Cyber Essentials vs ISO 27001

The two security credentials UK businesses are asked for, compared in plain English.

By Kat Korson · Last reviewed May 2026

Eaglepedia mascot

Cyber Essentials and ISO 27001 are the two information-security credentials UK businesses are most often asked to hold. Cyber Essentials is a UK government-backed scheme covering five basic technical controls. ISO 27001 is a full international standard for managing information security. Cyber Essentials is quicker and simpler to achieve, and ISO 27001 is broader and more rigorous.

What Cyber Essentials is

Cyber Essentials is a UK government-backed scheme run under the National Cyber Security Centre (NCSC). It focuses on five technical controls: secure configuration, boundary firewalls and internet gateways, access control, malware protection and patch management. Together these controls address the most common and damaging cyber attacks.

The scheme has two levels. Cyber Essentials is a self-assessed questionnaire verified by a certification body. Cyber Essentials Plus adds an independent technical audit of the same five controls, giving external assurance that the controls are genuinely in place. Both levels carry the government-recognised certification mark.

Cyber Essentials is mandatory for certain UK government contracts, particularly those involving handling personal data or providing IT products and services. It's also a credential that many private-sector supply chains increasingly expect from their suppliers.

What ISO 27001 is

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It takes a risk-based, organisation-wide approach: rather than prescribing a fixed set of controls, it asks an organisation to identify its own information-security risks and put in place appropriate, documented controls to manage them.

Certification is granted by an accredited certification body after a formal audit. That audit covers both the management system itself and the controls the organisation has chosen to implement. The certificate then needs to be maintained through annual surveillance audits and a full recertification cycle every three years.

ISO 27001 is widely recognised internationally and is the credential many larger organisations and regulated sectors ask for when they want confidence in a supplier's overall security posture.

The key differences

The two credentials differ in scope, effort and depth. Cyber Essentials covers five defined technical controls. ISO 27001 covers the whole organisation's approach to information security, including people, processes and technology. Cyber Essentials can usually be achieved quickly; ISO 27001 typically takes several months of preparation before an audit is possible.

Cost follows the same pattern: Cyber Essentials involves a modest certification fee and reasonable internal effort. ISO 27001 involves consultancy, internal project work, and ongoing audit costs that are significantly higher. The rigour is also different: Cyber Essentials checks that five controls exist; ISO 27001 assesses whether the whole management system is working as intended.

Think of Cyber Essentials as a solid baseline and ISO 27001 as a comprehensive management system built on top of it. Preparing for either benefits from a clear-eyed IT audit and good IT risk management practice beforehand.

Which one does your business need?

The right answer depends on what your clients and contracts ask for, your sector and the size and complexity of your organisation. Many UK SMEs start with Cyber Essentials because it satisfies most public-sector contract requirements and demonstrates a credible security baseline to private clients. It's also the more accessible first step.

As businesses grow, take on larger enterprise clients or enter regulated markets, the demand for ISO 27001 often follows. Some organisations hold both credentials, treating Cyber Essentials as the foundation and using ISO 27001 to build the broader management system around it. That's a sensible progression for a growing business.

Deciding which credential is right for you - and when to pursue it - is part of good IT governance. The starting point is understanding what you're being asked for and what your business's risk profile actually requires. Our guide to cybersecurity essentials for UK SMEs covers the practical steps in more detail.

Not sure which credential your business needs? Red Eagle Tech helps growing businesses work out which security credential is right for them and prepares them to achieve it. Find out more about our technology governance service.

Frequently asked questions

Cyber Essentials is a UK government-backed scheme covering five specific technical controls. ISO 27001 is an international standard for a full information security management system. Cyber Essentials is quicker and simpler to achieve; ISO 27001 is broader and more rigorous.

ISO 27001 is significantly harder. It requires an organisation-wide risk assessment, a documented management system and an audit by an accredited certification body. Cyber Essentials focuses on five technical controls and can usually be completed far more quickly.

Not necessarily. Many UK businesses hold Cyber Essentials alone and it's sufficient for most public-sector contracts. Some larger clients or sectors require ISO 27001. Some organisations hold both, treating Cyber Essentials as the baseline and ISO 27001 as the deeper layer.

It's not a general legal requirement, but it's mandatory for UK government contracts that involve handling personal data or providing certain IT products and services. Your contracts and client expectations are the best guide to whether you need it.

It typically takes several months, depending on the size and complexity of the organisation, how mature existing security practices are and how quickly the team can prepare for the certification audit. Smaller organisations with good foundations can move faster.
Kat Korson - Company Director at Red Eagle Tech

About the author

Kat Korson

Company Director

Company Director at Red Eagle Tech, leading our mission to make enterprise-grade technology accessible to businesses of all sizes. With a background spanning marketing, operations, and business development, I understand firsthand the challenges businesses face when trying to leverage technology for growth.

Read more about Kat

Discovery call

A friendly 15-minute video call with Kat to understand your needs. No preparation needed.

  • Discuss your project
  • Get honest advice
  • No obligation
Kat Korson, Founder of Red Eagle Tech

Kat Korson

Founder & Technical Director

Our team has 10+ years delivering software solutions for growing businesses across the UK.

Send us a message

Your information is secure. See our privacy policy.

Find us