Security HubCyber Essentials vs ISO 27001: Not a Real Comparison

Cyber Essentials vs ISO 27001: Not a Real Comparison

Netru Compliance6 min read

These two get compared constantly and they are not really comparable. Cyber Essentials is a technical baseline across five controls, achievable in weeks, verified by self-assessment or a light audit. ISO 27001 is a management system certification covering how an organisation governs security, taking months and audited by an accredited body. Comparing them is closer to comparing an MOT with a quality management system than comparing two competing standards.

What each one actually is

Cyber Essentials covers five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. It is a UK scheme, backed by the National Cyber Security Centre and delivered through IASME. The basic level is a self-assessment questionnaire verified by a certification body. Cyber Essentials Plus adds hands-on technical verification, including vulnerability scanning and testing of the controls you claimed.

ISO 27001 certifies an information security management system. It is about governance: defining scope, assessing risk, deciding which controls apply and why, treating risk, auditing yourself, and having management review the whole thing. Annex A lists controls, but the certificate is for the management system, not for holding a particular control set.

That is the crux. Cyber Essentials asks whether five specific technical things are true. ISO 27001 asks whether you have a functioning system for deciding what should be true and checking that it is.

When each is enough

Cyber Essentials is enough when a UK buyer asks for it, which is common in public sector procurement where it is frequently mandatory, and increasingly in private sector supply chains as a minimum bar. It is also genuinely worth doing on its own merits for a smaller organisation, because the five controls address the routes most commonly used in opportunistic attacks and the cost is low.

It is not enough when you are selling internationally, because it carries little recognition outside the UK, or when a buyer is assessing your organisation rather than your endpoints. It says nothing about your risk management, supplier assurance, incident response, business continuity, secure development or governance.

ISO 27001 is what international buyers, larger enterprises and regulated customers expect. It is also the foundation that national schemes map onto, so if you expect to face Saudi NCA ECC, UAE Information Assurance, TISAX or a SOC 2 in future, the management system is the reusable asset.

How much one helps with the other

Cyber Essentials towards ISO 27001: a little. You will have evidence for a handful of Annex A controls around access control, malware protection, configuration and patching. You will have none of the management system, which is where certification is won or lost. Treat it as a useful head start on a small part of the technical work rather than a stepping stone.

ISO 27001 towards Cyber Essentials: more, but with a catch worth knowing. An ISO 27001 organisation will generally satisfy the five controls comfortably, but Cyber Essentials asks specific prescriptive questions with specific thresholds, and a risk-based decision that is entirely defensible under ISO 27001 can still fail the questionnaire. Unsupported software is the classic example: ISO 27001 permits you to accept that risk with justification, and Cyber Essentials fails you for it outright.

That asymmetry surprises people. A more mature organisation can fail the simpler scheme precisely because the simpler scheme does not accept risk-based reasoning.

The sensible sequence

For a UK small business with UK customers, Cyber Essentials first, and possibly only. It is cheap, quick, and answers the question your buyers are actually asking.

For anyone selling internationally or into large enterprises, ISO 27001, with Cyber Essentials alongside if UK public sector work is in scope. The two together cost little more than ISO 27001 alone once the management system exists.

For anyone planning several frameworks over the next two years, build the management system first regardless. Every subsequent framework then becomes an exercise in mapping evidence you already hold, which is the entire economic argument for doing governance before certificates.

Related services

Talk to an engineer

We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.

Book a discovery call