Cyber Essentials certifies five basic technical controls and suits almost every UK business as a first step. ISO 27001 certifies a full, risk-based information security management system covering people, process and technology. Most businesses start with Cyber Essentials, then move to ISO 27001 when larger clients or tenders ask for it.
How do they compare?
| Cyber Essentials | ISO 27001 | |
|---|---|---|
| What it certifies | Five technical controls | A whole information security management system |
| Scope | Devices, networks and cloud services | People, processes, suppliers and technology |
| Recognised | Mainly in the UK | Internationally |
| Effort | Low: weeks | High: usually months |
| Renewal | Every 12 months | Three-year cycle with annual surveillance audits |
| Typically asked for by | Public sector and supply chains | Larger and international clients |
Which should you get first?
Cyber Essentials, in almost every case. It is quicker, cheaper and fixes the technical basics that ISO 27001 also expects. Many of the controls carry straight over, so the work is not wasted when you go further.
When do you need ISO 27001?
- Clients or tenders ask for it by name.
- You sell to larger or international organisations.
- You handle sensitive client data and want a recognised, audited framework.
- You want security managed as an ongoing system, not a yearly checklist.
Frequently asked questions
No. They are separate certifications, but ISO 27001's controls cover the same ground and more, so holding Cyber Essentials makes ISO 27001 easier.
Yes. The standard scales to any size; a tight scope keeps the effort proportionate.
ISO 27001. Cyber Essentials is a UK scheme, while ISO 27001 is an international standard.