Which certification your business actually needs · Last reviewed 16 September 2026
Cyber Essentials covers five technical controls, is assessed by questionnaire and takes weeks. ISO 27001 covers how your whole organisation manages information security, is audited externally and takes months. Cyber Essentials proves specific protections exist; ISO 27001 proves you run security as a managed, improving discipline.
They are often presented as rivals. They are not: they answer different questions, and plenty of organisations hold both. The practical decision is usually driven by what your customers, insurers and tender documents are asking for, and how much time you have.
Cyber Essentials is a UK government-backed scheme, overseen by the National Cyber Security Centre and delivered through IASME. It focuses on five technical controls that between them block the large majority of common internet-borne attacks:
Basic Cyber Essentials is a self-assessment questionnaire verified by a certification body. Cyber Essentials Plus covers identical ground but adds an independent technical audit, where an assessor tests a sample of your machines rather than trusting the answers. Certification is annual, and the question set changes: the 2026 update tightened requirements around multi-factor authentication, patching and unsupported software.
ISO/IEC 27001 is the international standard for an information security management system, or ISMS. Rather than prescribing a fixed technical checklist, it requires you to identify your risks, decide which controls address them, implement those controls, and then keep reviewing and improving the whole arrangement.
The current version, ISO/IEC 27001:2022, lists 93 controls in Annex A across four themes: organisational, people, physical and technological. You are not obliged to apply all 93. You justify what applies to your organisation and record why anything is excluded, which is why two certified companies can look quite different.
Certification is granted by an external certification body after an audit, and a certificate runs for three years with annual surveillance audits in between.
| Cyber Essentials | ISO 27001 | |
|---|---|---|
| Scope | Five technical controls | Whole management system: people, process, physical, technical |
| Approach | Prescriptive checklist | Risk-based, you justify the controls |
| Assessment | Self-assessment questionnaire; Plus adds a technical audit | External audit by a certification body |
| Typical timescale | Weeks | Months |
| Relative cost | Low, with most effort in fixing gaps | Significantly higher, plus ongoing management time |
| Renewal | Annual | Three-year certificate, annual surveillance audits |
| Recognition | UK, strong in public sector procurement | International, strong in enterprise procurement |
| Answers the question | "Are the basic protections in place?" | "Do you manage security properly, all the time?" |
Start with who is asking. If nobody has asked at all, Cyber Essentials is still worth doing, because the five controls are the same ones that prevent most real-world incidents and the same ones insurers ask about.
Cyber Essentials, almost always. It is quick, it is comparatively cheap, and the work it forces, patching discipline, multi-factor authentication, removing unsupported software, access control, is foundational to ISO 27001 anyway. You also get something to show customers within weeks instead of waiting for a months-long project to complete.
The usual blocker is not the paperwork. It is discovering that something in the estate is out of support, which fails the security update control outright. On desktops that is typically Windows 10; on servers, Windows Server 2016, which loses support on 12 January 2027.
Both certifications are easier with a provider who lives in the detail, and considerably easier if the day-to-day controls are already being managed: patching inside the window, MFA enforced, supported software, access reviewed, backups tested. That is ordinary managed IT support rather than a special project, which is why certification tends to be painless for organisations that already have it and painful for those that do not.
Mastercopy holds ISO 27001, ISO 9001 and Cyber Essentials, all verifiable on our trust centre. We have been through both processes ourselves, which is a rather different position from advising on them in theory.
Cyber Essentials is a UK government-backed scheme covering five technical controls, assessed by questionnaire and achievable in weeks. ISO 27001 is an international standard for an information security management system, covering people, process and physical security as well as technology, assessed by an external auditor and typically taking months. Cyber Essentials proves specific protections are in place; ISO 27001 proves you manage security as an ongoing discipline.
Cyber Essentials is the common baseline, and is a requirement for certain UK government contracts that involve handling sensitive information. Larger private-sector and enterprise procurement, particularly where you process significant volumes of customer data, more often asks for ISO 27001. Check the specific tender documents, because some ask for Cyber Essentials Plus rather than the basic certificate.
Cyber Essentials is a self-assessment questionnaire, verified by a certification body. Cyber Essentials Plus covers the same five controls but adds an independent hands-on technical audit, where an assessor tests a sample of your devices and systems rather than taking your answers on trust. Plus carries more weight with customers for that reason.
Cyber Essentials can realistically be achieved in a few weeks, and most of that time is spent fixing technical gaps such as unsupported software, missing multi-factor authentication or patching delays rather than completing the questionnaire. ISO 27001 usually takes several months, because you have to build and run a management system before an auditor can assess it.
ISO/IEC 27001:2022 lists 93 controls in Annex A, grouped into four themes: organisational, people, physical and technological. You are not required to implement all of them. The standard is risk-based, so you justify which controls apply to your organisation and document why any are excluded.
Usually, yes. Cyber Essentials tackles the technical basics quickly and cheaply, and those same controls support the ISO 27001 work later. Starting with Cyber Essentials also gives you a certificate to put in front of customers within weeks, rather than waiting months for the larger project to finish.
Yes. Cyber Essentials is certified annually, so the assessment is repeated each year against the current question set. An ISO 27001 certificate runs for three years, with annual surveillance audits in between and a full recertification audit at the end of the cycle.
Sources: scheme details from the NCSC Cyber Essentials overview and ISO/IEC 27001, checked 16 September 2026. Certification bodies publish current fees; requirements are reviewed periodically, so confirm details before budgeting.
A free review of where you stand against the Cyber Essentials controls, what would fail today, and what it takes to fix it.
ISO 27001 and ISO 9001 certified · Cyber Essentials · Same-day on-site engineers · Trading since 1989