Cyber Essentials is a technical baseline—five specific controls. ISO 27001 is a comprehensive management system covering all of information security. They're different things. Many organisations need both.
Quick answer: Cyber Essentials is a technical baseline—five specific controls. ISO 27001 is a comprehensive management system covering all of information security. They're different things. Many organisations need both.
The Key Differences
| Cyber Essentials | ISO 27001 | |
|---|---|---|
| What it is | Technical controls checklist | Management system |
| Scope | 5 specific controls | All of information security |
| Assessment | Self-assessed or verified | Formal audit by certification body |
| Time to achieve | 2-6 weeks | 6-18 months |
| Cost | £300-2,500 | £15,000-40,000+ |
| Renewal | Annual recertification | Annual surveillance audits |
| Effort | Low-medium | Significant ongoing |
What Cyber Essentials Covers
Five technical controls:
- Firewalls and internet gateways
- Secure configuration
- Access control
- Malware protection
- Patch management
What ISO 27001 Covers
Everything. ISO 27001 requires a complete Information Security Management System (ISMS):
- Risk assessment methodology
- Security policies and procedures
- Asset management
- Access control
- Cryptography
- Physical security
- Operations security
- Communications security
- Supplier relationships
- Incident management
- Business continuity
- Compliance
Which Do You Need?
Cyber Essentials is right if:
- You need baseline certification quickly
- Government contracts require it
- You want to demonstrate basic security hygiene
- You're early in your security journey
- Customers specifically require it
- You handle sensitive data and need comprehensive controls
- You want to build mature security practices
- You're bidding on larger contracts where it's expected
- Defence contracts (CE+ mandatory, ISO 27001 often expected)
- Larger organisations with diverse requirements
- You want comprehensive security AND the specific CE certification
They Don't Overlap Much
Cyber Essentials doesn't give you ISO 27001. ISO 27001 doesn't automatically give you CE (though you should pass easily).
CE is a narrow technical check. ISO 27001 is broad governance plus technical controls plus processes plus people plus continuous improvement.
Our View
Start with Cyber Essentials if you need certification quickly or for specific requirements. It's achievable in weeks and demonstrates baseline security.
Plan for ISO 27001 if you're serious about security maturity or your market demands it. It's a bigger investment but transforms how you manage security.
Do both if your customers require it—many defence and regulated industry clients do.
We're ISO 27001 certified ourselves. We help clients achieve both certifications—and maintain them.
---
- we'll advise based on your situation.
---
