ISO 27001 vs Cyber Essentials: which one a UK contract needs
Cyber Essentials checks that 5 technical controls are in place. ISO 27001 certifies the management system that decides which controls you need and keeps them working. UK public-sector procurement names the first; enterprise and international buyers usually ask for the second.
These two get treated as a small certificate and a large one, as though ISO 27001 were Cyber Essentials with more pages. They are different kinds of thing, owned by different bodies, and a contract that names one is not satisfied by assuming the other covers it.
ISO 27001 and Cyber Essentials, side by side
| ISO/IEC 27001 | Cyber Essentials | |
|---|---|---|
| Who owns it | ISO and IEC (an international standard) | The NCSC, the UK government’s cyber security authority |
| What it is | A management system: how you identify, treat and keep reviewing information security risk | 5 technical controls applied to your IT |
| What is checked | Clauses 4 to 10, plus the Annex A controls your risk assessment selected from 93 | Whether each of the five controls is in place across the scope |
| How it is assessed | Stage 1 and Stage 2 audits by a certification body | Cyber Essentials: a combination of self-assessment and independent audit. Cyber Essentials Plus adds independent technical testing |
| Scope | You define it; the persons doing work in scope drive the audit length | The whole IT infrastructure or a well-defined sub-set — and end-user devices and cloud services cannot be left out |
| Ongoing | Surveillance every year at one third of the initial audit; recertification in year three | Certificates are listed on a public register as current or not |
| Published price | None. Audit days are published; day rates are not | Cyber Essentials from £320 + VAT; Plus is quoted |
| Named by UK government procurement policy | No | Yes — PPN 014, “or equivalent” |
The row that decides most real cases is the last one. If a UK public-sector tender asks for Cyber Essentials, the question is not which scheme is more rigorous. It is what that contracting authority will accept, and that is its decision.
What Cyber Essentials actually checks
The NCSC organises the requirements under five technical controls, in NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026):
| Technical control | |
|---|---|
| 1 | Firewalls |
| 2 | Secure Configuration |
| 3 | Security Update Management |
| 4 | User Access Control |
| 5 | Malware Protection |
That is the whole scheme, and it is deliberately narrow. There is no risk assessment, no Statement of Applicability, no management review and no requirement to improve over time. What it buys is a clear, checkable baseline that a buyer can verify quickly.
The one requirement worth knowing by heart
Under security update management, all software on in-scope devices must “be updated, including vulnerability fixes, within 14 days of release, where: the update fixes vulnerabilities described by the vendor as ‘critical’ or ‘high risk’; the update addresses vulnerabilities with a CVSS v3 base score of 7 or above; there are no details of the level of vulnerabilities that the update fixes provided by the vendor”
So: 14 days for anything rated critical or high risk, or with a CVSS v3 base score of 7 or above — and also for any update where the vendor gives no severity at all. That last condition is the one teams miss, because it means an update with no severity information is treated as if it were critical.
Scope works differently, and v3.3 tightened it
This is where the two schemes diverge most in practice.
ISO 27001: you draw the boundary
You define the scope of your management system, and a narrower scope is legitimate. It also sets the price: the audit length is calculated from the persons doing work in scope.
Cyber Essentials: the default is everything
“Your assessment and certification should cover the whole of the IT infrastructure used to carry out your organisation’s business, or if necessary, a well-defined and separately managed sub-set.” You “must clearly define the scope boundary”, and “You must agree the scope with the Certification Body before assessment begins.” A partial scope is allowed, but “Where parts of an organisation’s infrastructure have been excluded from scope, you will need to justify the reason for a partial scope to your assessor.”
Two things cannot be left out at all. “A scope that doesn’t include end-user devices isn’t acceptable.” And:
“If your organisation’s data or services are hosted on cloud services, these services must be in scope. Cloud services cannot be excluded from scope.”
