iso27001partnersUK certification, costed Get a cost estimate

Is ISO 27001 mandatory in the UK? What each rule actually requires

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 4 October 2026
By the iso27001partners.co.uk editorial team · Published 4 October 2026 · Last reviewed 4 October 2026 · 8 min read
9 primary sources cited on this page. How we check what is on this site
Short answer Not in any UK rule we have read

Where UK public rules name a certification, it is Cyber Essentials. ISO 27001 is required when a customer's contract or tender requires it.

ISO 27001 is a voluntary international standard. The question behind “is it mandatory?” is narrower: does this contract, regulator or law require it? This page takes the UK rules that come up for suppliers one at a time, quotes what each one names, and says whether ISO 27001 is required, accepted as an equivalent, or not mentioned.

Rule by rule

UK rules and contracts: what each names, and whether ISO 27001 is required (each row quoted on the linked page)
RuleWhat it requiresIs ISO 27001 required?Detail
UK GDPR (Article 32)Security “appropriate to the risk”No. Certification under Article 42 is voluntary and is not ISO 27001Article 32
Central government contracts (PPN 014)Cyber Essentials or Plus, or equivalent, for in-scope contractsNo. ISO 27001 holders “will not automatically conform”Public sector
MOD contracts (DEFCON 658, Def Stan 05-138)Cyber Essentials at every risk level; Plus from level 2No. The standard does not mention ISO 27001DEFCON 658
Criminal legal aid (2025 Standard Crime Contract)Cyber Essentials or an agreed equivalentNo; but whole-firm UKAS ISO 27001 is named as highly likely to countLegal aid
Further education colleges (DfE)Cyber Essentials under the funding agreementNoSchools and colleges
NHS data and systems (DSPT)The Data Security and Protection ToolkitNo. It cannot be submitted insteadNHS suppliers
FCA-regulated firms (operational resilience)Important business services, impact tolerances, mapping, testingNo. The standard does not ask for those thingsFinancial services

We list only rules we have read first-hand. Other regulators' licence conditions and individual frameworks are not covered here, and a specific tender can always ask for more.

Data protection law

UK GDPR Article 32

“Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:” It names measures, not standards. An ISO 27001 management system is one way to run and evidence them.

Certification under UK GDPR

The law has its own certification route, under Article 42, and it is optional: “Applying for certification is voluntary.” ISO 27001 is not one of those schemes. See UK GDPR certification.

Public sector and regulated buyers

Central government (PPN 014)

“Evidence of holding a Cyber Essentials certificate, whether basic level or Plus level, or equivalent, is required before contract award for in-scope contracts.” The policy note adds: “The ISO27001 standard is widely used but companies that attain this standard will not automatically conform to Cyber Essentials. This is because it is not usual for all of the five technical controls in Cyber Essentials to be included in the scope for ISO27001 implementation. It is also unlikely that any of these controls will be tested for ISO27001. Therefore most businesses with ISO27001 will have to adopt Cyber Essentials in addition to ISO27001 or demonstrate equivalent controls are in place.” And: “In-scope organisations must not take a blanket approach.”

Defence (DEFCON 658 and Def Stan 05-138)

“The Supplier shall have Cyber Essentials certification that covers the scope required for all aspects of the contract and commit to maintaining this for the duration of the contract.” The standard does not mention ISO 27001. See DEFCON 658.

The 2025 Standard Crime Contract requires Cyber Essentials “or an equivalent certification as may be agreed with us”. The LAA's guidance: “Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.” It also names whole-firm, UKAS-accredited ISO 27001 as highly likely to be an acceptable equivalent.

Schools and colleges

“Cyber Essentials is a requirement for colleges under their funding agreement.” The DfE's standards do not mention ISO 27001.

NHS

“All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly.” ISO 27001 does not replace the toolkit and cannot be submitted instead of it. What holding ISO 27001 does is reduce how much separate evidence you have to assemble, because work you have already done for the management system can be reused against toolkit items. The submission itself is still yours to make.

