iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 vs Cyber Essentials: which one a UK contract needs

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 10 min read
5 primary sources cited on this page. How we check what is on this site
The one-line answer Different questions, not bigger and smaller

Cyber Essentials checks that 5 technical controls are in place. ISO 27001 certifies the management system that decides which controls you need and keeps them working. UK public-sector procurement names the first; enterprise and international buyers usually ask for the second.

These two get treated as a small certificate and a large one, as though ISO 27001 were Cyber Essentials with more pages. They are different kinds of thing, owned by different bodies, and a contract that names one is not satisfied by assuming the other covers it.

ISO 27001 and Cyber Essentials, side by side

ISO 27001 against Cyber Essentials
ISO/IEC 27001Cyber Essentials
Who owns itISO and IEC (an international standard)The NCSC, the UK government’s cyber security authority
What it isA management system: how you identify, treat and keep reviewing information security risk5 technical controls applied to your IT
What is checkedClauses 4 to 10, plus the Annex A controls your risk assessment selected from 93Whether each of the five controls is in place across the scope
How it is assessedStage 1 and Stage 2 audits by a certification bodyCyber Essentials: a combination of self-assessment and independent audit. Cyber Essentials Plus adds independent technical testing
ScopeYou define it; the persons doing work in scope drive the audit lengthThe whole IT infrastructure or a well-defined sub-set — and end-user devices and cloud services cannot be left out
OngoingSurveillance every year at one third of the initial audit; recertification in year threeCertificates are listed on a public register as current or not
Published priceNone. Audit days are published; day rates are notCyber Essentials from £320 + VAT; Plus is quoted
Named by UK government procurement policyNoYes — PPN 014, “or equivalent”

The row that decides most real cases is the last one. If a UK public-sector tender asks for Cyber Essentials, the question is not which scheme is more rigorous. It is what that contracting authority will accept, and that is its decision.

What Cyber Essentials actually checks

The NCSC organises the requirements under five technical controls, in NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026):

The five Cyber Essentials technical controls (Cyber Essentials: Requirements for IT Infrastructure v3.3, April 2026)
Technical control
1Firewalls
2Secure Configuration
3Security Update Management
4User Access Control
5Malware Protection

That is the whole scheme, and it is deliberately narrow. There is no risk assessment, no Statement of Applicability, no management review and no requirement to improve over time. What it buys is a clear, checkable baseline that a buyer can verify quickly.

The one requirement worth knowing by heart

Under security update management, all software on in-scope devices must “be updated, including vulnerability fixes, within 14 days of release, where: the update fixes vulnerabilities described by the vendor as ‘critical’ or ‘high risk’; the update addresses vulnerabilities with a CVSS v3 base score of 7 or above; there are no details of the level of vulnerabilities that the update fixes provided by the vendor”

So: 14 days for anything rated critical or high risk, or with a CVSS v3 base score of 7 or above — and also for any update where the vendor gives no severity at all. That last condition is the one teams miss, because it means an update with no severity information is treated as if it were critical.

Scope works differently, and v3.3 tightened it

This is where the two schemes diverge most in practice.

ISO 27001: you draw the boundary

You define the scope of your management system, and a narrower scope is legitimate. It also sets the price: the audit length is calculated from the persons doing work in scope.

Cyber Essentials: the default is everything

“Your assessment and certification should cover the whole of the IT infrastructure used to carry out your organisation’s business, or if necessary, a well-defined and separately managed sub-set.” You “must clearly define the scope boundary”, and “You must agree the scope with the Certification Body before assessment begins.” A partial scope is allowed, but “Where parts of an organisation’s infrastructure have been excluded from scope, you will need to justify the reason for a partial scope to your assessor.”

Two things cannot be left out at all. “A scope that doesn’t include end-user devices isn’t acceptable.” And:

“If your organisation’s data or services are hosted on cloud services, these services must be in scope. Cloud services cannot be excluded from scope.”