Cyber Essentials: Requirements for IT Infrastructure v3.3, April 2026
Why the cloud rule matters now
The NCSC lists this as new in version v3.3. For a SaaS supplier that scoped Cyber Essentials around its office network while its product and customer data lived in a cloud platform, that scope is no longer available. If your certificate renews under the current requirements, check the scope before you book the assessment, not during it.
| Change listed by the NCSC |
|---|
| Definition for ‘cloud services’ provided |
| Updated definition for Passwordless Authentication to include FIDO2 |
| Definitive statement that cloud services cannot be excluded from scope |
| Software Security Code of Practice introduced in Software Development section |
| Scope criteria no longer refers to ‘untrusted connections’ |
| Importance of backing up data is emphasised |
Cyber Essentials and Cyber Essentials Plus
The NCSC publishes its own comparison of the two levels:
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Same five technical controls | Yes | Yes |
| Independently verified | Yes | Yes |
| Technical audit / testing | No | Yes |
| Higher assurance | No (baseline) | Yes |
| Pricing approach | Tiered, from £320 + VAT | Quoted |
Plus is described as “The same protections, but with more rigorous, independent technical testing. This is priced according to the size and complexity of your network.” Neither level has a published price beyond the starting figure for the basic level, which the NCSC gives as £320 + VAT. The higher size bands we show on the cost page come from published summaries rather than from the scheme owner, and are labelled that way there.
How the basic level is actually done
Self-led: “Register for certification via IASME, make the payment, then complete the verified self-assessment. Your answers will be signed-off by a board member or equivalent and then marked by an assessor.” Or supported, by hiring a certification body licensed to assess against the requirements. Note the board-level sign-off: the self-assessment is a statement by the organisation, not by whoever filled it in.
Which one does the contract need?
UK central government and the wider public sector
PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note) requires Cyber Essentials or Cyber Essentials Plus, or equivalent, before contract award for in-scope contracts. Read “or equivalent” carefully, because it is doing a lot of work and it is not your decision. The contracting authority decides what it will accept as equivalent. Some buying organisations state in terms that ISO 27001 is not an acceptable substitute for Cyber Essentials Plus. So the certificate you hold may satisfy one authority and not the next, and the only way to find out is to read the tender and ask. What government contracts require goes through it.
NHS suppliers
Neither certificate replaces the NHS Data Security and Protection Toolkit, which has its own annual submission. The NHS supplier page covers the order in which most suppliers do them.
Enterprise customers and international buyers
Usually ISO 27001, and usually by name. Cyber Essentials is a UK scheme; ISO 27001 is the one a vendor-risk team in another country will recognise. For US buyers, SOC 2 is the more common ask — a comparison we have not published, because the criteria it is assessed against could not be read first-hand.
Nobody has named anything yet
Start with Cyber Essentials. It is cheaper, faster and narrower, it is what the public sector names, and none of the work is wasted if you later go on to ISO 27001.
Check a supplier's claim
“Find all current Cyber Essentials certificates on our Cyber Essentials Delivery Partner IASME’s website.” Cyber Essentials certificates can be looked up centrally, which ISO 27001 certificates cannot — for those, read the certificate itself.
What each costs
Cyber Essentials has a published starting price of £320 + VAT from the NCSC. ISO 27001 has no published price at all — what is published is the number of audit days. At 10 people that is 5 days of certification audit, which at our estimated UK day rates comes to roughly £5,500 to £7,500 before any preparation. That is our estimate, not a published figure, and the method says how it is built.
The gap is real and it is the honest reason most small UK suppliers should do Cyber Essentials first. The calculator gives the ISO 27001 figure for your own headcount.
The insurance condition
The NCSC also states: “Any UK organisation with a turnover under £20m, that achieves certification covering their whole organisation, is automatically entitled to Cyber Liability Insurance arranged by our Cyber Essentials’ Delivery Partner, IASME.” The condition that bites is the last one: certification covering the whole organisation. A sub-set scope does not qualify. We have not read the policy terms and would not rely on this without doing so.
