scale, ISO 27001 is what your customers and partners expect to see. CE alone will not satisfy their due diligence requirements. In these situations, start ISO 27001 planning as a priority and treat CE as an interim step, not the destination.
If you are a startup or early-stage business with fewer than twenty employees and no formal processes yet, ISO 27001 is premature. The standard requires a functioning management system with documented policies, a risk register with named owners, and defined responsibilities. Without those foundations in place, you will spend more time building infrastructure than improving security. Cyber Essentials is the right starting point. Revisit ISO 27001 when you have the organisational processes to sustain it.
Cyber Essentials is a useful preparation step for ISO 27001. The five CE control areas map to technological controls in ISO 27001 Annex A (A.8 in particular). Getting CE certified means you have sorted the technical baseline. ISO 27001 then adds risk management, governance, supplier controls, business continuity, and the full documentation structure on top of what you have built. The two certifications build on each other well when tackled in the right order.
Do they overlap?
Yes, and the overlap is considerable. Cyber Essentials' five control areas sit within what ISO 27001 calls technological controls (Annex A.8). An organisation that has implemented ISO 27001 will meet CE requirements across all five areas almost by definition, because CE's scope is a subset of what ISO 27001 requires in the technical domain.
The reverse is not true. Cyber Essentials covers only technical controls and does not require any of the following:
- Documented information security policies and formal management commitment
- A risk assessment and risk treatment process with documented decisions
- Supplier and third-party security controls
- Physical security controls for offices and facilities
- A business continuity and disaster recovery plan
- An internal audit programme and management review cycle
- A risk register with named owners and treatment status
ISO 27001 requires all of these. An organisation with CE certification has the technical baseline sorted but has no formal governance structure around it. ISO 27001 adds that governance and process layer.
There is a middle option worth considering: IASME Cyber Assurance. IASME administers it (the same body that runs Cyber Essentials), and it sits between CE and ISO 27001 in scope and cost. IASME Cyber Assurance Level 2 is GDPR-aligned and covers a broader range of controls than CE, including governance, people security, and data handling requirements. For organisations that need more assurance than CE provides but are not yet ready for the full ISO 27001 project, it can be a practical intermediate step.
Cyber Essentials certification does not grant ISO 27001 certification, and ISO 27001 certification does not grant Cyber Essentials certification. They are separate assessments run by different bodies against different criteria. An ISO 27001-certified organisation would still need to sit the CE questionnaire and go through a separate assessment to hold CE certification.
Next steps
For Cyber Essentials, start at the IASME portal (iasme.co.uk). IASME maintains a directory of accredited certification bodies, and you complete the self-assessment questionnaire through their platform. The process is straightforward, and many small businesses work through it without a consultant provided they have a clear picture of their IT environment and current controls.
For ISO 27001, the right first step is a gap assessment rather than diving straight into implementation. Before committing budget and time to a full certification project, you need to understand where your current controls, documentation, and processes sit relative to the standard. A gap assessment identifies what you have that counts toward the standard, what needs formalising, and what needs building from scratch. With that picture in hand, you can plan the project with realistic timelines and resource estimates, and avoid treating every Annex A control with the same urgency.
Cyvra works with UK businesses at both stages. We help organisations get Cyber Essentials in place when a contract requires it, and we lead ISO 27001 implementations from scope definition through to audit support. If you are unsure which to prioritise or want to understand what an ISO 27001 project would involve for your organisation, get in touch for a conversation about where you are starting from.