Clients, tender documents and insurers increasingly ask the same question: what certification do you hold? The two answers most UK organisations reach for are Cyber Essentials and ISO 27001. They are often mentioned together, but they do very different jobs, and choosing the wrong one first can cost time and money.
What Cyber Essentials is
Cyber Essentials is a UK government-backed scheme, run on behalf of the National Cyber Security Centre, that shows an organisation has five basic technical controls in place:
- Firewalls, so that only safe and necessary internet services can be reached.
- Secure configuration, so that devices and software are set up to reduce weaknesses.
- Security update management, so that software is kept patched.
- User access control, so that people only have the access they need.
- Malware protection, so that malicious software is prevented or detected.
At the basic level, the organisation completes a self-assessment that is reviewed by a certification body. Cyber Essentials Plus covers the same controls but adds hands-on technical verification of your systems by an assessor. Certification needs renewing every year.
Cyber Essentials is focused, relatively quick to achieve and well recognised. It is a requirement for some UK government contracts, and many larger organisations now ask their suppliers for it.
What ISO 27001 is
ISO/IEC 27001 is the international standard for an information security management system, usually shortened to ISMS. Rather than checking a fixed list of technical settings, it asks you to understand the information you hold, assess the risks to it, and put proportionate controls in place across people, processes and technology.
The current version, ISO 27001:2022, includes a reference set of 93 controls in Annex A, grouped into organisational, people, physical and technological themes. You decide which apply to you through your risk assessment and record that decision in a Statement of Applicability.
Certification is carried out by an independent certification body in a two-stage audit: a review of your documentation and readiness, followed by an assessment of how the ISMS works in practice. Certificates normally run on a three-year cycle, with surveillance audits in between, so the standard expects continual improvement rather than a one-off effort.
The key differences
- Scope. Cyber Essentials covers five technical controls. ISO 27001 covers how the whole organisation manages information security, including governance, suppliers, people and incident response.
- Approach. Cyber Essentials sets a fixed baseline. ISO 27001 is risk-based, so it adapts to your organisation and the threats it faces.
- Recognition. Cyber Essentials is a UK scheme. ISO 27001 is recognised internationally, which matters if you work with overseas clients or in regulated supply chains.
- Effort. Cyber Essentials is usually the lighter undertaking. ISO 27001 takes more time and involvement from across the business, because it changes how security is run day to day.
Which should you pursue first?
Cyber Essentials is often the right first step if you are a smaller organisation, if you need to meet a specific contract requirement quickly, or if you want to close the most common technical gaps before anything else.
ISO 27001 is usually the right goal if clients or tenders ask for it by name, if you handle sensitive or high-value information for others, if you work internationally, or if you want security to be managed as an ongoing business process rather than a yearly check.
The two are not either-or. Cyber Essentials fits comfortably inside an ISO 27001 programme, and the controls it requires overlap with parts of Annex A. Many organisations hold both.
Not sure where you stand?
The quickest way to decide is to understand your current position. Our information security health check gives you an honest picture of your controls and what to fix first, and if ISO 27001 is the right goal, our ISO 27001 consultancy will help you prepare for certification. Vinula is an independent consultancy, not a certification body, so we can give you impartial advice on what fits. Get in touch to talk it through.