Cyber Essentials: Requirements for IT Infrastructure v3.3, April 2026

Why the cloud rule matters now

The NCSC lists this as new in version v3.3. For a SaaS supplier that scoped Cyber Essentials around its office network while its product and customer data lived in a cloud platform, that scope is no longer available. If your certificate renews under the current requirements, check the scope before you book the assessment, not during it.

What changed in Cyber Essentials v3.3 (April 2026)
Change listed by the NCSC
Definition for ‘cloud services’ provided
Updated definition for Passwordless Authentication to include FIDO2
Definitive statement that cloud services cannot be excluded from scope
Software Security Code of Practice introduced in Software Development section
Scope criteria no longer refers to ‘untrusted connections’
Importance of backing up data is emphasised

Cyber Essentials and Cyber Essentials Plus

The NCSC publishes its own comparison of the two levels:

Cyber Essentials against Cyber Essentials Plus, as the NCSC compares them
Cyber EssentialsCyber Essentials Plus
Same five technical controlsYesYes
Independently verifiedYesYes
Technical audit / testingNoYes
Higher assuranceNo (baseline)Yes
Pricing approachTiered, from £320 + VATQuoted

Plus is described as “The same protections, but with more rigorous, independent technical testing. This is priced according to the size and complexity of your network.” Neither level has a published price beyond the starting figure for the basic level, which the NCSC gives as £320 + VAT. The higher size bands we show on the cost page come from published summaries rather than from the scheme owner, and are labelled that way there.

How the basic level is actually done

Self-led: “Register for certification via IASME, make the payment, then complete the verified self-assessment. Your answers will be signed-off by a board member or equivalent and then marked by an assessor.” Or supported, by hiring a certification body licensed to assess against the requirements. Note the board-level sign-off: the self-assessment is a statement by the organisation, not by whoever filled it in.

Which one does the contract need?

UK central government and the wider public sector

PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note) requires Cyber Essentials or Cyber Essentials Plus, or equivalent, before contract award for in-scope contracts. Read “or equivalent” carefully, because it is doing a lot of work and it is not your decision. The contracting authority decides what it will accept as equivalent. Some buying organisations state in terms that ISO 27001 is not an acceptable substitute for Cyber Essentials Plus. So the certificate you hold may satisfy one authority and not the next, and the only way to find out is to read the tender and ask. What government contracts require goes through it.

NHS suppliers

Neither certificate replaces the NHS Data Security and Protection Toolkit, which has its own annual submission. The NHS supplier page covers the order in which most suppliers do them.

Enterprise customers and international buyers

Usually ISO 27001, and usually by name. Cyber Essentials is a UK scheme; ISO 27001 is the one a vendor-risk team in another country will recognise. For US buyers, SOC 2 is the more common ask — a comparison we have not published, because the criteria it is assessed against could not be read first-hand.

Nobody has named anything yet

Start with Cyber Essentials. It is cheaper, faster and narrower, it is what the public sector names, and none of the work is wasted if you later go on to ISO 27001.

Check a supplier's claim

“Find all current Cyber Essentials certificates on our Cyber Essentials Delivery Partner IASME’s website.” Cyber Essentials certificates can be looked up centrally, which ISO 27001 certificates cannot — for those, read the certificate itself.

What each costs

Cyber Essentials has a published starting price of £320 + VAT from the NCSC. ISO 27001 has no published price at all — what is published is the number of audit days. At 10 people that is 5 days of certification audit, which at our estimated UK day rates comes to roughly £5,500 to £7,500 before any preparation. That is our estimate, not a published figure, and the method says how it is built.

The gap is real and it is the honest reason most small UK suppliers should do Cyber Essentials first. The calculator gives the ISO 27001 figure for your own headcount.