We are paid by ISO 27001 consultancies, a fixed fee per enquiry agreed in advance and unchanged by what you decide. This page nonetheless tells most small UK suppliers to start with the cheaper scheme that is not ISO 27001, because that is what the requirements and the procurement policy support.
Where this goes next
- Public sector tenders
- What ISO 27001 costs
- Certified, compliant, accredited
- How an ISO 27001 audit runs
- SaaS and cloud suppliers
Common questions
What is the difference between ISO 27001 and Cyber Essentials?
They answer different questions. Cyber Essentials, owned by the NCSC, checks whether 5 technical controls are in place across your IT: firewalls, secure configuration, security update management, user access control and malware protection. ISO 27001 certifies a management system — whether you have a working process for identifying information security risk, deciding what to do about it and keeping that under review. Cyber Essentials is a set of controls; ISO 27001 is the machinery that decides which controls you need and proves you keep operating them.
Does ISO 27001 replace Cyber Essentials?
Not for UK public-sector contracts that ask for it. PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note) requires Cyber Essentials or Cyber Essentials Plus, or equivalent, before contract award for in-scope contracts, and whether ISO 27001 counts as equivalent is the contracting authority's decision, not yours. Some buying organisations say in terms that it does not. If a tender names Cyber Essentials, read the requirement and ask a clarification question rather than assuming.
Which should we do first?
For most UK suppliers starting from nothing, Cyber Essentials. It is what public-sector procurement names, its published price starts at £320 + VAT, and the five controls are ones an ISO 27001 management system will need anyway. Go to ISO 27001 when a customer asks for it by name, when you sell to large enterprises or outside the UK, or when you need to answer questions about governance, risk and suppliers that five technical controls do not reach.
Can cloud services be left out of Cyber Essentials scope?
Not any more. Version v3.3 of the NCSC requirements (April 2026) states: “If your organisation’s data or services are hosted on cloud services, these services must be in scope. Cloud services cannot be excluded from scope.” It lists this as new in that version. A supplier whose certificate was scoped around its office network while its product ran in the cloud should expect that scope not to be accepted at renewal.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
The NCSC describes Cyber Essentials as a combination of self-assessment and independent audit, and Cyber Essentials Plus as “The same protections, but with more rigorous, independent technical testing. This is priced according to the size and complexity of your network.” Both cover the same five controls. The difference is that Plus independently tests your systems to verify the controls work in practice. Cyber Essentials is priced by organisation size from £320 + VAT; Plus is quoted.
How do I check whether a supplier holds Cyber Essentials?
The NCSC points to a public register: “Find all current Cyber Essentials certificates on our Cyber Essentials Delivery Partner IASME’s website.” So unlike ISO 27001, where you check the certificate against the issuing certification body, a Cyber Essentials certificate can be looked up centrally. It is worth doing for any supplier that claims it.
Is there really free insurance with Cyber Essentials?
The NCSC says so, with conditions: “Any UK organisation with a turnover under £20m, that achieves certification covering their whole organisation, is automatically entitled to Cyber Liability Insurance arranged by our Cyber Essentials’ Delivery Partner, IASME.” Two conditions matter: the turnover ceiling of £20m, and certification covering the whole organisation. A sub-set scope does not qualify. Read the policy terms yourself before relying on it; we have not.
Do the two overlap enough to do both at once?
The five Cyber Essentials controls map onto technological controls an ISO 27001 management system is very likely to select anyway, so doing Cyber Essentials first is rarely wasted work. What does not carry over is the management system itself — the risk assessment, the Statement of Applicability, the internal audit and the management review have no Cyber Essentials counterpart.
Sources cited on this page
- NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026)
- NCSC, Cyber Essentials overview
- PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Not sure which one your contract is asking for?
Say what triggered this and who the customer is. That usually settles which scheme you need.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.