Cyber Essentials Plus, Cyber Essentials and ISO 27001 get talked about as three rungs on one ladder, and that is the first mistake. Two of them certify a fixed set of five technical controls. The third certifies a management system that decides which controls you need at all. They answer different questions, they are bought by different people, and the gap between the cheapest and the dearest is roughly fifty times.
The practical question is almost never “which is best”. It is “which one unlocks the contract in front of me, at the lowest cost, in the time I have left”. A procurement portal asking for a certificate number by the end of the month is a different problem from an enterprise security questionnaire asking how you treat risk. Answer the wrong one and you spend nine months and £25,000 on an accreditation nobody asked for.
This guide sets the three schemes side by side on assessment method, cost, elapsed time, scope, renewal and buyer recognition. It works through the five Cyber Essentials controls, the five test cases behind Cyber Essentials Plus, and the clauses and Annex A controls that ISO 27001 adds on top. It closes with a decision path, the overlap you can reuse if you end up doing both, and the questions buyers actually ask.
Table of contents
- Cyber Essentials, Cyber Essentials Plus and ISO 27001 at a Glance
- What the Five Cyber Essentials Controls Actually Require
- How Cyber Essentials Plus Verification Really Works
- What ISO 27001 Adds That Cyber Essentials Plus Does Not
- Cyber Essentials Plus vs ISO 27001 on Cost and Time
- Which Certification Your Buyers and Contracts Actually Demand
- What Neither Certification Protects You From
- Choosing Between Cyber Essentials Plus and ISO 27001
- Running Cyber Essentials Plus and ISO 27001 Together
- Cyber Essentials Plus and ISO 27001 Questions Answered
- References
Cyber Essentials, Cyber Essentials Plus and ISO 27001 at a Glance
The three certifications differ on one axis more than any other: who checks the answers. Cyber Essentials is a self-assessment questionnaire that an assessor marks. Cyber Essentials Plus is the same questionnaire plus a hands-on technical audit of your live estate. ISO 27001 is an audit of a management system by an accredited certification body, repeated on a three-year cycle.
That difference cascades into everything else. A self-assessment can be finished in a fortnight. A technical audit needs a booked assessor, a device sample and working remote access. A management system needs documented risk decisions, an internal audit function and evidence that senior management reviews the thing.
The one-line version of each scheme
Cyber Essentials proves you have the five basic technical controls in place, on your word, checked against a marking scheme. Cyber Essentials Plus proves the same five controls actually work, because somebody tested them. ISO 27001 proves you run a repeatable process for deciding which risks matter and what you do about them.
Where each one stops
Cyber Essentials stops at the technical baseline. It says nothing about staff vetting, supplier contracts, physical security, business continuity or how you handle an incident. Cyber Essentials Plus stops in exactly the same place, with better evidence. ISO 27001 covers all of that, but it does not mandate any specific technical standard, which is why some buyers ask for both.
| Factor | Cyber Essentials | Cyber Essentials Plus | ISO 27001 |
|---|---|---|---|
| What it certifies | Five technical controls | Five technical controls, verified | An information security management system |
| Assessment method | Self-assessment, marked | Self-assessment plus technical audit | Stage 1 and Stage 2 audit |
| Who assesses | IASME certification body | IASME assessor, on your estate | Accredited certification body |
| Typical first-year cost | £320-£600 plus VAT | £1,700-£3,600 all-in | £6,000-£48,000 |
| Typical elapsed time | 1-4 weeks | 4-10 weeks | 6-12 months |
| Certificate validity | 12 months | 12 months | 3 years, with annual surveillance |
| Scope you choose | Whole organisation or defined sub-scope | Must match the Cyber Essentials scope | Any defined scope you can justify |
| Risk assessment required | No | No | Yes, and documented |
| Strongest with | UK public sector, small suppliers | MoD, NHS, higher-risk UK contracts | Enterprise and international buyers |
What the Five Cyber Essentials Controls Actually Require
Both Cyber Essentials and Cyber Essentials Plus are assessed against the same document: the NCSC’s Requirements for IT Infrastructure, currently version 3.3, effective from 27 April 2026. The five controls have not changed in years. What changes is how tightly they are interpreted, and version 3.3 tightened several definitions again.
Firewalls and secure configuration
Every device that connects to the internet needs a correctly configured boundary firewall or a host-based firewall. Default administrative passwords must be changed, unnecessary user accounts removed, and any service that is not needed disabled. Auto-run of software from removable media has to be off or controlled.
