Is ISO 27001 mandatory in the UK? What each rule actually requires
Where UK public rules name a certification, it is Cyber Essentials. ISO 27001 is required when a customer's contract or tender requires it.
ISO 27001 is a voluntary international standard. The question behind “is it mandatory?” is narrower: does this contract, regulator or law require it? This page takes the UK rules that come up for suppliers one at a time, quotes what each one names, and says whether ISO 27001 is required, accepted as an equivalent, or not mentioned.
Rule by rule
| Rule | What it requires | Is ISO 27001 required? | Detail |
|---|---|---|---|
| UK GDPR (Article 32) | Security “appropriate to the risk” | No. Certification under Article 42 is voluntary and is not ISO 27001 | Article 32 |
| Central government contracts (PPN 014) | Cyber Essentials or Plus, or equivalent, for in-scope contracts | No. ISO 27001 holders “will not automatically conform” | Public sector |
| MOD contracts (DEFCON 658, Def Stan 05-138) | Cyber Essentials at every risk level; Plus from level 2 | No. The standard does not mention ISO 27001 | DEFCON 658 |
| Criminal legal aid (2025 Standard Crime Contract) | Cyber Essentials or an agreed equivalent | No; but whole-firm UKAS ISO 27001 is named as highly likely to count | Legal aid |
| Further education colleges (DfE) | Cyber Essentials under the funding agreement | No | Schools and colleges |
| NHS data and systems (DSPT) | The Data Security and Protection Toolkit | No. It cannot be submitted instead | NHS suppliers |
| FCA-regulated firms (operational resilience) | Important business services, impact tolerances, mapping, testing | No. The standard does not ask for those things | Financial services |
We list only rules we have read first-hand. Other regulators' licence conditions and individual frameworks are not covered here, and a specific tender can always ask for more.
Data protection law
UK GDPR Article 32
“Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:” It names measures, not standards. An ISO 27001 management system is one way to run and evidence them.
Certification under UK GDPR
The law has its own certification route, under Article 42, and it is optional: “Applying for certification is voluntary.” ISO 27001 is not one of those schemes. See UK GDPR certification.
Public sector and regulated buyers
Central government (PPN 014)
“Evidence of holding a Cyber Essentials certificate, whether basic level or Plus level, or equivalent, is required before contract award for in-scope contracts.” The policy note adds: “The ISO27001 standard is widely used but companies that attain this standard will not automatically conform to Cyber Essentials. This is because it is not usual for all of the five technical controls in Cyber Essentials to be included in the scope for ISO27001 implementation. It is also unlikely that any of these controls will be tested for ISO27001. Therefore most businesses with ISO27001 will have to adopt Cyber Essentials in addition to ISO27001 or demonstrate equivalent controls are in place.” And: “In-scope organisations must not take a blanket approach.”
Defence (DEFCON 658 and Def Stan 05-138)
“The Supplier shall have Cyber Essentials certification that covers the scope required for all aspects of the contract and commit to maintaining this for the duration of the contract.” The standard does not mention ISO 27001. See DEFCON 658.
Legal aid
The 2025 Standard Crime Contract requires Cyber Essentials “or an equivalent certification as may be agreed with us”. The LAA's guidance: “Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.” It also names whole-firm, UKAS-accredited ISO 27001 as highly likely to be an acceptable equivalent.
Schools and colleges
“Cyber Essentials is a requirement for colleges under their funding agreement.” The DfE's standards do not mention ISO 27001.
NHS
“All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly.” ISO 27001 does not replace the toolkit and cannot be submitted instead of it. What holding ISO 27001 does is reduce how much separate evidence you have to assemble, because work you have already done for the management system can be reused against toolkit items. The submission itself is still yours to make.
Financial services
An ISO 27001 certificate is evidence about an information security management system. It is not evidence that you have identified important business services, set impact tolerances or mapped and tested against them, because the standard does not ask for any of those things. Where the two meet is in the supplier’s own assurance pack: a regulated client doing third-party due diligence on you may ask for the certificate as one input, then ask operational-resilience questions the certificate cannot answer.
When ISO 27001 does become a requirement
A customer's contract or tender
A private buyer can require ISO 27001 in its contract, and then it is mandatory for that contract. Read the wording: the edition, the scope it expects to be covered, and whether the certificate must be accredited.
As an equivalent
Where a rule allows an equivalent to Cyber Essentials, an ISO 27001 certificate may be offered — the LAA's test is UKAS accreditation, whole-organisation scope and the five technical controls. See ISO 27001 vs Cyber Essentials.
Check what you were sent (our reading)
“ISO 27001 or equivalent”, “ISO 27001 certified” and “aligned to ISO 27001” are three different requests. Only the second needs a certificate.
Before you start a certification project
Find the sentence in the contract or tender that asks for it, and check whether Cyber Essentials, an equivalent, or ISO 27001 by name is what it says.
We do not give legal advice, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use, including when the answer is that you do not need ISO 27001. Each rule is quoted from its own text.
Where this fits
Common questions
Is ISO 27001 mandatory in the UK?
Not under any of the UK rules we have read: UK GDPR, the central government procurement policy on Cyber Essentials, the MOD's DEFCON 658, the legal aid crime contract, the DfE's standards, the NHS toolkit and the FCA's operational resilience rules. Where they name a certification it is Cyber Essentials. ISO 27001 becomes required when a customer's contract or tender says so.
Is ISO 27001 a legal requirement for GDPR?
No. Article 32 requires security “appropriate to the risk”. The certification UK GDPR describes is under Article 42, and the ICO says: “Applying for certification is voluntary.” ISO 27001 is not an Article 42 scheme.
Who needs ISO 27001?
Organisations whose customers, contracts or tenders ask for it. On the texts we have read, the public rules name Cyber Essentials, and in two cases (PPN 014, the legal aid contract) allow an equivalent. Commercial buyers set their own requirements, so the answer is in the contract you are bidding for.
Is ISO 27001 required for government contracts?
Not by PPN 014. “Evidence of holding a Cyber Essentials certificate, whether basic level or Plus level, or equivalent, is required before contract award for in-scope contracts.” And on ISO 27001: “The ISO27001 standard is widely used but companies that attain this standard will not automatically conform to Cyber Essentials. This is because it is not usual for all of the five technical controls in Cyber Essentials to be included in the scope for ISO27001 implementation. It is also unlikely that any of these controls will be tested for ISO27001. Therefore most businesses with ISO27001 will have to adopt Cyber Essentials in addition to ISO27001 or demonstrate equivalent controls are in place.”
Does a legal aid firm need ISO 27001?
No. The LAA's guidance: “Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.”
If it is not mandatory, why do suppliers get it?
Because a buyer asked. A private customer's contract can require it, and the public rules above name Cyber Essentials while leaving room for equivalents. The benefits page sets out what a certificate does and does not give you.
Sources cited on this page
- UK GDPR (Regulation (EU) 2016/679 as retained), legislation.gov.uk, Articles 32 and 42
- ICO, Certification schemes: a guide (updated 13 February 2026)
- PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
- Ministry of Defence, Def Stan 05-138 Issue 4, Cyber security for defence suppliers (published 23 May 2024), GOV.UK
- Legal Aid Agency, 2025 Standard Crime Contract — Standard Terms, version 1 (effective 1 October 2025)
- Legal Aid Agency, Provider Data Security Guidance v5 (October 2025)
- Department for Education, Cyber security standards for schools and colleges (updated 16 September 2026)
- NHS Data Security and Protection Toolkit
- FCA, Operational resilience
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A contract asking for ISO 27001?
Paste the wording it uses and say who the customer is.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.