Financial services

An ISO 27001 certificate is evidence about an information security management system. It is not evidence that you have identified important business services, set impact tolerances or mapped and tested against them, because the standard does not ask for any of those things. Where the two meet is in the supplier’s own assurance pack: a regulated client doing third-party due diligence on you may ask for the certificate as one input, then ask operational-resilience questions the certificate cannot answer.

When ISO 27001 does become a requirement

A customer's contract or tender

A private buyer can require ISO 27001 in its contract, and then it is mandatory for that contract. Read the wording: the edition, the scope it expects to be covered, and whether the certificate must be accredited.

As an equivalent

Where a rule allows an equivalent to Cyber Essentials, an ISO 27001 certificate may be offered — the LAA's test is UKAS accreditation, whole-organisation scope and the five technical controls. See ISO 27001 vs Cyber Essentials.

Check what you were sent (our reading)

“ISO 27001 or equivalent”, “ISO 27001 certified” and “aligned to ISO 27001” are three different requests. Only the second needs a certificate.

Before you start a certification project

Find the sentence in the contract or tender that asks for it, and check whether Cyber Essentials, an equivalent, or ISO 27001 by name is what it says.

We do not give legal advice, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use, including when the answer is that you do not need ISO 27001. Each rule is quoted from its own text.

Where this fits

Common questions

Is ISO 27001 mandatory in the UK?

Not under any of the UK rules we have read: UK GDPR, the central government procurement policy on Cyber Essentials, the MOD's DEFCON 658, the legal aid crime contract, the DfE's standards, the NHS toolkit and the FCA's operational resilience rules. Where they name a certification it is Cyber Essentials. ISO 27001 becomes required when a customer's contract or tender says so.

Is ISO 27001 a legal requirement for GDPR?

No. Article 32 requires security “appropriate to the risk”. The certification UK GDPR describes is under Article 42, and the ICO says: “Applying for certification is voluntary.” ISO 27001 is not an Article 42 scheme.

Who needs ISO 27001?

Organisations whose customers, contracts or tenders ask for it. On the texts we have read, the public rules name Cyber Essentials, and in two cases (PPN 014, the legal aid contract) allow an equivalent. Commercial buyers set their own requirements, so the answer is in the contract you are bidding for.

Is ISO 27001 required for government contracts?

Not by PPN 014. “Evidence of holding a Cyber Essentials certificate, whether basic level or Plus level, or equivalent, is required before contract award for in-scope contracts.” And on ISO 27001: “The ISO27001 standard is widely used but companies that attain this standard will not automatically conform to Cyber Essentials. This is because it is not usual for all of the five technical controls in Cyber Essentials to be included in the scope for ISO27001 implementation. It is also unlikely that any of these controls will be tested for ISO27001. Therefore most businesses with ISO27001 will have to adopt Cyber Essentials in addition to ISO27001 or demonstrate equivalent controls are in place.”

Does a legal aid firm need ISO 27001?

No. The LAA's guidance: “Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.”

If it is not mandatory, why do suppliers get it?

Because a buyer asked. A private customer's contract can require it, and the public rules above name Cyber Essentials while leaving room for equivalents. The benefits page sets out what a certificate does and does not give you.

Sources cited on this page

  1. UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
  2. ICO, Certification schemes: a guide (updated 13 February 2026)
  3. PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
  4. Ministry of Defence, Def Stan 05-138 Issue 4, Cyber security for defence suppliers (published 23 May 2024), GOV.UK
  5. Legal Aid Agency, 2025 Standard Crime Contract — Standard Terms, version 1 (effective 1 October 2025)
  6. Legal Aid Agency, Provider Data Security Guidance v5 (October 2025)
  7. Department for Education, Cyber security standards for schools and colleges (updated 16 September 2026)
  8. NHS Data Security and Protection Toolkit
  9. FCA, Operational resilience

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

A contract asking for ISO 27001?

Paste the wording it uses and say who the customer is.

Step 1 of 6
What has made this a live question?

Whatever is pushing this may also set the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now