Security update management
This is the control that fails more applicants than any other. Software must be licensed and supported, and updates that fix vulnerabilities rated high or critical — CVSS v3 score of 7.0 or above — must be applied within 14 days of release. Unsupported software anywhere in scope is an automatic fail, with no partial credit.
User access control and malware protection
Accounts are created through an approved process, administrative privileges are separated from day-to-day accounts, and multi-factor authentication is mandatory on all cloud services. Malware protection must be present on every in-scope device, either through anti-malware software, application allow-listing, or the platform’s own controls on modern mobile devices.
Scope is the decision that costs the most money
Before any of the five controls is assessed, you declare a scope, and that single choice drives the price and difficulty of everything downstream. The default is the whole organisation. You may certify a defined sub-scope instead — one business unit, one network segment — but it has to be genuinely separated, not merely described as separate, and the boundary must be defensible to an assessor.
Sub-scoping looks attractive and usually is not. A segment that shares a domain, a file server or an identity provider with the rest of the business is not separated. Worse, a sub-scope you win a contract on has to stay separated for the life of that contract. Most organisations that try it end up certifying everything the following year anyway, having paid twice.
Whatever you declare for Cyber Essentials becomes the scope for Cyber Essentials Plus, because the audit tests the same boundary the questionnaire described. Under ISO 27001 the scoping logic is different again: you justify the boundary against your risk assessment and interested parties, and the certification body challenges it directly.
Why the controls matter more than the certificate
The five controls are deliberately unglamorous. They are the ones that stop the attacks most UK organisations actually face, which is why the Cyber Security Breaches Survey 2025 keeps finding phishing and unpatched systems at the top of the incident list. A vulnerability assessment run before you apply usually tells you within a day whether the five controls are genuinely in place.
How Cyber Essentials Plus Verification Really Works
Cyber Essentials Plus is not a harder questionnaire. It is the same questionnaire, followed by an assessor who tests whether your answers hold. You must already hold a valid Cyber Essentials certificate, and the Cyber Essentials Plus assessment has to be completed within three months of that basic certificate being awarded. Miss the window and you re-sit the self-assessment first.
The device sample
The assessor does not test everything. They take a representative sample across each operating system and build combination in scope — a slice of Windows laptops, a slice of macOS machines, whatever mobile platforms you issue, and the servers that matter. The sample size scales with the size of the estate, so a 300-device organisation gets meaningfully more scrutiny than a 12-device one.
The five test cases
The tests come from the NCSC’s Cyber Essentials Plus Illustrative Test Specification, currently version 3.2. They are deliberately practical: an external scan, an internal patch scan, two malware delivery tests, and a check that multi-factor authentication is genuinely enforced rather than merely available.
| Test case | What the assessor does | What usually fails it |
|---|---|---|
| External vulnerability scan | Scans every public-facing IP address in scope | A forgotten test server or an exposed management port |
| Authenticated device scan | Runs a credentialed patch scan on the sampled devices | Third-party apps past the 14-day window, not the OS |
| Malware by email | Sends harmless test files to a real mailbox | A filtering gap on one mailbox type or alias |
| Malware by web download | Downloads harmless test files in a browser | Browsers or devices outside the managed build |
| Account separation and MFA | Checks MFA and admin separation on cloud services | A director reading email from an admin account |
Preparing properly costs less than failing
The organisations that pass Cyber Essentials Plus first time do three things in the fortnight beforehand. They produce an accurate device inventory and reconcile it against the estate, because the assessor’s sample is drawn from what actually exists rather than what the spreadsheet claims. They run their own credentialed patch scan and fix what it finds. And they confirm multi-factor authentication is enforced on every cloud service, including the ones marketing bought without telling anyone.
The fourth thing is unglamorous: check every piece of software for a supported version, including firmware on routers and firewalls. Unsupported software is the single most common structural failure, and unlike a missing patch it cannot be corrected in an afternoon.
Why Cyber Essentials Plus fails at the last minute
The self-assessment is answered by someone who believes the estate is in a certain state. The Cyber Essentials Plus audit measures the estate as it is. The gap between the two is where applications die — usually a device nobody logged, or a patching policy that covers Windows but not the eleven third-party applications on it. Most of the common Cyber Essentials failure reasons only become visible under this kind of testing.
