Compliance

Cyber Essentials vs ISO 27001: Which Certification Should You Pursue First?

Both frameworks improve your security posture, but they serve different audiences and demand very different resources. Here is how to choose between them, and how to sequence them if you need both.

E7
Edge7 Networks Team
Networking & Security Specialists
19 May 2026
6 min read
Share

The question behind the question

When an organisation asks whether it should pursue Cyber Essentials or ISO 27001, the real question is usually more specific: a customer, tender, or regulator has asked for evidence of good security, and someone needs to decide what to commit to. The two frameworks are often mentioned in the same breath, which suggests they are alternatives. They are better understood as different tools for different jobs.

Choosing well saves months of effort. Choosing badly means either over-investing in a heavyweight certification you did not need yet, or gaining a lightweight one that does not satisfy the customer who asked. Here is how to tell them apart, and how to sequence them if the answer turns out to be "both".

What Cyber Essentials is

Cyber Essentials is a UK government-backed scheme, run by IASME on behalf of the National Cyber Security Centre. It is deliberately focused. Rather than assessing your whole management system, it checks that five technical controls are in place to defend against the most common internet-based attacks:

  • Firewalls at the boundary between your network and the internet
  • Secure configuration of devices and software
  • Security update management, keeping systems patched and supported
  • User access control, limiting access and admin rights to what is needed
  • Malware protection across devices

The base certification is a verified self-assessment. Cyber Essentials Plus adds an independent technical audit, where an assessor tests the controls rather than taking your word for them. The scheme is updated on a regular cycle. The current requirements sit under version 3.3, assessed through the "Danzell" question set introduced in April 2026, which among other changes treats multi-factor authentication as an auto-fail where it is available but not enabled. The point of the cycle is that the bar rises as common attacks evolve.

Why it exists

A floor, not a ceiling

Cyber Essentials is designed to stop the bulk of commodity attacks: the automated, opportunistic threats that make up most of what any organisation faces. It is a strong baseline that most organisations can reach in weeks, not months. It does not attempt to be a complete information security programme, and it is not trying to be.

What ISO 27001 is

ISO 27001 is an international standard for an Information Security Management System, or ISMS. That phrase matters. It is not a checklist of controls. It is a framework for how an organisation identifies its information security risks, decides what to do about them, implements measures, and improves them over time. The controls are a means to an end. The system that manages them is the substance.

Certification is granted by an accredited body after a two-stage external audit, and it is maintained through surveillance audits over a three-year cycle. The current version is ISO 27001:2022, which restructured the control set in Annex A into 93 controls across four themes (organisational, people, physical, and technological) and introduced eleven new controls covering areas such as threat intelligence, cloud security, and data leakage prevention.

Timeline note

The 2013 version has now retired

The transition period from ISO 27001:2013 to the 2022 revision ended on 31 October 2025. Certificates against the 2013 version are no longer valid. Any organisation certifying now does so directly against ISO 27001:2022, so there is no longer a "which version" decision to make. If you last certified under 2013 and let it lapse, you are looking at a fresh certification rather than a transition.

The differences that drive the decision

The two are not competing for the same slot. Cyber Essentials verifies a set of baseline technical controls. ISO 27001 certifies a management system. That single distinction explains most of the practical differences.

 Cyber EssentialsISO 27001
What it certifiesFive baseline technical controlsA whole information security management system
RecognitionUK-focused; strong for UK public sector and supply chainsInternationally recognised
AssessmentSelf-assessment, or Plus auditTwo-stage external audit by an accredited body
Typical effortWeeksSeveral months to a year
Ongoing burdenAnnual re-certificationSurveillance audits across a three-year cycle
Best suited toEstablishing or proving a solid baselineDemonstrating mature, audited governance

"Cyber Essentials proves you have the locks fitted. ISO 27001 proves you run a system that decides which locks you need, checks they work, and improves them. One is a control check. The other is a management discipline."

Edge7 Networks, Compliance Practice

How to sequence them

For most organisations the two are complementary, and the sensible order is Cyber Essentials first, ISO 27001 when maturity or contracts demand it.

Cyber Essentials is achievable quickly and delivers immediate value: it satisfies a large share of UK tender and supply-chain requirements, and it forces the baseline technical hygiene that any serious programme depends on. Reaching it is a useful test of whether the fundamentals are actually in place, and the work done to achieve it maps directly onto several ISO 27001 Annex A controls. It is groundwork you would have to do anyway.

ISO 27001 is the right next step when the drivers are larger: international customers, enterprise procurement that expects audited governance, regulatory expectations, or a level of security maturity that you want independently verified. Attempting it before the basics are stable tends to be slow and painful, because the ISMS ends up documenting processes that do not yet run reliably.

A note for Irish organisations

Both travel, in different directions

Cyber Essentials is a UK scheme, but it is frequently requested of Irish organisations that sell into UK public sector or supply chains, so it carries real commercial weight beyond Britain. ISO 27001, being an international standard, is recognised everywhere and is often the more relevant target for organisations whose customer base is broad or European. Let the customers and contracts you are pursuing decide which recognition matters more.

Deciding for your organisation

Strip it back to two questions. First, what is actually being asked of you, and by whom? A specific tender requirement usually names the certification it wants, which settles the matter. Second, how stable are your fundamentals today? If the honest answer is "not very", Cyber Essentials is both the faster win and the right foundation, whatever your longer-term ISO ambitions.

The failure to avoid is treating certification as the goal in itself. Both frameworks are worth far more when the security behind them is real than when the badge is chased for its own sake. The aim is a materially stronger posture that the certification then evidences.

Edge7 Networks holds both certifications and helps IT teams across Ireland and the UK decide which to pursue, and get there without wasted effort. If you are weighing up Cyber Essentials against ISO 27001, or planning the path from one to the other, a short conversation about what your customers are asking for is the right starting point. For organisations that need the governance depth without a full internal team, our compliance and vCISO services can carry the ISMS.


E7
Edge7 Networks Team
Networking & Security Specialists, Ireland & UK

Edge7 Networks is a specialist networking and security provider, founded in 2018. Our team works with IT leaders across Ireland and the UK on enterprise networking, managed security, and compliance. We hold ISO 27001:2022, ISO 9001:2015, and Cyber Essentials certifications.

Planning your certification path?

Our team helps IT leaders across Ireland and the UK choose, sequence, and reach the right certifications. If you would like to talk it through, we are easy to reach.