The insurance condition

The NCSC also states: “Any UK organisation with a turnover under £20m, that achieves certification covering their whole organisation, is automatically entitled to Cyber Liability Insurance arranged by our Cyber Essentials’ Delivery Partner, IASME.” The condition that bites is the last one: certification covering the whole organisation. A sub-set scope does not qualify. We have not read the policy terms and would not rely on this without doing so.

We are paid by ISO 27001 consultancies, a fixed fee per enquiry agreed in advance and unchanged by what you decide. This page nonetheless tells most small UK suppliers to start with the cheaper scheme that is not ISO 27001, because that is what the requirements and the procurement policy support.

Where this goes next

Common questions

What is the difference between ISO 27001 and Cyber Essentials?

They answer different questions. Cyber Essentials, owned by the NCSC, checks whether 5 technical controls are in place across your IT: firewalls, secure configuration, security update management, user access control and malware protection. ISO 27001 certifies a management system — whether you have a working process for identifying information security risk, deciding what to do about it and keeping that under review. Cyber Essentials is a set of controls; ISO 27001 is the machinery that decides which controls you need and proves you keep operating them.

Does ISO 27001 replace Cyber Essentials?

Not for UK public-sector contracts that ask for it. PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note) requires Cyber Essentials or Cyber Essentials Plus, or equivalent, before contract award for in-scope contracts, and whether ISO 27001 counts as equivalent is the contracting authority's decision, not yours. Some buying organisations say in terms that it does not. If a tender names Cyber Essentials, read the requirement and ask a clarification question rather than assuming.

Which should we do first?

For most UK suppliers starting from nothing, Cyber Essentials. It is what public-sector procurement names, its published price starts at £320 + VAT, and the five controls are ones an ISO 27001 management system will need anyway. Go to ISO 27001 when a customer asks for it by name, when you sell to large enterprises or outside the UK, or when you need to answer questions about governance, risk and suppliers that five technical controls do not reach.

Can cloud services be left out of Cyber Essentials scope?

Not any more. Version v3.3 of the NCSC requirements (April 2026) states: “If your organisation’s data or services are hosted on cloud services, these services must be in scope. Cloud services cannot be excluded from scope.” It lists this as new in that version. A supplier whose certificate was scoped around its office network while its product ran in the cloud should expect that scope not to be accepted at renewal.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The NCSC describes Cyber Essentials as a combination of self-assessment and independent audit, and Cyber Essentials Plus as “The same protections, but with more rigorous, independent technical testing. This is priced according to the size and complexity of your network.” Both cover the same five controls. The difference is that Plus independently tests your systems to verify the controls work in practice. Cyber Essentials is priced by organisation size from £320 + VAT; Plus is quoted.

How do I check whether a supplier holds Cyber Essentials?

The NCSC points to a public register: “Find all current Cyber Essentials certificates on our Cyber Essentials Delivery Partner IASME’s website.” So unlike ISO 27001, where you check the certificate against the issuing certification body, a Cyber Essentials certificate can be looked up centrally. It is worth doing for any supplier that claims it.

Is there really free insurance with Cyber Essentials?

The NCSC says so, with conditions: “Any UK organisation with a turnover under £20m, that achieves certification covering their whole organisation, is automatically entitled to Cyber Liability Insurance arranged by our Cyber Essentials’ Delivery Partner, IASME.” Two conditions matter: the turnover ceiling of £20m, and certification covering the whole organisation. A sub-set scope does not qualify. Read the policy terms yourself before relying on it; we have not.

Do the two overlap enough to do both at once?

The five Cyber Essentials controls map onto technological controls an ISO 27001 management system is very likely to select anyway, so doing Cyber Essentials first is rarely wasted work. What does not carry over is the management system itself — the risk assessment, the Statement of Applicability, the internal audit and the management review have no Cyber Essentials counterpart.

Sources cited on this page

  1. NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026)
  2. NCSC, Cyber Essentials overview
  3. PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
  4. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  5. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Not sure which one your contract is asking for?

Say what triggered this and who the customer is. That usually settles which scheme you need.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now