What ISO 27001 Adds That Cyber Essentials Plus Does Not
ISO/IEC 27001:2022 is not a bigger version of Cyber Essentials Plus. It is a different object. The certified thing is an information security management system: the process by which your organisation identifies risks, decides what to do about them, checks that it happened, and improves. The controls are an output of that process, not the standard itself.
The mandatory clauses
Clauses 4 to 10 are where the real work sits, and none of them has an equivalent in Cyber Essentials Plus. You define the scope and the interested parties, secure demonstrable leadership commitment, run a documented risk assessment and risk treatment, set measurable objectives, operate an internal audit programme, and hold management reviews. An auditor will spend as much time on these as on any technical control.
Annex A and the Statement of Applicability
The 2022 revision restructured Annex A into 93 controls across four themes: organisational, people, physical and technological. You are not required to implement all 93. You are required to consider each one and record, in a Statement of Applicability, whether it applies and why. That document is the spine of the audit.
| Requirement | Cyber Essentials Plus | ISO 27001 |
|---|---|---|
| Documented risk assessment | Not required | Mandatory, and re-run on change |
| Statement of Applicability | Not required | Mandatory, covering 93 controls |
| Internal audit programme | Not required | Mandatory, on a planned cycle |
| Management review | Not required | Mandatory, minuted |
| Supplier security controls | Out of scope | Annex A 5.19-5.23 |
| HR and staff screening | Out of scope | Annex A 6.1-6.6 |
| Physical security | Out of scope | Annex A 7.1-7.14 |
| Incident management process | Out of scope | Annex A 5.24-5.28 |
| Business continuity | Out of scope | Annex A 5.29-5.30 |
| Independent technical testing | Yes, every year | Only if your risk assessment says so |
The three-year cycle nobody budgets for
ISO 27001 certification is not an event, it is a cycle. The initial assessment splits into Stage 1, a documentation and readiness review, and Stage 2, the full implementation audit. Pass both and the certificate runs for three years — but only if you pass a surveillance audit in year one and year two, then a full recertification in year three.
That structure changes the budgeting question completely. Cyber Essentials Plus is a fixed annual cost you can forecast exactly. ISO 27001 is a large year-one number followed by two smaller surveillance years and a third large one, plus the internal effort of keeping the management system alive between audits. Organisations that treat the year-one quote as the total price are routinely surprised.
The uncomfortable asymmetry
That last row is worth sitting with. ISO 27001 is broader on governance and narrower on proof of technical hygiene. Nothing in the standard forces an authenticated patch scan of your laptops. Cyber Essentials Plus forces exactly that, every year. This is why a mature buyer will sometimes accept ISO 27001 alone, and sometimes insist on Cyber Essentials Plus alongside it. They are testing different things.
Cyber Essentials Plus vs ISO 27001 on Cost and Time
Cost is where the three schemes separate most violently. Cyber Essentials is a fixed, published price tied to headcount: £320 plus VAT for a micro organisation of nine people or fewer, rising to £600 plus VAT at 250 people and above. Cyber Essentials Plus has no fixed price — each certification body sets its own fee based on the size and messiness of the estate.
What Cyber Essentials Plus actually costs
For a straightforward small business on one managed platform, budget £1,400 to £2,500 plus VAT for the Cyber Essentials Plus audit itself, on top of the basic certificate. Multiple operating systems, bring-your-own-device, several sites or a large device sample push that toward £4,000 and beyond. Remediation is the wildcard: if the audit finds unsupported software, the cost is replacing it, not the assessment.
What ISO 27001 actually costs
Certification body audit days run roughly £900 to £1,500 each, and a small business needs several across Stage 1 and Stage 2. Add the implementation work and the realistic first-year range is £6,000 to £15,000 for a micro business and £14,000 to £30,000 for a typical small one, as broken down in our ISO 27001 certification cost guide.
Elapsed time is the constraint that actually bites
Money is negotiable; a tender deadline is not. Cyber Essentials can be turned around in a fortnight if your estate is already clean. Cyber Essentials Plus adds the wait for an assessor booking plus the audit itself. ISO 27001 needs a risk assessment, a documented management system and — critically — enough operating history for an auditor to see the internal audit and management review cycles having actually run.
Which Certification Your Buyers and Contracts Actually Demand
Nobody buys a certificate for its own sake. They buy it because a customer, a framework or an insurer asked. So the right way to choose is to read what is actually being asked for, in writing, before spending anything.
The UK public sector position
Procurement Policy Note 09/14 requires Cyber Essentials for central government contracts that involve handling personal information or providing certain ICT services. Some higher-risk contracts — defence work in particular — specify Cyber Essentials Plus rather than the basic tier. NHS organisations and their suppliers meet related expectations through the Data Security and Protection Toolkit, which references Cyber Essentials Plus for some categories.
Enterprise and international buyers
Large corporate and overseas buyers usually ask for ISO 27001 because it is the standard their own auditors recognise. A UK-only certification often means nothing to a procurement team in Frankfurt or Chicago. If your growth plan involves selling to enterprises outside the UK, ISO 27001 is the one that travels.
| Who is asking | Usually wants | Why |
|---|---|---|
| UK central government | Cyber Essentials | PPN 09/14 sets it as the baseline |
| MoD and defence supply chain | Cyber Essentials Plus | Risk profile demands verified controls |
| NHS and health suppliers | Cyber Essentials Plus | Referenced by the DSP Toolkit |
| Large UK corporates | ISO 27001, sometimes both | Their own auditors recognise it |
| International enterprise | ISO 27001 | Cyber Essentials is a UK-only scheme |
| Cyber insurers | Either, plus evidence of MFA | Both reduce assessed claim likelihood |
| Local authorities | Cyber Essentials, rising to Plus | Proportionate to data handled |
Read the clause, not the summary
Contract wording matters more than the scheme name. “Certified to Cyber Essentials or equivalent” is a very different obligation from “shall maintain Cyber Essentials Plus certification throughout the term”, and the second one commits you to an annual audit forever. Our guide to Cyber Essentials for suppliers works through the wording that causes disputes.
What Neither Certification Protects You From
Both schemes are worth having and neither is a security guarantee. Understanding the gap is what separates a useful certification programme from an expensive compliance theatre exercise.
A certificate is a snapshot
Cyber Essentials Plus tests your estate on one day. ISO 27001 audits a sample of your management system on a handful of days across three years. Neither watches your network on a Tuesday afternoon in November when somebody disables a firewall rule to make a supplier integration work. The controls have to be operated between audits by people who care, and no certificate creates those people.
Scope excludes more than it includes
Because both schemes let you define a boundary, both can be technically true and practically misleading. A certificate covering a head-office network says nothing about the manufacturing site, the acquired subsidiary or the developer laptops on a separate domain. Buyers who read the scope statement rather than the certificate number are the ones asking the right question.
Neither covers detection and response
The five controls are preventative. They stop common attacks reaching you; they do not tell you when one succeeds. Nothing in Cyber Essentials Plus requires logging, monitoring or an ability to respond, and ISO 27001 requires an incident management process without specifying how quickly you would notice. A tested incident response capability is a separate investment, and for most organisations a more valuable one than moving up a certification tier.
The regulatory floor is rising anyway
None of this sits still. The forthcoming Cyber Security and Resilience Bill extends duties to more organisations and their suppliers, which will push baseline expectations above what Cyber Essentials Plus alone demonstrates. Certification is the floor of a security programme, not its ceiling.
Choosing Between Cyber Essentials Plus and ISO 27001
There is a decision path here, and it is shorter than most people expect. It starts with evidence of demand and only then considers ambition.
Start with the certificate someone has asked for
If a live tender names a scheme, do that scheme, and do it at the tier named. Nothing else is urgent. If two tenders name different schemes, do the cheaper one first — Cyber Essentials Plus certification will be finished long before an ISO 27001 audit is even bookable, so the sequencing is decided for you.
If nobody has asked yet
Do Cyber Essentials. It costs a few hundred pounds, it takes a fortnight, and it forces you to find out whether the five controls are genuinely in place. Almost every organisation that runs it for the first time discovers something — an unsupported machine, a shared admin account, a cloud service without multi-factor authentication.
When Cyber Essentials Plus is the right stopping point
Stop at Cyber Essentials Plus if your customers are UK-based, your data is not especially sensitive, and your buyers are satisfied by a recognised certificate rather than a governance narrative. The annual audit is a genuine control, not just a badge — it re-tests your patching and malware defences every single year, which no other scheme in this comparison guarantees.
When to go straight to ISO 27001
Go straight to ISO 27001 if you sell internationally, if you process significant volumes of client data, if enterprise security questionnaires are already eating your sales team’s week, or if you need a framework that also carries IT governance and supplier management. The cost is real, but so is the effect on deal velocity. IASME Cyber Assurance sits between the two if you want governance breadth without full ISO 27001 audit cost.
Two worked examples
A 20-person engineering consultancy bidding for a defence subcontract has one answer: the tender names Cyber Essentials Plus, so certify basic Cyber Essentials immediately and book the audit for six weeks out. ISO 27001 would cost fifteen times as much and would not satisfy the clause as written. Revisit it only when a different customer asks.
A 60-person software business selling to European banks has the opposite answer. Its buyers send 200-question security assessments that ISO 27001 answers in a single line, and a UK-only certificate carries no weight with them. Here Cyber Essentials Plus is still worth doing — it is cheap, quick and produces technical evidence the ISO auditor will want — but it is the warm-up, not the destination.
Running Cyber Essentials Plus and ISO 27001 Together
Plenty of UK organisations hold both, and the combination is cheaper than the headline numbers suggest, because the evidence overlaps in one direction. Doing Cyber Essentials Plus first genuinely reduces ISO 27001 effort. Doing ISO 27001 first does surprisingly little for a Cyber Essentials Plus application.
What the overlap actually gives you
The five controls map cleanly onto Annex A’s technological theme — configuration management, malware protection, patch and vulnerability management, access control and network security. If those are already evidenced and independently tested, a meaningful slice of your Annex A implementation is done, and the auditor has third-party test results to look at rather than your assurances.
What it does not give you
The overlap stops at the technical boundary. Cyber Essentials Plus contributes nothing toward your risk assessment, Statement of Applicability, internal audit programme, management review, supplier controls, HR screening, physical security or continuity planning. Those are the bulk of an ISO 27001 project, and no amount of technical hygiene shortens them.
Sequencing that saves money
Certify Cyber Essentials in month one, Cyber Essentials Plus in month three, then start the ISO 27001 scoping and risk assessment while the technical evidence is fresh. That order gives you a sellable certificate almost immediately, a verified technical baseline to point auditors at, and no wasted work. Reversing it means paying consultants to document controls you have not yet proven work.
Cyber Essentials Plus and ISO 27001 Questions Answered
Does ISO 27001 replace Cyber Essentials Plus?
No. They certify different things, and some UK buyers explicitly require both. ISO 27001 does not mandate the specific technical tests that Cyber Essentials Plus performs, so holding it is not evidence that your patching or malware defences were independently verified this year.
Can I get Cyber Essentials Plus without the basic certificate?
No. A valid Cyber Essentials certificate is a prerequisite, and the Cyber Essentials Plus assessment must be completed within three months of it being awarded.
Is Cyber Essentials Plus recognised outside the UK?
Rarely. It is a UK government-backed scheme delivered by IASME, and overseas procurement teams generally do not recognise it. ISO 27001 is the international standard and is what travels across borders.
How long does a Cyber Essentials Plus audit take?
The on-site or remote testing itself is usually half a day to two days depending on the device sample. The longer part is preparation and, if anything fails, remediation. Some certification bodies allow a short correction window; others require a fresh booking.
Do I need penetration testing for either scheme?
Neither mandates it. Cyber Essentials Plus includes an external vulnerability scan, which is narrower than a full test. ISO 27001 requires testing only if your risk assessment concludes it is necessary — which for most organisations handling client data, it does. A scoped penetration test is a sensible addition to either.
What happens if we fail the Cyber Essentials Plus audit?
You get told what failed and, in most cases, a short window to correct it before a re-test. If the failure is structural — unsupported software in scope, or a device estate that cannot meet the patching rule — the fix is a project, not a correction, and the certificate waits.
Does either scheme satisfy UK GDPR?
Neither is a compliance certificate for data protection law. Both are useful evidence of appropriate technical and organisational measures, and ISO 27001 maps far more of the accountability requirements. Neither one, on its own, answers a regulator.
Which should a ten-person company choose?
Cyber Essentials first, then Cyber Essentials Plus if a customer requires verified controls. ISO 27001 at that size is usually only worth it when a specific, named contract depends on it, or when security questionnaires have become a genuine drag on sales.
References
NCSC: Cyber Essentials Overview
NCSC: Cyber Essentials Requirements for IT Infrastructure v3.3
NCSC: Cyber Essentials Plus Illustrative Test Specification v3.2
NCSC: Cyber Essentials Resources and Question Sets
IASME: Cyber Essentials Certification
IASME: Cyber Assurance Standard
Procurement Policy Note 09/14: Cyber Essentials Scheme Certification
NHS Data Security and Protection Toolkit